Skip to content

Engineering

  • PSD3 Compliance Requirements

    PSD3 and PSR compliance is an offset from an unset anchor, not a calendar date. The 21 and 27 month tiers, sourced from the Council's April 2026 compromise texts, and what a build has to have ready before either clock starts.

  • Macro of a printed source document marked with cut lines at its section breaks and one exception clause bracketed back to the rule above it.
    RAG Data Pipeline

    A RAG corpus is a live system with state, not a build artifact. This piece traces one document through arrival, change, duplication, deletion and embedding model migration, and shows where five major vector stores document contradictory answers to the same event.

  • An accessibility testing bench laid out with a refreshable braille display, a keyboard with the mouse set aside, a switch access pad and headphones.
    European Accessibility Act Compliance

    The European Accessibility Act never names WCAG or EN 301 549. This piece sorts a software company into the role that actually carries liability, and states plainly why the standard everyone cites carries no legal presumption here.

  • Duty analysts at a public sector security operations desk during a shift handover with a wall clock and a paper incident log between them.
    NIS2 Compliance Software Requirements

    NIS2 never names a software company as a regulated type. This piece sorts a software vendor into the route that actually applies, then lists the artifacts each route asks it to keep on a shelf.

  • Hardware test bench with a small connected device opened on an anti static mat beside a clipped printed dependency list and an archive box.
    CRA Vulnerability Handling Requirements

    Annex I Part II of the Cyber Resilience Act sets eight standing vulnerability handling duties, and Article 13 layers two further clocks on top: a support period of at least five years, unless the product's expected use is genuinely shorter, and a ten year availability window on every security update issued during it. Which conformity route a product takes then depends on its Annex III or Annex IV class.

  • Two colleagues in a documentation and print room, one lifting a printed checklist from an office printer while the other types into a plain web form on a laptop.
    CRA Single Reporting Platform Integration

    The CRA's Single Reporting Platform is a web form and case management system that ENISA runs, not an API, with no published roadmap for one. Registration runs through named individual Assigned Representatives, and one notification record moves through three stages that lock for good once the final report is submitted.

  • Hands and shoulders of two colleagues comparing clauses across three thick ring binders opened flat in a small meeting booth.
    CRA NIS2 and DORA Reporting Overlap

    A company that is at once a CRA manufacturer, a NIS2 essential or important entity and a DORA financial entity keeps three separate reporting duties on three separate filings, even where two of them reach the same national CSIRT. The CRA's Single Reporting Platform consolidates filings within the CRA itself and does not fold NIS2 or DORA into that filing.

  • Close up of a printed two column triage sheet and a fanned stack of index cards on a security operations desk with wall monitors behind.
    CRA Severe Incident Classification

    The Cyber Resilience Act never defines severe as a standalone term. The threshold sits in Article 14(5), narrowing the general incident definition to sensitive or important data or functions, or to malicious code, while Article 3(42) sets a separate evidentiary bar for actively exploited that a high severity score alone does not meet.

  • Top down view of two printed reporting timelines, a desk clock and a marked regulation extract on an incident war room table.
    CRA Incident Reporting Deadlines

    The EU Cyber Resilience Act's Article 14 sets up two separate reporting duties, not one sequence: an actively exploited vulnerability and a severe incident share the same 24-hour and 72-hour stages but diverge at the final report deadline. Filing there does not satisfy the separate duty to inform affected users.

  • LLM Observability Cost

    A real LLM observability cost model built from verified vendor pricing retrieved 2026-08-08, showing why Langfuse, LangSmith, Braintrust and Arize cannot be compared on list price alone and how the OpenTelemetry GenAI conventions' Development status quietly breaks naive cost attribution.

  • MCP Server Development

    A spec-current guide to MCP server development after the 2026-07-28 revision, covering the stateless protocol change, the modern-vs-legacy split, server primitives, transports, authorization and the named security failure modes, plus what a server actually costs to build and maintain.

  • Electronic Money Token Issuance

    MiCA describes an accounting outcome for an e-money token and almost never a mechanism. This follows one euro through the licence gate, the mint, placement, circulation, the redemption request, burn and attestation, states which of those steps the Regulation actually specifies and names the two places where it specifies nothing at all.

  • E-Money Safeguarding Reconciliation

    An EMI or PI CTO has to prove on any business day that customer balances in the ledger equal the safeguarding accounts. No EU instrument in force names how often that comparison runs. This walks the invariants that do exist, the way each one breaks and the control that catches the break, ordered by how fast the control fires.

  • Instant Payments Sanctions Screening

    Article 5d did not ban sanctions screening on the instant rail. It moved the object of the screening from the transaction to the customer base, prohibited one specific check in one specific window between two specific parties and carved out three categories expressly. This walks the pre-2025 screening stack component by component and states, for each one, what replaces it and which control it was carrying.

  • Verification of Payee Implementation

    Verification of Payee is two jobs in one build, and the scheme treats them very differently. The requesting side is a specified round trip with a five second envelope and a discard rule. The responding side is a specified message shape wrapped around a decision the scheme declines to make, in a guidance document that says it is not part of the Rulebook and that the responder is free to ignore. This walks the message lifecycle position by position, states each one twice and closes each one on the contract both sides owe.

  • ISO 20022 Structured Address Migration: What Breaks on 15 November 2026

    The EPC's 15 November 2026 inter-PSP settlement date and Swift's 14 November 2026 SR 2026 go-live are two different events on one cutover weekend. This walks an address population through seven gates, from scope to the inter-PSP double rejection duty, and states at each gate which records die and what the remedy is.

  • CASP Wind Down Plan

    A CASP wind down plan is required by MiCA Article 74 and defined by almost nothing else in the act: no paragraph numbering, no recital, no technical standard, no filing duty and no deadline. What MiCA does supply is two conflicting destinations for client assets, a transfer to a successor provider under Article 64(8) and a return to the client under Article 75(6), and it never says which one runs. This article walks the wind-down in execution order, from the duties that have to be standing before any exit decision through trigger, freeze, client instruction, execution, sub-custody unwind and register closeout, and it is honest about the three different timing formulas MiCA writes for cessation, none of which is a number.

  • Omnibus vs Segregated Crypto Wallets

    Omnibus vs segregated crypto wallets is an architecture decision with a statutory edge: MiCA Article 75(7) limb one requires that on the distributed ledger, clients' crypto-assets are held separately from the CASP's own. This article reads that sentence closely, shows where per-client granularity actually lives, walks the cost of each branch on UTXO and account-model chains and treats reconciliation between the on-ledger position and the Article 75(2) register as the evidence artefact a supervisor will ask for.

  • Smart Contract Risk in Crypto Custody

    Smart contract risk in crypto custody is the one ESMA Common Supervisory Action scope item with no settled evidence practice behind it. This article treats each claim a CASP makes about its contracts as a claim under test, and names the artefact that proves or falsifies it: how upgrade privilege is proven on chain and revoked, what a proxy admin key does to an Article 75(7) segregation argument, what a staking contract does to the register of positions and what 130 audits say about where the critical findings actually cluster.

  • GPAI Model Obligations

    What a general-purpose AI model provider owes regulators under Annex XI versus downstream integrators under Annex XII, where the open-source carve-out stops and why GPAI penalties sit in Article 101, not Article 99.

  • AI Act Technical Documentation

    Annex IV of the EU AI Act translated point by point into engineering deliverables, plus the logging and retention duties in Article 12, Article 19 and Article 26 and the unconfirmed SME simplified-documentation route.

  • AI Act High Risk Classification

    How to classify an AI system as high-risk under Article 6 and Annex III of the EU AI Act after the Digital Omnibus, with the new 1a to 1c carve-outs, a decision tree and worked examples.

  • AI Act Article 50

    What Article 50 of the EU AI Act actually requires for marking AI-generated content, the two mandatory layers, the transitional date hidden in Article 111(4) and the failure modes the Code of Practice admits marking cannot survive.

  • EU AI Act Compliance

    A dated EU AI Act compliance timeline and applicability map after Regulation (EU) 2026/1744, covering what changed in Article 113, Article 6 and Article 50 and why EUR-Lex, the Commission's AI Act tool and the most-cited third-party tracker still show the pre-amendment rules.

  • Crypto AML Rule Tuning

    Crypto AML rule tuning covering the ATL/BTL threshold-testing lifecycle, a hedged sub-1 percent SAR-conversion retirement signal, the back-test gate before a threshold ships and what MiCA vs the incoming AMLR actually require of CASP transaction monitoring.

  • CASP License Cost by Country

    CASP license cost broken down per EU country: national regulator fees from Latvia's EUR 2,500 to Malta's EUR 25,000, MiCA's EU-wide capital floors, market total-setup estimates, the Poland no-license-window trap and passporting under Article 65.

  • Three people in a bright testing room reading a printed timeline taped in a row along the wall during a red team and blue team replay session.
    Threat-Led Penetration Testing for Crypto Firms

    DORA Threat-Led Penetration Testing (TLPT) for crypto firms mapped provision by provision: the Article 26(8) designation gate that decides which CASPs owe TLPT at all, how it differs from ordinary Article 25 testing, the ECB TIBER-EU phases behind it, tester requirements under Article 27 and the evidence a regulator expects afterward.

  • A work table in a records room with a dozen contract folders spread in rows beside a clipped stack of printed multi column template pages and a blue file band.
    DORA Register of Information

    How a MiCA-authorized CASP builds and maintains the DORA Register of Information under Article 28: the 15-template data model from Commission Implementing Regulation (EU) 2024/2956, mandatory LEI/EUID identifiers, the criticality classification that drives subcontractor depth and risk assessment, common register-build mistakes and the xBRL-CSV submission pipeline.

  • MPC vs Multisig vs HSM

    The engineering decision underneath MiCA custody: MPC threshold signatures, HSM tamper-response hardware and on-chain multi-sig compared on single-point-of-failure resistance, auditability, recovery, cost and chain-agnosticism, with a cold/warm/hot tiering pattern and key ceremony, rotation and disaster-recovery design notes.

  • MiCA Custody Requirements

    MiCA custody requirements mapped provision by provision: Article 70's safekeeping baseline for every CASP, Article 75's nine-paragraph custody rulebook, the three-limb segregation test, the liability cap at market value at time of loss and the evidence a CASP should have ready for each obligation.

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let's work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 4 hours. Prefer email? hello@pharosproduction.com

What happens next?

  1. Contact us

    Contact us today to discuss your project. We're ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We're committed to keeping your information confidential, so we'll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we'll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let's connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day