Skip to content

Last updated

Engineering

  • A part filled paper identification form and a size self assessment sheet on a desk beside a laptop showing a plain sign in panel, a company registering with its national cybersecurity authority
    NIS2 Entity Registration

    NIS2 puts two different filings behind one word. Member States build the list and require entities to submit identifying information for it, on a two-week update clock, while a narrower set of digital entity types files a longer record with its national authority, corrects it on a three-month clock and has it forwarded to ENISA without its IP ranges. This guide separates the two, marks who is bound by each, and shows what national portals add on top.

  • A management board reviewing a tabbed outsourcing contract at a boardroom table with a soft security operations dashboard on the wall screen behind, one member signing the accountability sheet
    NIS2 Compliance Outsourcing

    NIS2 contains no prohibition on outsourcing any security measure, so the real question is which parts of Article 21 the market can supply and which acts sit with management bodies under Article 20 and the implementing regulation rather than with a provider. A decision guide for an entity whose scope is already settled, covering the supply chain duty that buying anything creates and the evidence a supervisory authority asks the entity, not the vendor, to produce.

  • A hotel revenue manager checking a wall mounted availability grid against a rack of room key cards in the back office, the inventory a channel manager keeps synced across channels
    Hotel Channel Manager Integration

    Hotel channel manager integration as a catalog of failure modes: ARI drift, overbooking from inventory races, rate and room mapping errors, reservation desync and the certification gates standing between a connector and a live OTA channel.

  • A privacy operations employee at a desk cross-referencing a printed data-erasure request against several system record printouts, a wall calendar with one date circled behind them, resolving a GDPR erasure request that arrived through an EUDI Wallet
    EUDI Wallet Data Deletion

    A wallet user taps erase and what reaches you is a GDPR Article 17 request. This is the boundary between the wallet's machinery and the controller's own obligations, the one-month clock the recital's word immediate does not shorten, and the refusal path most build estimates miss.

  • A payments operations employee at a back-office desk holding a smartphone showing a blurred wallet confirmation screen beside a monitor displaying a blurred transaction record and a card terminal printing a receipt, a payment service processing a wallet-presented SCA Attestation
    EUDI Wallet SCA

    A wallet-presented SCA Attestation is an OpenID4VP presentation carrying transactional data, and TS12 states that its verified jti claim serves as the Authentication Code PSD2 requires for electronic payments. This guide walks a payment service through the processing order: reading type metadata, signing and encrypting the request, surviving the locale check, verifying the Key Binding JWT and gating on the amr array. Written throughout as a second acceptance path alongside an existing implementation, never as a replacement for one.

  • A phone showing a chat style layout resting beside a boarding pass and passport on a quiet desk, an AI travel agent assembling a flight booking
    AI Travel Agent Development

    AI travel agent development for an OTA, TMC or booking platform: what a tool-calling agent can and cannot book today, how it stays grounded on live inventory, the guardrails a mis-booking risk requires and an evaluation protocol before launch.

  • A printed crypto-asset white paper open at its ruled sections with a separate summary sheet on top, beside a monitor showing a soft nested outline of tagged sections
    MiCA White Paper Requirements

    The crypto-asset white paper under MiCA Title II is a disclosure document nobody approves and whose content the offeror is solely responsible for. This guide sets out who must draw one up and who is exempt from precisely which obligations, what Annex I forces into the document, the Inline XBRL format rule and its application date, and the notification, publication, modification and withdrawal clocks that run around it.

  • A compliance team assembling a crypto authorization application dossier from labelled binders against a printed document checklist, an application form open on a tablet
    CASP License Application

    An item-by-item walkthrough of the MiCA CASP authorization file: the nineteen points of Article 62(2), what Delegated Regulation (EU) 2025/305 adds on top of them, the annex form and contact point set by the implementing regulation, and the completeness and assessment periods stated as rules rather than as a countdown.

  • Two colleagues in a video call room reading a printed client onboarding record during a call with a remote participant, illustrating reverse solicitation evidence under MiCA Article 61
    Reverse Solicitation Under MiCA: The Article 61 Boundary

    The MiCA transitional period was over everywhere by 1 July 2026, earlier in Member States that shortened it. A third-country crypto firm serving EU clients without a CASP authorization now has exactly one legal basis left, Article 61 reverse solicitation, and two years of ESMA guidance have narrowed it to a keyhole. We work through the statute, the 26 February 2025 guidelines, the broker-model opinion on routing and letter-box entities and ESMA's freshest compliance table dated 10 July 2026, which shows Poland and Romania still without a designated authority for these guidelines ten days after grandfathering ended. Then we cover what an engineering team actually builds to prove a client showed up on its own.

  • A DMC operations team marking a wall departure calendar while reviewing a paper supplier contract at a desk with a wall map behind, the operational surface a tour operator platform has to encode
    Tour Operator Software Development

    Tour operator software development as a phased migration off a legacy reservation system: supplier contracting, allotments and release rules, quotes and vouchers, data cutover and what the Package Travel Directive, both the 2015 text and the 2026 amendment, requires the platform to encode.

  • A compliance officer laying a thin national registration certificate beside a thick authorization decision on a desk, comparing two crypto authorization regimes against a hand ruled decision table
    CASP vs VASP

    VASP is a supervisory label that appears nowhere in EU legislation, used by national regulators for firms on the anti-money-laundering registers the Fifth Anti-Money Laundering Directive required. CASP is an authorization under MiCA Title V with a defined service list and an EU passport. This guide sets the entity-level regimes side by side, including the electronic money institution license and the Article 60 notification route that removes the need for a CASP application for seven categories of already-licensed institution.

  • Close up of a secure door in a custody operations room with an access reader, a hand filled access log on a clipboard and a sealed cabinet for crypto-asset safekeeping.
    MiCA Custody Requirements

    MiCA custody requirements mapped provision by provision: Article 70's safekeeping baseline for every CASP, Article 75's nine-paragraph custody rulebook, the three-limb segregation test, the liability cap at market value at time of loss and the evidence a CASP should have ready for each obligation.

  • Two distribution engineers laying out printed message sample sheets in sequence across a long desk, the Offer to Order message flow behind an airline NDC integration
    NDC API Integration

    NDC API integration for a flight-booking platform: the Offer and Order message set message by message, aggregator versus direct connect, servicing after the sale and what IATA's own capability program actually measures.

  • Printed export inventory on a desk, permission lists beside a schema diagram, a catalog table and a network trust diagram
    Data Act cloud switching requirements

    Article 30 of the EU Data Act splits a switching duty by capability, not by service-model label, and Article 2(37) defines functional equivalence in law while no published standard operationalises it into a threshold. This article works through the exemption gate, the export inventory beyond raw data and the escrow-and-rebuild record that stands in for the missing standard, including the correction most coverage misses: 12 January 2027 zeroes switching charges, not multi-cloud egress.

  • Two records of the same fund holdings compared side by side, a printed ledger listing and a bound shareholder register
    Tokenized fund register reconciliation

    A tokenized fund runs two books, the ledger the token moves on and the shareholder register a transfer agent maintains, and three published regimes now say which one wins when they disagree, in two opposite directions. None of them says how anyone learns the two diverged, at what cadence or where the investor stands between a bad entry and its reversal.

  • An on-duty engineer standing at a desk with a phone handset lifted off its cradle and starting the first entry on a blank printed incident record form, the moment one of the AI Act reporting clocks starts running
    AI Act Serious Incident Reporting

    The AI Act defines a serious incident in four alternative limbs and attaches three different reporting deadlines to them, and since 27 July 2026 the recipient of the report depends on who supervises the provider.

  • Two bound hardcover incident logbooks lying open side by side on one desk with visibly different column rulings and a separate pen resting in each, the two independent classification passes a financial entity runs under the AI Act and DORA
    AI Act and DORA Overlap

    How the EU AI Act and DORA land on the same financial entity without either text citing the other, why Article 74(6) puts the AI file on the financial supervisor's desk, and what Articles 26(5), 26(6), 72(4) and 73(9) actually change.

  • A bank compliance officer reading from an open supplier manual while a colleague fills a single row on a wide ruled sheet whose other rows stay empty, the deployer side fundamental rights impact assessment owed by banks and insurers under the AI Act
    AI Act Fundamental Rights Impact Assessment

    Article 27 of the AI Act puts the fundamental rights impact assessment on the deployer, names creditworthiness and life and health insurance pricing explicitly, and since July 2026 lets it cross-reference an existing data protection impact assessment.

  • A hand-ruled monitoring plan draft on plain paper beside a printed list of logging fields on a working desk, the Article 72 plan a team has to design itself because the mandatory template never issued
    AI Act Post-Market Monitoring Plan

    What Article 72 of the EU AI Act requires of a post-market monitoring system and plan, why the mandatory Commission template was repealed before it ever appeared, and what telemetry, logging and retention an engineering team has to build to make the plan real.

  • A provider's own staff signing the declaration page on a thick conformity file in a small office with no external assessor present, the Annex VI internal control route for credit scoring and insurance pricing under the AI Act
    AI Act Conformity Assessment

    Which conformity assessment procedure applies to a high-risk AI system under Article 43, why Annex III point 5 credit and insurance systems take the Annex VI internal control route with no notified body involved, and what evidence a self-assessment has to produce and keep.

  • Macro of a printed source document marked with cut lines at its section breaks and one exception clause bracketed back to the rule above it.
    RAG Data Pipeline

    A RAG corpus is a live system with state, not a build artifact. This piece traces one document through arrival, change, duplication, deletion and embedding model migration, and shows where five major vector stores document contradictory answers to the same event.

  • Three colleagues laying out a dated compliance sequence along a long paper wall planner and moving small cards between three separate dated windows, the timeline work behind EU AI Act compliance
    EU AI Act Compliance

    A dated EU AI Act compliance timeline and applicability map after Regulation (EU) 2026/1744, covering what changed in Article 113, Article 6 and Article 50 and why EUR-Lex, the Commission's AI Act tool and the most-cited third-party tracker still show the pre-amendment rules.

  • Five national application dossiers of visibly different thickness laid in a row beside a desk calculator and a printed fee schedule, the cost of a MiCA CASP licence across Member States
    CASP License Cost by Country

    CASP license cost broken down per EU country: national regulator fees from Latvia's EUR 2,500 to Malta's EUR 25,000, MiCA's EU-wide capital floors, market total-setup estimates, the Poland no-license-window trap and passporting under Article 65.

  • Close up of a printed payment provider shortlist with four entries circled and one crossed out, on a treasury desk beside a monitor edge and a card terminal.
    Stablecoin Payment API Selection: Orchestration vs Issuance

    Stablecoin payment API selection for CTOs and engineering leads: orchestration vs issuance API compared, a six-provider landscape table and the custody, licensing and off-ramp criteria that actually decide the pick.

  • Two clipped printed legislative texts on a payments engineering desk under a magnetic wall planner strip whose first slot sits empty, PSD3 and PSR planning without a publication date
    PSD3 Compliance Requirements

    PSD3 and PSR compliance is an offset from an unset anchor, not a calendar date. The 21 and 27 month tiers, sourced from the Council's April 2026 compromise texts, and what a build has to have ready before either clock starts.

  • Duty analysts at a public sector security operations desk during a shift handover with a wall clock and a paper incident log between them.
    NIS2 Compliance Software Requirements

    NIS2 never names a software company as a regulated type. This piece sorts a software vendor into the route that actually applies, then lists the artifacts each route asks it to keep on a shelf.

  • An accessibility testing bench laid out with a refreshable braille display, a keyboard with the mouse set aside, a switch access pad and headphones.
    European Accessibility Act Compliance

    The European Accessibility Act never names WCAG or EN 301 549. This piece sorts a software company into the role that actually carries liability, and states plainly why the standard everyone cites carries no legal presumption here.

  • A printed identity intake form with five filled rows and a run of blank rows beneath them, one filled row marked with a small paper flag, standing in for the five guaranteed EUDI Wallet identity fields against fourteen optional fields that may never arrive
    EUDI Wallet Onboarding

    Person identification data guarantees five fields and marks fourteen more optional, and a mandatory field may carry a substituted value where the real one is unknown. What an onboarding flow can and cannot assume from a wallet presentation.

  • Engineer at a prototype bench between a wired test rig, a taped row of printed paper screen mockups and a laptop showing a working sign up form, proof of concept and prototype and MVP deliverables
    PoC vs MVP vs Prototype

    PoC vs MVP vs prototype explained as three different questions rather than three sizes of the same build, with real cost ranges and a decision framework for which to build first.

  • Close up of a printed two column triage sheet and a fanned stack of index cards on a security operations desk with wall monitors behind.
    CRA Severe Incident Classification

    The Cyber Resilience Act never defines severe as a standalone term. The threshold sits in Article 14(5), narrowing the general incident definition to sensitive or important data or functions, or to malicious code, while Article 3(42) sets a separate evidentiary bar for actively exploited that a high severity score alone does not meet.

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let's work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 4 hours

What happens next?

  1. Contact us

    Contact us today to discuss your project. We're ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We're committed to keeping your information confidential, so we'll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we'll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let's connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day