ScopeDeliverablesAnchorsFive capabilities that reinforce one another
What we deliver is not consulting hours: it is an organisation that keeps operating on the day the unexpected happens. An incident contained in minutes rather than days, a plant that does not stop, a contract that is not lost for lack of evidence of what was already being done well.
Everything we design rests on two principles that are not up for negotiation: security by design, built into the blueprint rather than added once the system is already in production, and zero trust, where no user, device or service gains access simply by being inside the network, but only after verification on every request.
Security and compliance
Risk analysis, statement of applicability, adequacy plan and support throughout the audit. The framework changes with the counterpart: the National Security Framework when contracting with government, ISO/IEC 27001 to evidence management to clients, insurers and large accounts, and IEC 62443-2-1 when the management system must also cover the plant. If the client is financial, DORA; if it manufactures products with digital elements, the Cyber Resilience Act. NIS2 readiness well before the obligation arrives by letter. Includes authorised technical assessments in white, grey and black box, and 24×7 SOC capability with XDR and EDR.
RD 311/2022 · ISO/IEC 27001:2022 · IEC 62443-2-1 · EU 2022/2555Auditable artificial intelligence
Risk classification before the first line of code, data lineage, bias control and documented lifecycle governance. An ISO/IEC 42001 management system where the volume justifies it.
Regulation EU 2024/1689 · ISO/IEC 42001IoT, OT and Industry 4.0
Asset inventory, zones and conduits, passive monitoring that never touches production, and phased segmentation measured at every step.
IEC 62443-3-3 · ISA-95Process innovation and smart territory
Diagnose the process before the software. Automation, systems integration, digital twins and city platforms with data sovereignty and a written governance model.
ISO 37122 · UNE 178104 · UNE 178108Automation and workflows
Bespoke development on a process that has already been diagnosed: integration between systems that today do not talk to each other, document workflows with full traceability, robotisation of repetitive work and explicit handling of exceptions. Nothing gets automated before it has been measured.
BPMN 2.0 · ISO/IEC 25010 · InteroperabilityEU 2024/1689EU 2026/1744ISO/IEC 42001Art. 22 GDPRWhat already applies today, even though high risk has been postponed
The Digital Omnibus, Regulation (EU) 2026/1744, moved the obligations for Annex III systems to December 2027. The rest of the Regulation keeps its original calendar, and that is where most organisations still have work to do.
Role before technology
Almost no organisation develops artificial intelligence: it deploys it. Establishing whether you act as a provider or as a deployer changes the entire list of obligations, and it is the first deliverable of any engagement.
Arts. 3, 16 and 26Inventory and risk classification
Which AI systems are in use, who procured them, what data they run on and which decisions they take part in. Without an inventory there is no compliance, only statements.
Annexes I and IIIAI literacy
In force since February 2025 for every organisation using AI, with no size threshold and no exemption for small firms. Training proportionate to each person's role, with a record of who received it.
Art. 4Transparency and human oversight
Disclosing when someone interacts with an AI system, marking synthetic content, and documenting the human control point, aligned with Article 22 GDPR where the decision has legal effects on a person.
Art. 50 · Art. 14Fundamental rights impact assessment
Required of public bodies and certain essential services deploying high-risk systems. It is prepared ahead of the date, not the month before.
Art. 27Regulatory calendar last reviewed on 8 August 2026. The framework is evolving and we verify the dates at the start of every engagement.
Ground segmentGNSSCrypto-agilitySpace, communications and post-quantum
Three fronts where the deadline drives the work. Data encrypted and captured today can be decrypted the day a cryptographically relevant quantum computer exists: that is the harvest-now-decrypt-later logic, and it is why migration starts with an inventory rather than a product.
Space systems security
Ground segment, control stations and telecommand and telemetry links. Link encryption and authentication, station hardening, and separation between the operations network and the corporate one. The space sector sits in Annex I of NIS2, which makes its operators essential entities.
CCSDS SDLS · ECSS · NIS2 Annex ISatellite communications and GNSS
Protecting satellite links against deliberate interference and spoofing, and protecting the time synchronisation that energy, industry and the traceability of logs themselves depend on.
Position, navigation and timing resiliencePost-quantum transition
Cryptographic inventory, classification by data lifetime, and a migration plan to the standardised algorithms. Recommendation (EU) 2024/1101 and the NIS Cooperation Group roadmap place the start at the end of 2026 and critical infrastructure at the end of 2030.
FIPS 203, 204 and 205 · Rec. (EU) 2024/1101PublicPrivateIndustrialFinancialWhat applies to you, and from when
The costliest compliance mistake is applying the wrong framework. This is the full map, with who is caught by each one and which date governs.
Data protection
Applies to every organisation processing personal data, with no size exemption. Covers risk analysis, impact assessment where required, and breach notification within 72 hours.
Regulation EU 2016/679 · LO 3/2018National Security Framework
Mandatory for the Spanish public sector and contractually required of its suppliers. System categorisation, statement of applicability and periodic audit according to category.
RD 311/2022NIS2
Essential and important entities across eighteen sectors, with direct liability for the management body. Spain has not completed transposition: the Cybersecurity Coordination and Governance Act is still unpublished in the official gazette and RDL 12/2018 remains in force. The substantive obligations, however, have been stable since 2022 and are already required contractually.
Directive EU 2022/2555 · RDL 12/2018DORA
Financial and insurance entities, and also the technology providers serving them. Applicable since 17 January 2025, with a register of third-party arrangements and digital operational resilience testing.
Regulation EU 2022/2554Cyber Resilience Act
Manufacturers, importers and distributors of products with digital elements, from industrial devices to mobile apps. From 11 September 2026, actively exploited vulnerabilities must be reported within 24 hours and expanded within 72. The cybersecurity CE marking arrives on 11 December 2027, and fines reach €15 million or 2.5 % of global turnover.
Regulation EU 2024/2847Artificial Intelligence Act
Providers and deployers of AI systems. Literacy duties and prohibitions are already in force; Annex III high-risk obligations moved to December 2027 under the Digital Omnibus.
Regulation EU 2024/1689 · EU 2026/1744Accessibility
Mandatory for the public sector since 2018 and for the private sector since 28 June 2025, with an exemption for service microenterprises. The technical reference is the European harmonised standard.
Act 11/2023 · RDL 1/2013 · EN 301 549Voluntary standards that end up mandatory
ISO/IEC 27001 for the management system, ISO/IEC 42001 for artificial intelligence and IEC 62443 for industrial environments. The law does not impose them; tender documents, insurers and large clients do.
ISO/IEC 27001 · ISO/IEC 42001 · IEC 62443Map reviewed on 10 August 2026. We verify deadlines and transposition status at the start of every engagement.