Capabilities
ScopeDeliverablesAnchors

Five capabilities that reinforce one another

What we deliver is not consulting hours: it is an organisation that keeps operating on the day the unexpected happens. An incident contained in minutes rather than days, a plant that does not stop, a contract that is not lost for lack of evidence of what was already being done well.

Everything we design rests on two principles that are not up for negotiation: security by design, built into the blueprint rather than added once the system is already in production, and zero trust, where no user, device or service gains access simply by being inside the network, but only after verification on every request.

Security and compliance

Risk analysis, statement of applicability, adequacy plan and support throughout the audit. The framework changes with the counterpart: the National Security Framework when contracting with government, ISO/IEC 27001 to evidence management to clients, insurers and large accounts, and IEC 62443-2-1 when the management system must also cover the plant. If the client is financial, DORA; if it manufactures products with digital elements, the Cyber Resilience Act. NIS2 readiness well before the obligation arrives by letter. Includes authorised technical assessments in white, grey and black box, and 24×7 SOC capability with XDR and EDR.

RD 311/2022 · ISO/IEC 27001:2022 · IEC 62443-2-1 · EU 2022/2555

Auditable artificial intelligence

Risk classification before the first line of code, data lineage, bias control and documented lifecycle governance. An ISO/IEC 42001 management system where the volume justifies it.

Regulation EU 2024/1689 · ISO/IEC 42001

IoT, OT and Industry 4.0

Asset inventory, zones and conduits, passive monitoring that never touches production, and phased segmentation measured at every step.

IEC 62443-3-3 · ISA-95

Process innovation and smart territory

Diagnose the process before the software. Automation, systems integration, digital twins and city platforms with data sovereignty and a written governance model.

ISO 37122 · UNE 178104 · UNE 178108

Automation and workflows

Bespoke development on a process that has already been diagnosed: integration between systems that today do not talk to each other, document workflows with full traceability, robotisation of repetitive work and explicit handling of exceptions. Nothing gets automated before it has been measured.

BPMN 2.0 · ISO/IEC 25010 · Interoperability
AI governance
EU 2024/1689EU 2026/1744ISO/IEC 42001Art. 22 GDPR

What already applies today, even though high risk has been postponed

The Digital Omnibus, Regulation (EU) 2026/1744, moved the obligations for Annex III systems to December 2027. The rest of the Regulation keeps its original calendar, and that is where most organisations still have work to do.

Role before technology

Almost no organisation develops artificial intelligence: it deploys it. Establishing whether you act as a provider or as a deployer changes the entire list of obligations, and it is the first deliverable of any engagement.

Arts. 3, 16 and 26

Inventory and risk classification

Which AI systems are in use, who procured them, what data they run on and which decisions they take part in. Without an inventory there is no compliance, only statements.

Annexes I and III

AI literacy

In force since February 2025 for every organisation using AI, with no size threshold and no exemption for small firms. Training proportionate to each person's role, with a record of who received it.

Art. 4

Transparency and human oversight

Disclosing when someone interacts with an AI system, marking synthetic content, and documenting the human control point, aligned with Article 22 GDPR where the decision has legal effects on a person.

Art. 50 · Art. 14

Fundamental rights impact assessment

Required of public bodies and certain essential services deploying high-risk systems. It is prepared ahead of the date, not the month before.

Art. 27

Regulatory calendar last reviewed on 8 August 2026. The framework is evolving and we verify the dates at the start of every engagement.

Specialised lines
Ground segmentGNSSCrypto-agility

Space, communications and post-quantum

Three fronts where the deadline drives the work. Data encrypted and captured today can be decrypted the day a cryptographically relevant quantum computer exists: that is the harvest-now-decrypt-later logic, and it is why migration starts with an inventory rather than a product.

Space systems security

Ground segment, control stations and telecommand and telemetry links. Link encryption and authentication, station hardening, and separation between the operations network and the corporate one. The space sector sits in Annex I of NIS2, which makes its operators essential entities.

CCSDS SDLS · ECSS · NIS2 Annex I

Satellite communications and GNSS

Protecting satellite links against deliberate interference and spoofing, and protecting the time synchronisation that energy, industry and the traceability of logs themselves depend on.

Position, navigation and timing resilience

Post-quantum transition

Cryptographic inventory, classification by data lifetime, and a migration plan to the standardised algorithms. Recommendation (EU) 2024/1101 and the NIS Cooperation Group roadmap place the start at the end of 2026 and critical infrastructure at the end of 2030.

FIPS 203, 204 and 205 · Rec. (EU) 2024/1101
Regulatory map
PublicPrivateIndustrialFinancial

What applies to you, and from when

The costliest compliance mistake is applying the wrong framework. This is the full map, with who is caught by each one and which date governs.

Data protection

Applies to every organisation processing personal data, with no size exemption. Covers risk analysis, impact assessment where required, and breach notification within 72 hours.

Regulation EU 2016/679 · LO 3/2018

National Security Framework

Mandatory for the Spanish public sector and contractually required of its suppliers. System categorisation, statement of applicability and periodic audit according to category.

RD 311/2022

NIS2

Essential and important entities across eighteen sectors, with direct liability for the management body. Spain has not completed transposition: the Cybersecurity Coordination and Governance Act is still unpublished in the official gazette and RDL 12/2018 remains in force. The substantive obligations, however, have been stable since 2022 and are already required contractually.

Directive EU 2022/2555 · RDL 12/2018

DORA

Financial and insurance entities, and also the technology providers serving them. Applicable since 17 January 2025, with a register of third-party arrangements and digital operational resilience testing.

Regulation EU 2022/2554

Cyber Resilience Act

Manufacturers, importers and distributors of products with digital elements, from industrial devices to mobile apps. From 11 September 2026, actively exploited vulnerabilities must be reported within 24 hours and expanded within 72. The cybersecurity CE marking arrives on 11 December 2027, and fines reach €15 million or 2.5 % of global turnover.

Regulation EU 2024/2847

Artificial Intelligence Act

Providers and deployers of AI systems. Literacy duties and prohibitions are already in force; Annex III high-risk obligations moved to December 2027 under the Digital Omnibus.

Regulation EU 2024/1689 · EU 2026/1744

Accessibility

Mandatory for the public sector since 2018 and for the private sector since 28 June 2025, with an exemption for service microenterprises. The technical reference is the European harmonised standard.

Act 11/2023 · RDL 1/2013 · EN 301 549

Voluntary standards that end up mandatory

ISO/IEC 27001 for the management system, ISO/IEC 42001 for artificial intelligence and IEC 62443 for industrial environments. The law does not impose them; tender documents, insurers and large clients do.

ISO/IEC 27001 · ISO/IEC 42001 · IEC 62443

Map reviewed on 10 August 2026. We verify deadlines and transposition status at the start of every engagement.