Three engagements, each ending in an artefact you can hand to a reviewer
We do not sell compliance programmes. We produce the specific evidence that unblocks a deal or an audit, and document how it was verified.
01
AI Act readiness
Article 50 has applied since 2 August 2026. The high-risk obligations moved: Annex III to 2 December 2027, Annex I to 2 August 2028. Most readiness projects on the market are still priced against the old calendar. We scope yours against the current one.
Your customer is in scope for NIS2, so you are audited as part of their supply chain. That audit asks for artefacts, not intentions: asset inventory, patch windows, incident timelines, subcontractor list, exit plan.
Sovereignty is a buyer's problem stated as a hosting question. We answer it as an architecture decision: which layer must stay in your jurisdiction, what that costs over three years, and what an auditor accepts as proof.
Choose between on-prem, air-gapped, network-isolated and private-cloud AI with the numbers and the audit consequences of each option.
A deployment recommendation with a three-year cost model, not a vendor preference
Data Act egress, audit evidence, TCO
Frequently asked questions
Do high-risk obligations apply from August 2026?
No. The Digital Omnibus that entered into force on 27 July 2026 moved Annex III systems to 2 December 2027 and Annex I to 2 August 2028. Only Article 50 applies from 2 August 2026.
What still has a 2026 deadline?
2 December 2026: the end of the grace period for marking synthetic content, and the prohibition covering CSAM and non-consensual intimate imagery.
Does NIS2 apply to us if we only sell software?
Often indirectly. If your customer is an essential or important entity, its supply-chain obligations become contractual requirements on you, whatever your own scope status is.
Is ISO 27001 enough?
It carries a large part of the control evidence and none of the reporting duties. The overlap is real but partial.
Is on-prem always cheaper?
Only above a sustained utilisation threshold. Below it, private cloud wins on three-year TCO even with sovereignty premiums included.
Do auditors require an air gap?
Rarely. Documented network isolation with enforced egress controls is accepted far more often than a true air gap, which most teams cannot operate consistently.