Compliance built in

Software that is compliant from day one

New EU rules turn security, transparency and updates into obligations. We build them into your software from the first requirement — so compliance is part of the solution, not an expensive add-on.

EU AI Act

Status: In force since 1 Aug 2024. Prohibitions and AI literacy apply since 2 Feb 2025, GPAI rules since 2 Aug 2025, transparency duties from 2 Aug 2026; high-risk obligations follow on 2 Dec 2027 and 2 Aug 2028.

What it means for your software

Software with AI features needs a clear risk classification, human oversight, traceability and transparency towards users.

What we deliver

  • Technical support for the AI system inventory and risk classification
  • Logging, traceability and human-oversight functions
  • Transparency notices built into the user interface
  • Technical documentation for your AI features
Discuss your case →

Cyber Resilience Act (CRA)

Status: Reporting obligations apply since 11 Sep 2026 (early warning within 24 h, notification within 72 h); full application from 11 Dec 2027.

What it means for your software

Products with digital elements must be secure by design, handle vulnerabilities and receive security updates over their support period (as a rule at least five years).

What we deliver

  • Secure-by-design architecture and hardening
  • SBOM and dependency monitoring
  • Vulnerability handling and coordinated disclosure process
  • Signed update delivery and the 24 h / 72 h reporting playbook
  • Technical documentation for the conformity assessment
Discuss your case →

NIS2 / NISG 2026 (Austria)

Status: Austria’s NISG 2026 is in force since 1 Oct 2026; affected entities must manage cyber risks — including in their supply chain.

What it means for your software

Your software and IT suppliers become part of your risk management. Access control, logging, backup and incident handling must be demonstrable.

What we deliver

  • Secure infrastructure: hardening, MFA, logging and monitoring
  • Backup and recovery concepts that are tested
  • Supplier documentation for your NIS2 audits
  • Support in incident handling
Discuss your case →

GDPR

Status: Applies since 25 May 2018 — privacy by design and by default are legal requirements (Art. 25).

What it means for your software

Personal data must be minimised, protected and deletable — and processing must be documented.

What we deliver

  • Data minimisation, roles and deletion concepts in the software
  • Technical and organisational measures (TOMs) documented
  • Data processing agreement (Art. 28) where we process data for you
  • Hosting in the EU or on your own servers
Discuss your case →

Product Liability Directive (EU) 2024/2853

Status: Applies to products placed on the market from 9 Dec 2026. Software counts as a product.

What it means for your software

A missing security update within the manufacturer’s control can make a product defective — update capability and documented testing become a liability question.

What we deliver

  • Update capability designed in from the start
  • Documented testing and change history
  • Long-term support with planned security updates
Discuss your case →

How it fits into our process

Every one of our nine steps produces evidence — from the regulatory scope note at the start to the 24 h / 72 h reporting chain in support.

  1. 1. Customer request: goals, costs, time required — Regulatory scope note: which rules apply (AI Act risk class, CRA product scope, NIS2, GDPR).
  2. 2. Study — with experience — Risk and data-protection assessment, threat model.
  3. 3. Agree on the smallest change — Architecture decision record incl. security and privacy by design.
  4. 4. Implement — SBOM, secure-coding rules, reviewed AI-assisted code.
  5. 5. Check — Test and security-scan records, traceable to requirements.
  6. 6. Improve — Vulnerability handling and documented change history.
  7. 7. Publish — Release notes, technical documentation, signed releases.
  8. 8. The benefit for your customers — User information and transparency notices (e.g. for AI features).
  9. 9. Support & maintenance — Security updates over the support period, 24 h / 72 h reporting chain (CRA).

How we work →

Governance and deadlines

AI governance, policies and local AI operation: KI-Beratung.st ↗

Current deadlines of 12 EU rule sets: ITDA-S EU Rules Radar ↗

We deliver engineering and technical implementation, not legal advice. For a binding legal assessment, please involve a lawyer.

Let's talk about your project

Tell us what you're building — we'll follow up within one business day.

info@qmisoft.com

Call usFree initial call