In application
Interoperable Europe Act: Regulation applies
A governance framework for cross-border interoperability and the reuse of public-sector solutions.
Public Sector & Government
We design, build and run digital services for public bodies: accessible by law, secure by default, interoperable by design and documented well enough to outlast the contract. 600+ European government projects for public bodies across the European Union have shaped how we work.
For ministries, agencies, regions and municipalities across Europe that must serve every citizen, in every official language, under EU and national rules at once.

28 June 2025
European Accessibility Act applies
Accessibility duties now reach key private services, alongside the rules public bodies already follow.
24 December 2026
EU Digital Identity Wallets due
Every Member State must offer at least one wallet, and public services must accept it.
2 December 2027
AI Act high-risk duties apply
Including the fundamental rights impact assessment for public deployers, as amended in 2026.
600+European government projects
The AI Act, NIS2, eIDAS 2, the Interoperable Europe Act and the Data Act reach the same IT estates within a few years. Each adds documentation, risk and reporting duties, and tenders now ask suppliers to show how they support them.
People expect to apply, follow up and receive decisions online, in their own language, without supplying the same evidence twice. For key cross-border procedures, once-only is already an obligation.
Experienced caseworkers and the engineers who know the legacy code are leaving faster than they can be replaced. What lives in people and old systems has to move into documented services and tools the next generation can work with.
AI can shorten queues and backlogs, but a public body must be able to explain a decision, keep a named person accountable and disclose the systems it uses. That changes how AI is designed, not only how it is bought.
Core case systems are decades old, and every legal change means a risky release.
We modernise in steps behind stable interfaces: extract services, migrate data with reconciliation and retire modules one at a time. Citizens are spared a big-bang switchover.
Citizens and businesses supply the same evidence again and again.
We connect services to authentic sources and national data exchange platforms, so data is fetched once, with a legal basis, and every access is logged.
Contact centres absorb questions the website should answer.
Multilingual service assistants grounded in your published rules and procedures, with a clear handover to staff and no answers outside approved sources.
Caseworkers lose hours reading, sorting and re-keying incoming files.
Document intelligence classifies and extracts, a person validates uncertain fields and the case system receives structured data with a full audit trail.
AI pilots stall at legal and ethics review.
We design for review from discovery onwards: risk classification, input for the data protection and fundamental rights impact assessments, logging, human oversight and documentation for transparency registers.
Policy knowledge is scattered across intranets, PDFs and people.
Permission-aware knowledge search that cites the regulation, circular or procedure behind every answer, so staff can check before they act.
Dates that shape architecture and procurement decisions now. National transpositions and implementing acts can add their own dates.
In application
A governance framework for cross-border interoperability and the reuse of public-sector solutions.
In application
National laws apply as each is adopted. Public administration entities come into scope, with risk management and incident reporting duties.
In application
Before deciding on new or substantially changed trans-European digital public services.
In application
Including social scoring by public authorities. AI literacy duties start on the same date.
In application
For key products and services, through national laws.
In application
Including data requests by public bodies in cases of exceptional need and cloud switching rules.
In application
People must be told when they interact with an AI system, and generated content must be marked.
Status as of 2 October 2026
Upcoming
Each Member State offers at least one wallet; public services that require online identification must accept it.
Upcoming
For stand-alone high-risk uses such as access to public services and benefits, as amended in 2026.
The instruments that most often shape a public-sector specification, in plain words, with what each one means for the programme.
This overview supports planning conversations. It is not legal advice, and national transpositions differ. Dates reviewed on 2 October 2026.
Risk-based rules for AI systems. AI used to decide on access to essential public services and benefits, migration, asylum and border control, justice and law enforcement is listed as high-risk.
Public bodies that deploy high-risk systems must carry out a fundamental rights impact assessment (Article 27), assign human oversight and keep logs. Under the Act as amended in 2026, these duties apply from 2 December 2027.
We classify each use case during discovery, build oversight and logging into the system and prepare the technical documentation your legal team needs. The legal assessment stays with your own counsel.
SourceRegulation (EU) 2024/1689, EUR-Lex (opens external site)
Central government administrations are in scope, and Member States may add regional and local administrations. Duties cover risk management, supply-chain security and staged incident reporting, starting with an early warning within 24 hours.
Expect security clauses in every contract. We document our controls, report incidents through the agreed channels and give you the evidence your own supervisory duties require.
SourceDirective (EU) 2022/2555, EUR-Lex (opens external site)
Each Member State must offer at least one EU Digital Identity Wallet by 24 December 2026. Public services that require electronic identification must accept it, next to national eID schemes.
Login, attribute sharing and electronic signatures have to work with the wallet. We design identity integration so a new credential type is configuration, not a rebuild.
SourceRegulation (EU) 2024/1183, EUR-Lex (opens external site)
Applies since 12 July 2024. Since 12 January 2025 public bodies must carry out an interoperability assessment before deciding on new or substantially changed trans-European digital public services, and are encouraged to share and reuse solutions, including open source.
We prepare the assessment input with you, reuse existing building blocks and document interfaces so others can adopt what you build.
SourceRegulation (EU) 2024/903, EUR-Lex (opens external site)
Since 12 December 2023, users of key cross-border procedures can ask for evidence to be exchanged directly between authorities through the Once-Only Technical System, instead of uploading it themselves.
Evidence exchange must be consent-based, previewable and logged. We integrate national data exchange platforms and once-only connectors into the service flow.
SourceRegulation (EU) 2018/1724, EUR-Lex (opens external site)
Public-sector websites and mobile apps must meet the harmonised standard EN 301 549, which builds on WCAG, and publish an accessibility statement with a feedback mechanism. National laws transpose it, for example BITV 2.0 in Germany.
We build to WCAG 2.2 AA, test with assistive technology and help you keep the accessibility statement accurate.
SourceDirective (EU) 2016/2102, EUR-Lex (opens external site)
Applies since 28 June 2025 to key products and services such as banking, e-commerce, e-books and transport services. It applies to economic operators, not to public bodies directly, but public procurement uses its accessibility requirements and services run with private partners may be in scope.
Accessibility now runs through the whole delivery chain. We make it part of the acceptance criteria, not a late audit.
SourceDirective (EU) 2019/882, EUR-Lex (opens external site)
Applies since 12 September 2025. Public bodies can request data held by companies in cases of exceptional need, and data processing services must make switching provider possible, with switching charges phased out by January 2027.
We design exit plans and data portability into cloud architectures, so changing provider is a planned project rather than a crisis.
SourceRegulation (EU) 2023/2854, EUR-Lex (opens external site)
Public bodies buy through open, restricted and negotiated procedures, competitive dialogue and framework agreements with mini-competitions. The rules follow Directive 2014/24/EU and its national transpositions, each with its own documents, contract terms and timelines.
We work within those rules: requirement-by-requirement answers, named team members, transparent pricing structures and delivery plans an evaluation committee can score. We take part directly or within a consortium, depending on the lot.
We share what is technically realistic without steering the specification. Early dialogue reduces the risk of tenders nobody can deliver.
We read the specification against the law, the standards and your existing estate, and ask questions through the official channel only.
A structured response: architecture, plan, team, security and accessibility approach, and an exit plan from the start.
After the standstill period: named people, onboarding to your security rules and an agreed first release.
Reporting against contract indicators, documented handover and data return, so the next procurement starts from a clean position.
Hosting regions, encryption key control and support access locations are decided with you before build and written into the architecture.
Open standards, documented data models and infrastructure as code keep switching costs visible, as the Data Act intends.
We assess reusable public components and open-source options first, in line with national open-source policies and the Interoperable Europe Act.
FromNine is ISO/IEC 27001 certified. Controls, supplier management and incident handling follow a certified information security management system.
Incident channels, vulnerability handling and supply-chain transparency are agreed per contract, so you can meet your own NIS2 duties.
Identity, the service front end and the case system sit on top of a data exchange layer that reads from authentic sources.
A citizen or business signs in to a service portal with a national eID or an EU Digital Identity Wallet. A service assistant can answer questions and open the right form.
The portal passes the request to the case system, where a caseworker reviews exceptions and takes decisions.
Portal and case system read the data they need through a national data exchange platform. The platform fetches data from authentic sources such as the population register, the business register and tax and benefits data, and writes every access to a log.
For cross-border procedures the exchange platform connects to the Once-Only Technical System, which exchanges evidence with authorities in other Member States.
Services fetch data from the register that owns it, through national exchange platforms, instead of keeping their own copies.
The European Interoperability Framework, national reference architectures and semantic standards shape the interfaces we design.
Every exchange has a legal basis, a purpose and a log entry that citizens and auditors can trace.
Procedures in scope of the Single Digital Gateway connect to the Once-Only Technical System through national access points.
EN 301 549 builds on WCAG. We design and test to WCAG 2.2 AA, so services meet today's rules and the next revision.
Automated checks in the delivery pipeline, manual audits with screen readers and keyboard, and usability sessions with disabled users wherever you can arrange them.
Content written for the reader's task, with the same quality in each language the service must support.
We help you keep the accessibility statement and feedback route accurate as the service changes.
Integration with national schemes such as the Belgian eID and itsme, DigiD and eHerkenning, BundID, FranceConnect, Cl@ve, SPID and CIE, through their official brokers.
Wallet login and verifiable attestations added alongside existing schemes, so citizens choose and services do not fork.
Request only the attributes a service needs, show the citizen what is shared and keep a record.
Acting on behalf of a company or another person, which most benefit and permit processes need.
Benefits, contributions and employment services, where decisions affect livelihoods and every step must be explainable.
Permits, local taxes, citizen contact and shared services between municipalities.
Case and document flows with strict access control, retention rules and chain-of-custody logging.
Student administration, grant management and research data services.
Shared platforms, registers and back-office systems used across ministries.
Applications and supporting documents are classified and checked for completeness. Caseworkers review flagged items before any decision is made.
Answers questions about procedures in the official languages of the region, cites the page it relied on and hands over to staff when a question needs judgement.
Officers search circulars, procedures and case law in one place. Results respect access rights, and every answer links to its source.
A legacy permit application is replaced module by module behind a stable API, with data reconciled at every step and the old system retired last.
Requests are logged, relevant documents located and redaction proposals prepared. An officer approves every release.
How the parts work together in daily operation. These are illustrative workflows, not client cases.
The citizen signs in with a national eID or an EU Digital Identity Wallet. Only the attributes the service needs are requested.
A service assistant answers in the citizen's language from approved sources, or opens the right online form.
Known data is fetched once from authentic sources and shown to the citizen to confirm.
The request reaches the right team with its history, so nobody asks the same question twice.
Human checkpoint. Staff handle exceptions and anything that needs judgement. The assistant never decides on rights or benefits.
Status and decision arrive in the citizen's digital mailbox, with a clear route to object or appeal.
Applications arrive by portal, email or post. Scanned post joins the same queue.
Documents are classified and key fields extracted, each with a confidence score.
Rules check what is missing and draft a request for further information.
Human checkpoint. A caseworker validates uncertain fields and takes the decision. Suggestions are labelled as suggestions.
The decision, its rationale and the data used are written to the case system and the audit log.
Corrections feed the evaluation set, so quality is measured release after release.
Case management, citizen and business contact centres and grant processes, integrated with back-office registers and national identity services.
Finance, HR and procurement for administrations, and connecting SAP to case systems and data platforms without destabilising the core.
A pragmatic back office for smaller public bodies, agencies and intermunicipal partnerships, with open-source licensing options to assess.
Partner levels are those held by FromNine. Product names are trademarks of their respective owners.
International
Many programmes we are asked about cross borders: an agency serving users in several Member States, a shared service for regions with different languages, or a procedure in scope of the Single Digital Gateway. The EU layer is common, from the Interoperable Europe Act to eIDAS 2, but NIS2 transpositions, accessibility laws, identity schemes and procurement rules differ per country.
We design one architecture that keeps those differences in configuration and documentation rather than in separate code bases, reuse what Interoperable Europe and national catalogues already offer, and plan content and documentation for the languages each authority works in.
Our experience spans 600+ European government projects, delivered and ongoing, for public bodies across the European Union. We do not name public bodies without their permission. References are discussed within procurement procedures, under the conditions the contracting authority sets.
Tell us which framework, lot or purchasing system you buy through. We will confirm whether and how we can take part, directly or within a consortium.
We classify the use case during discovery. Where it is high-risk, such as deciding on access to benefits, we design human oversight, logging and documentation into the system and prepare input for your fundamental rights impact assessment.
Where you decide. We design for EU data residency and agree hosting locations, encryption key control and support locations with you before build, including sovereign options where required, and document them in the architecture.
Yes. We design and test to WCAG 2.2 AA, the level behind EN 301 549, combine automated and manual testing and help you maintain the accessibility statement.
Yes. Multilingual services are standard in our public-sector work: interfaces, content, assistants and documentation in the official languages your users need, with the same quality in each. Our teams work in your language: Dutch, French, German, English and other European languages.
Preparing a tender, a modernisation or an AI service under the AI Act? Talk to a team that knows procurement rules, accessibility law and multilingual public services across Member States.