Skip to main content
FromNine
Menu

Public Sector & Government

Built for public accountability.

We design, build and run digital services for public bodies: accessible by law, secure by default, interoperable by design and documented well enough to outlast the contract. 600+ European government projects for public bodies across the European Union have shaped how we work.

For ministries, agencies, regions and municipalities across Europe that must serve every citizen, in every official language, under EU and national rules at once.

Geometric stone and glass façade of a modern public building
  1. 28 June 2025

    European Accessibility Act applies

    Accessibility duties now reach key private services, alongside the rules public bodies already follow.

    SourceDirective (EU) 2019/882 (opens external site)

  2. 24 December 2026

    EU Digital Identity Wallets due

    Every Member State must offer at least one wallet, and public services must accept it.

    SourceRegulation (EU) 2024/1183 (opens external site)

  3. 2 December 2027

    AI Act high-risk duties apply

    Including the fundamental rights impact assessment for public deployers, as amended in 2026.

    SourceRegulation (EU) 2024/1689 (opens external site)

600+European government projects

  • Public bodies across the European Union

Credentials

  • ISO/IEC 27001 certifiedCertified information security management
  • Summit Partner · SalesforceOn the platforms many administrations already run
  • Gold Partner · SAP and OdooOn the platforms many administrations already run

What is changing for public bodies

  1. Regulation is landing all at once

    The AI Act, NIS2, eIDAS 2, the Interoperable Europe Act and the Data Act reach the same IT estates within a few years. Each adds documentation, risk and reporting duties, and tenders now ask suppliers to show how they support them.

    SourceEU digital rulebook overview

  2. Citizens expect one front door

    People expect to apply, follow up and receive decisions online, in their own language, without supplying the same evidence twice. For key cross-border procedures, once-only is already an obligation.

    SourceRegulation (EU) 2018/1724

  3. Knowledge is retiring

    Experienced caseworkers and the engineers who know the legacy code are leaving faster than they can be replaced. What lives in people and old systems has to move into documented services and tools the next generation can work with.

  4. AI under public scrutiny

    AI can shorten queues and backlogs, but a public body must be able to explain a decision, keep a named person accountable and disclose the systems it uses. That changes how AI is designed, not only how it is bought.

Challenges and our response

  1. The challenge

    Core case systems are decades old, and every legal change means a risky release.

    Our response

    We modernise in steps behind stable interfaces: extract services, migrate data with reconciliation and retire modules one at a time. Citizens are spared a big-bang switchover.

  2. The challenge

    Citizens and businesses supply the same evidence again and again.

    Our response

    We connect services to authentic sources and national data exchange platforms, so data is fetched once, with a legal basis, and every access is logged.

  3. The challenge

    Contact centres absorb questions the website should answer.

    Our response

    Multilingual service assistants grounded in your published rules and procedures, with a clear handover to staff and no answers outside approved sources.

  4. The challenge

    Caseworkers lose hours reading, sorting and re-keying incoming files.

    Our response

    Document intelligence classifies and extracts, a person validates uncertain fields and the case system receives structured data with a full audit trail.

  5. The challenge

    AI pilots stall at legal and ethics review.

    Our response

    We design for review from discovery onwards: risk classification, input for the data protection and fundamental rights impact assessments, logging, human oversight and documentation for transparency registers.

  6. The challenge

    Policy knowledge is scattered across intranets, PDFs and people.

    Our response

    Permission-aware knowledge search that cites the regulation, circular or procedure behind every answer, so staff can check before they act.

The regulatory timeline public services are built against

Dates that shape architecture and procurement decisions now. National transpositions and implementing acts can add their own dates.

  1. In application

    Interoperable Europe Act: Regulation applies

    A governance framework for cross-border interoperability and the reuse of public-sector solutions.

  2. In application

    NIS2: National NIS2 rules apply

    National laws apply as each is adopted. Public administration entities come into scope, with risk management and incident reporting duties.

  3. In application

    Interoperable Europe Act: Interoperability assessments required

    Before deciding on new or substantially changed trans-European digital public services.

  4. In application

    AI Act: Prohibited AI practices banned

    Including social scoring by public authorities. AI literacy duties start on the same date.

  5. In application

    European Accessibility Act: Accessibility requirements apply

    For key products and services, through national laws.

  6. In application

    Data Act: Data Act applies

    Including data requests by public bodies in cases of exceptional need and cloud switching rules.

  7. In application

    AI Act: Transparency obligations apply

    People must be told when they interact with an AI system, and generated content must be marked.

  8. Status as of 2 October 2026

  9. Upcoming

    eIDAS 2: EU Digital Identity Wallets available

    Each Member State offers at least one wallet; public services that require online identification must accept it.

  10. Upcoming

    AI Act: High-risk obligations apply

    For stand-alone high-risk uses such as access to public services and benefits, as amended in 2026.

Regulation and standards reference

The instruments that most often shape a public-sector specification, in plain words, with what each one means for the programme.

This overview supports planning conversations. It is not legal advice, and national transpositions differ. Dates reviewed on 2 October 2026.

EU AI ActScopeEU-wide

Risk-based rules for AI systems. AI used to decide on access to essential public services and benefits, migration, asylum and border control, justice and law enforcement is listed as high-risk.

Public bodies that deploy high-risk systems must carry out a fundamental rights impact assessment (Article 27), assign human oversight and keep logs. Under the Act as amended in 2026, these duties apply from 2 December 2027.

What it means for your programme

We classify each use case during discovery, build oversight and logging into the system and prepare the technical documentation your legal team needs. The legal assessment stays with your own counsel.

SourceRegulation (EU) 2024/1689, EUR-Lex (opens external site)

NIS2ScopeEU-wide

Central government administrations are in scope, and Member States may add regional and local administrations. Duties cover risk management, supply-chain security and staged incident reporting, starting with an early warning within 24 hours.

What it means for your programme

Expect security clauses in every contract. We document our controls, report incidents through the agreed channels and give you the evidence your own supervisory duties require.

SourceDirective (EU) 2022/2555, EUR-Lex (opens external site)

eIDAS 2 and the EU Digital Identity WalletScopeEU-wide

Each Member State must offer at least one EU Digital Identity Wallet by 24 December 2026. Public services that require electronic identification must accept it, next to national eID schemes.

What it means for your programme

Login, attribute sharing and electronic signatures have to work with the wallet. We design identity integration so a new credential type is configuration, not a rebuild.

SourceRegulation (EU) 2024/1183, EUR-Lex (opens external site)

Interoperable Europe ActScopeEU-wide

Applies since 12 July 2024. Since 12 January 2025 public bodies must carry out an interoperability assessment before deciding on new or substantially changed trans-European digital public services, and are encouraged to share and reuse solutions, including open source.

What it means for your programme

We prepare the assessment input with you, reuse existing building blocks and document interfaces so others can adopt what you build.

SourceRegulation (EU) 2024/903, EUR-Lex (opens external site)

Single Digital Gateway and once-onlyScopeEU-wide

Since 12 December 2023, users of key cross-border procedures can ask for evidence to be exchanged directly between authorities through the Once-Only Technical System, instead of uploading it themselves.

What it means for your programme

Evidence exchange must be consent-based, previewable and logged. We integrate national data exchange platforms and once-only connectors into the service flow.

SourceRegulation (EU) 2018/1724, EUR-Lex (opens external site)

Web Accessibility Directive and EN 301 549ScopeEU-wide

Public-sector websites and mobile apps must meet the harmonised standard EN 301 549, which builds on WCAG, and publish an accessibility statement with a feedback mechanism. National laws transpose it, for example BITV 2.0 in Germany.

What it means for your programme

We build to WCAG 2.2 AA, test with assistive technology and help you keep the accessibility statement accurate.

SourceDirective (EU) 2016/2102, EUR-Lex (opens external site)

European Accessibility ActScopeEU-wide

Applies since 28 June 2025 to key products and services such as banking, e-commerce, e-books and transport services. It applies to economic operators, not to public bodies directly, but public procurement uses its accessibility requirements and services run with private partners may be in scope.

What it means for your programme

Accessibility now runs through the whole delivery chain. We make it part of the acceptance criteria, not a late audit.

SourceDirective (EU) 2019/882, EUR-Lex (opens external site)

Data ActScopeEU-wide

Applies since 12 September 2025. Public bodies can request data held by companies in cases of exceptional need, and data processing services must make switching provider possible, with switching charges phased out by January 2027.

What it means for your programme

We design exit plans and data portability into cloud architectures, so changing provider is a planned project rather than a crisis.

SourceRegulation (EU) 2023/2854, EUR-Lex (opens external site)

Procurement by the rules, lot by lot.

Public bodies buy through open, restricted and negotiated procedures, competitive dialogue and framework agreements with mini-competitions. The rules follow Directive 2014/24/EU and its national transpositions, each with its own documents, contract terms and timelines.

We work within those rules: requirement-by-requirement answers, named team members, transparent pricing structures and delivery plans an evaluation committee can score. We take part directly or within a consortium, depending on the lot.

  1. Market consultation

    We share what is technically realistic without steering the specification. Early dialogue reduces the risk of tenders nobody can deliver.

  2. Tender and clarifications

    We read the specification against the law, the standards and your existing estate, and ask questions through the official channel only.

  3. Offer

    A structured response: architecture, plan, team, security and accessibility approach, and an exit plan from the start.

  4. Award and mobilisation

    After the standstill period: named people, onboarding to your security rules and an agreed first release.

  5. Delivery and exit

    Reporting against contract indicators, documented handover and data return, so the next procurement starts from a clean position.

Sovereignty and security

Data residency by design

Hosting regions, encryption key control and support access locations are decided with you before build and written into the architecture.

Exit plans built in

Open standards, documented data models and infrastructure as code keep switching costs visible, as the Data Act intends.

Open source where it fits

We assess reusable public components and open-source options first, in line with national open-source policies and the Interoperable Europe Act.

Certified security management

FromNine is ISO/IEC 27001 certified. Controls, supplier management and incident handling follow a certified information security management system.

NIS2-aware delivery

Incident channels, vulnerability handling and supply-chain transparency are agreed per contract, so you can meet your own NIS2 duties.

Interoperability and once-only

Illustrative example
Citizen or businesseID or EU DigitalIdentity WalletService portalService assistantCase systemCaseworker reviewAccess logOnce-Only TechnicalSystemNational data exchange platformOther Member StatePopulation registerBusiness registerTax and benefitsdata
How a once-only service fits together

Identity, the service front end and the case system sit on top of a data exchange layer that reads from authentic sources.

Read the diagram as text

A citizen or business signs in to a service portal with a national eID or an EU Digital Identity Wallet. A service assistant can answer questions and open the right form.

The portal passes the request to the case system, where a caseworker reviews exceptions and takes decisions.

Portal and case system read the data they need through a national data exchange platform. The platform fetches data from authentic sources such as the population register, the business register and tax and benefits data, and writes every access to a log.

For cross-border procedures the exchange platform connects to the Once-Only Technical System, which exchanges evidence with authorities in other Member States.

  • Authentic sources, not copies

    Services fetch data from the register that owns it, through national exchange platforms, instead of keeping their own copies.

  • Standards first

    The European Interoperability Framework, national reference architectures and semantic standards shape the interfaces we design.

  • Legal basis and logging

    Every exchange has a legal basis, a purpose and a log entry that citizens and auditors can trace.

  • Cross-border ready

    Procedures in scope of the Single Digital Gateway connect to the Once-Only Technical System through national access points.

Accessibility as law

  • WCAG 2.2 AA as the floor

    EN 301 549 builds on WCAG. We design and test to WCAG 2.2 AA, so services meet today's rules and the next revision.

  • Tested with tools and people

    Automated checks in the delivery pipeline, manual audits with screen readers and keyboard, and usability sessions with disabled users wherever you can arrange them.

  • Plain language in every official language

    Content written for the reader's task, with the same quality in each language the service must support.

  • Statements that stay true

    We help you keep the accessibility statement and feedback route accurate as the service changes.

Read our accessibility statement

Digital identity

  • National eIDs today

    Integration with national schemes such as the Belgian eID and itsme, DigiD and eHerkenning, BundID, FranceConnect, Cl@ve, SPID and CIE, through their official brokers.

  • The EU wallet next

    Wallet login and verifiable attestations added alongside existing schemes, so citizens choose and services do not fork.

  • Least data, clear consent

    Request only the attributes a service needs, show the citizen what is shared and keep a record.

  • Mandates and representation

    Acting on behalf of a company or another person, which most benefit and permit processes need.

Government segments we build for

  • Social security and employment

    Benefits, contributions and employment services, where decisions affect livelihoods and every step must be explainable.

  • Local and regional government

    Permits, local taxes, citizen contact and shared services between municipalities.

  • Justice and public safety

    Case and document flows with strict access control, retention rules and chain-of-custody logging.

  • Education and research

    Student administration, grant management and research data services.

  • Central government and agencies

    Shared platforms, registers and back-office systems used across ministries.

Illustrative use cases

Illustrative example
  1. Benefit application intake

    Applications and supporting documents are classified and checked for completeness. Caseworkers review flagged items before any decision is made.

  2. Multilingual citizen information assistant

    Answers questions about procedures in the official languages of the region, cites the page it relied on and hands over to staff when a question needs judgement.

  3. Policy and regulation search for staff

    Officers search circulars, procedures and case law in one place. Results respect access rights, and every answer links to its source.

  4. Phased replacement of a permit system

    A legacy permit application is replaced module by module behind a stable API, with data reconciled at every step and the old system retired last.

  5. Freedom-of-information request handling

    Requests are logged, relevant documents located and redaction proposals prepared. An officer approves every release.

Two flows, end to end

How the parts work together in daily operation. These are illustrative workflows, not client cases.

Citizen service: from question to resolved request

Illustrative workflow
  1. Step 01Sign in

    The citizen signs in with a national eID or an EU Digital Identity Wallet. Only the attributes the service needs are requested.

  2. Step 02Ask or apply

    A service assistant answers in the citizen's language from approved sources, or opens the right online form.

  3. Step 03Prefill from sources

    Known data is fetched once from authentic sources and shown to the citizen to confirm.

  4. Step 04Route with context

    The request reaches the right team with its history, so nobody asks the same question twice.

  5. Step 05Staff decide

    Human checkpoint. Staff handle exceptions and anything that needs judgement. The assistant never decides on rights or benefits.

  6. Step 06Inform

    Status and decision arrive in the citizen's digital mailbox, with a clear route to object or appeal.

Case processing: from incoming file to accountable decision

Illustrative workflow
  1. Step 01Receive

    Applications arrive by portal, email or post. Scanned post joins the same queue.

  2. Step 02Classify and extract

    Documents are classified and key fields extracted, each with a confidence score.

  3. Step 03Check completeness

    Rules check what is missing and draft a request for further information.

  4. Step 04Officer review

    Human checkpoint. A caseworker validates uncertain fields and takes the decision. Suggestions are labelled as suggestions.

  5. Step 05Record

    The decision, its rationale and the data used are written to the case system and the audit log.

  6. Step 06Measure

    Corrections feed the evaluation set, so quality is measured release after release.

Platforms in the public sector

  • Salesforce

    Summit Partner

    Case management, citizen and business contact centres and grant processes, integrated with back-office registers and national identity services.

  • SAP

    Gold Partner

    Finance, HR and procurement for administrations, and connecting SAP to case systems and data platforms without destabilising the core.

  • Odoo

    Gold Partner

    A pragmatic back office for smaller public bodies, agencies and intermunicipal partnerships, with open-source licensing options to assess.

Partner levels are those held by FromNine. Product names are trademarks of their respective owners.

International

A shared EU layer, national rules on top

Many programmes we are asked about cross borders: an agency serving users in several Member States, a shared service for regions with different languages, or a procedure in scope of the Single Digital Gateway. The EU layer is common, from the Interoperable Europe Act to eIDAS 2, but NIS2 transpositions, accessibility laws, identity schemes and procurement rules differ per country.

We design one architecture that keeps those differences in configuration and documentation rather than in separate code bases, reuse what Interoperable Europe and national catalogues already offer, and plan content and documentation for the languages each authority works in.

Frequently asked questions

What public-sector experience do you have?

Our experience spans 600+ European government projects, delivered and ongoing, for public bodies across the European Union. We do not name public bodies without their permission. References are discussed within procurement procedures, under the conditions the contracting authority sets.

Can we buy through our framework agreement?

Tell us which framework, lot or purchasing system you buy through. We will confirm whether and how we can take part, directly or within a consortium.

How do you handle the AI Act in public services?

We classify the use case during discovery. Where it is high-risk, such as deciding on access to benefits, we design human oversight, logging and documentation into the system and prepare input for your fundamental rights impact assessment.

Where is our data hosted?

Where you decide. We design for EU data residency and agree hosting locations, encryption key control and support locations with you before build, including sovereign options where required, and document them in the architecture.

Do you build to accessibility law?

Yes. We design and test to WCAG 2.2 AA, the level behind EN 301 549, combine automated and manual testing and help you maintain the accessibility statement.

Can services support several official languages?

Yes. Multilingual services are standard in our public-sector work: interfaces, content, assistants and documentation in the official languages your users need, with the same quality in each. Our teams work in your language: Dutch, French, German, English and other European languages.

Discuss your public-sector programme

Preparing a tender, a modernisation or an AI service under the AI Act? Talk to a team that knows procurement rules, accessibility law and multilingual public services across Member States.