Skip to content
Sixteen Pillars.
  • Framework
    • Blast Radius
    • Full Governance by Sixteen Pillars
    • State of the Estate
  • Capabilities
    • Services
  • Thinking
    • Topics
  • Who
  • Studio
  • Let’s talk

EU Regulation

DAC8 Live: Crypto-Asset Tax Reporting From 1 January 2026 in Code

August 25, 2026 by Richard King

DAC8 crypto-asset reporting applies from 1 January 2026 with first exchange by 30 September 2027. A practitioner’s guide to building and validating the CARF-aligned XML report in code.

Categories EU Regulation Tags Crypto & Digital Assets, Cyprus, DAC8 & CARF, MiCA

IDD Product Oversight and Governance: Turning POG Into a Product-Data Control, Not a Committee Minute

August 20, 2026 by Richard King

IDD’s product oversight and governance duties are usually discharged as committee minutes. Encoded as tracked product-lifecycle data, they become demonstrable to a supervisor rather than anecdotal.

Categories EU Regulation Tags Data Governance, EBA & EIOPA, European Union, Insurance, Manufacturing

NIS2 Registration: Getting Your Entity Onto the National Register Before the Regulator Finds You

August 18, 2026 by Richard King

NIS2 registration is a self-identification duty, not an invitation. Work out scope by sector and size, register across the member states you serve, and understand what the filing discloses and commits you to before an authority names you first.

Categories EU Regulation Tags ENISA & CSIRT Reporting, European Union, Manufacturing, NIS2

Mapping Your ICT Subcontracting Chain Under the DORA Subcontracting RTS

August 18, 2026 by Richard King

The DORA subcontracting RTS forces you to model the full chain supporting critical functions. That is a graph-data and monitoring problem, not a contract-review one.

Categories EU Regulation Tags Banking, Concentration & Exit Risk, Dependency Management, DORA, European Union, RTS & ITS, Third-Party Risk

Accessibility for Self-Service Terminals and Apps Under the EAA: The Hardware-Plus-Software Scope

August 18, 2026 by Richard King

The EAA is not just a website obligation. It reaches ATMs, ticketing machines, payment terminals, e-readers and mobile apps. Here is how to inventory the in-scope estate and what each device type actually demands.

Categories EU Regulation Tags Cyber Resilience Act, European Accessibility Act, European Union, Retail & E-Commerce, Supply Chain Security

The European Accessibility Act Is Live: Turning WCAG 2.1 AA Into a CI Gate, Not a Year-End Audit

August 17, 2026 by Richard King

The European Accessibility Act has applied since June 2025. How to wire WCAG 2.1 AA checks into CI so builds fail on violations, and how to define the manual-test residual automation cannot see.

Categories EU Regulation Tags Business Intelligence, DevOps & CI/CD, European Accessibility Act, Maritime & Shipping

DORA Incident Classification Thresholds in Code: Turning the RTS into a Decision Engine

August 18, 2026August 17, 2026 by Richard King

DORA’s classification RTS gives quantitative thresholds for major incidents. Encode them as a decision engine so triage is deterministic, auditable and not a judgement call at 2am.

Categories EU Regulation Tags Banking, DORA, Operational Resilience, Regulatory Reporting, RTS & ITS

Data Altruism Organisations: The Consent, Logging and Security Rulebook Under the DGA

August 18, 2026August 14, 2026 by Richard King

Recognised data altruism status under the EU Data Governance Act rests on engineering controls. Here is the consent ledger, access logging and security you must build to register defensibly.

Categories EU Regulation Tags Backup & Recovery, Consent & Privacy Operations, Data Governance, European Union, GDPR

IReF: Why the ECB’s 2031 Timeline Still Means Starting Your Data Model Now

August 18, 2026August 13, 2026 by Richard King

First official IReF reporting is Q2 2031 with a 2030 pilot, and that distance breeds complacency. The semantic-model work that makes IReF cheap must start years earlier.

Categories EU Regulation Tags Banking, Data Governance, Data Lineage, ECB & SSM Supervision, European Union, Regulatory Reporting

EHDS Secondary Use: Preparing Health Data for the Access Bodies Without Breaching GDPR

August 18, 2026August 13, 2026 by Richard King

EHDS secondary use will require health-data holders to hand structured, described, quality-labelled datasets to the access bodies. The engineering for that is a multi-year programme, and it starts well before the 2029 obligations bite.

Categories EU Regulation Tags Data Lineage, European Health Data Space, European Union, GDPR, Healthcare
Older posts
Page1 Page2 … Page7 Next →
Sixteen Pillars
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
Storing your preferences — such as language or display settings — so the site works as you left it. These cookies are set automatically and do not require your consent.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. Some storage is set automatically to keep the site functioning — not based on your choices, but on technical requirements. This includes things like load balancing and session continuity.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}

Sixteen Pillars Technology Control Framework

About the framework Full pillar index



The Sixteen Pillars

  1. Asset & Estate Visibility
  2. Architecture Comprehension
  3. Data Trust & Lineage
  4. Dependency Mapping
  5. Decision Rights & Accountability
  6. Change Governance
  7. Investment & Portfolio Control
  8. Supplier & Third-Party Control
  9. Security Posture
  10. Identity & Access Control
  11. Resilience & Continuity
  12. Operational Capability
  13. Regulatory Adaptability
  14. Scalability & Performance Headroom
  15. Technical Debt & Sustainability
  16. Adaptability & Strategic Optionality

Services

  • All services
  • Fractional CTO
  • Technology Control Assessment
  • Technology Due Diligence
  • First 90 Days
  • Architecture Review
  • Pricing
  • Studio — build & rescue

Regulations

  • All regulations
  • DORA
  • MiCA
  • NIS2
  • EU AI Act
  • DORA ICT Third-Party Risk

Sectors

  • All sectors
  • Financial Services
  • Shipping & Maritime
  • iGaming
  • Digital Assets
  • Legal
  • eCommerce
  • Healthcare & Medical
  • Engineering

Company

  • About
  • Approach
  • Writing
  • Topics
  • Thinking
  • Control Matrix
  • Start a conversation
Cookie Policy Accessibility Statement

© Sixteen Pillars 2012 – 2026. All Rights Reserved.