Government and public sector
Government Software Development
We have already shipped for a government client: an EU co-financed mobile and web application for the Provincial Secretariat for Urban Planning, built over a multi-year engagement. We also build and run our own products, including Arhivix, the document platform 500+ companies archive on. Public bodies are not buying adjectives. They are buying a team that can clear an accessibility audit, survive a supplier security questionnaire, and still ship something citizens will actually use.
The problem
Where government teams get stuck.
The spec is frozen before anyone talks to a user
Above the 2026-2027 EU procurement thresholds, currently EUR 140,000 for central government supplies and services and EUR 216,000 for sub-central contracting authorities, the full tendering regime applies and the technical specification has to be written into the tender documents.
So the solution design gets locked months before the first sprint, by people who have not yet watched anyone use the thing. The rest of the contract is then spent pushing every real discovery through a change control board.
Accessibility surfaces at UAT instead of at design
Public sector sites and apps must publish an accessibility statement and run a feedback mechanism, and member states monitor them and report to the Commission every three years against harmonised standard EN 301 549.
Automated scanners only cover part of the criteria. Keyboard focus order, form error handling, screen reader semantics, tagged PDFs, and native app labels all need manual testing, and every one of them is far more expensive to retrofit after the UI has been signed off.
The identity layer is changing under live services
Member states must provide EU Digital Identity Wallets to citizens by the end of 2026, and service providers legally obliged to identify their customers will have to accept the wallet for authentication.
A portal whose authentication stack ends at SAML federation with a national eID now needs a full relying party build: registration and scope declaration with the competent authority, presentation flows, wallet attestation checks, and real-time credential revocation. That work does not fit into a maintenance retainer.
Security duties arrive as a supplier questionnaire
NIS2 lists public administration among the sectors of high criticality and requires covered entities to address cybersecurity risk in their supply chains and supplier relationships.
The practical effect is that your obligations become your vendor obligations. If the agency owes an early warning 24 hours after becoming aware of an incident, the system has to be built so that someone can actually reconstruct what happened inside 24 hours. Most legacy portals cannot.
What we build
How we solve it.
Compliance
The rules that shape the build.
eIDAS 2.0 and the EU Digital Identity Wallet
Regulation (EU) 2024/1183 amended eIDAS and created the European Digital Identity Wallet. The European Commission states that member states must provide EU Digital Identity Wallets to citizens by the end of 2026, and that service providers legally obliged to identify their customers unequivocally will be obliged to accept the wallet for authentication.
For a relying party that means four concrete workstreams: registration with the competent authority in your member state, including the exact attribute scopes you are permitted to request, since a wallet will refuse anything outside them; OID4VP presentation flows for same-device, cross-device, and offline use; credential handling for both SD-JWT VC and ISO/IEC 18013-5 mDL, because you do not get to choose the format the issuer used; and trust verification, meaning wallet attestation checks plus status list lookups for revocation.
The technical build is bounded, roughly six months for a focused team. Procurement in front of it is usually the longer half of the calendar, which is why scoping in 2026 matters more than building in 2027.
Web Accessibility Directive and EN 301 549
Directive (EU) 2016/2102 covers public sector websites and mobile applications. Per the Commission, bodies must publish an accessibility statement and provide a feedback mechanism, member states run regular monitoring and report to the Commission every three years, and harmonised standard EN 301 549 v3.2.1 gives presumption of conformity.
Two details decide whether a project passes. First, EN 301 549 is broader than a website: it reaches native mobile applications and published documents, so an untagged PDF library and an app that never had a screen reader pass are both findings. Second, conformance is evidence-based. A monitoring body asks what was tested, by whom, with which assistive technology, and against which success criteria. Teams that only ran an automated scanner have nothing to hand over.
We build the component library to the standard, test with keyboard and screen reader on real content, and deliver the audit trail alongside the software.
NIS2 and supply chain security
Public administration sits among the sectors of high criticality under NIS2, covered entities must address cybersecurity risk in supply chains and supplier relationships, and the reporting duty runs in three stages: early warning within 24 hours of becoming aware of a significant incident, notification within 72 hours, and a final report within one month.
That converts directly into build requirements for whoever writes your code. A software bill of materials for everything delivered. Static analysis and dependency scanning in the pipeline, not as an annual event. Documented remediation timelines by severity. Multi-factor authentication and least-privilege access as defaults. And logging designed backwards from the reports: if your team cannot assemble a defensible 72-hour assessment from the system itself, the logging design failed.
We treat these as architecture, not as a security annex written after handover, and we are happy to have them written into the contract.
Procurement, GDPR, and records obligations
Directive 2014/24/EU governs public tenders above the thresholds set for 2026-2027 by Commission Delegated Regulation (EU) 2025/2152: EUR 140,000 for central government supplies and services, EUR 216,000 for sub-central contracting authorities, and EUR 750,000 for Annex XIV services. Below those, national transparency and documented selection rules still apply.
Then the layers stack: GDPR data minimization and defined retention for every citizen record, national archiving law for anything with a legal retention duty, freedom of information retrieval, and the European Interoperability Framework pushing open standards and documented APIs so a neighboring agency can consume your data later.
None of that is paperwork. It is data architecture, and it has to be right early. Retrofitting a retention or audit model into a live registry is expensive precisely because the data model change drags documentation, approvals, and re-testing behind it.
Proof
Products we have shipped.
Related reading
FAQ
Common questions.
Let's talk
Planning a public sector build or a wallet integration?
Book a free 30-minute consultation. Bring the tender documents, the accessibility findings, or the 2026 eIDAS deadline you are staring at, and you get an honest read on scope, sequencing, and whether we are the right team for it. No sales pitch.
Book a Free Consultation


