The framework asks for systems. Not only policies.

    DORA, MiCA, KYC/AML, PCI-DSS and GDPR are argued in legal. They fail in the stack. This guide splits what must be adapted technically from what is not ours to do.

    A Fintech or LegalTech does not “have a compliance project”. It has a product that moves money, identity or documents, and a supervisor — or an investor — who will ask how it is built. Adapting technology to the framework is not translating the gazette into a spreadsheet. It is deciding what changes in identity, data, continuity, records and vendors, and doing it at a pace that survives the next change. Orbit works that stretch. The opinion, no.

    Why the stack decouples from the rule

    The product grows every sprint. The framework updates in waves. In between, engineering ships features and legal ships memos. Nobody owns the seam. Access nobody revoked, logs that cannot serve as evidence, a processor in a country the DPA never named, a runbook that lives in one person’s head.

    That gap does not close with a workshop. It closes by touching systems and leaving a trail. And it reopens if nobody watches. That is why a one-off project — however good the report — does not hold the orbit of a regulated company.

    What the framework usually asks of the system (not the lawyer)

    DORA, in operational substance, is about ICT: risk, incidents, tests, critical third parties. That becomes inventory, access, backups, observability and technical contracts with vendors. MiCA adds information and control duties on crypto-assets: traceability, custody, reporting. KYC/AML and PCI touch identity, retention and payment-data segmentation. GDPR and, in investment, MiFID, touch stores, consent and audit trails.

    None of those acronyms “installs”. Each implies change in the same perimeter: who gets in, which data lives where, what is recorded and who answers when it fails. The typical error is buying a tool per acronym. The real work is ranking gaps in that perimeter and closing them in order.

    A sequence you can operate

    First, know which framework actually applies — not the one on a generic list. The Orbit diagnostic estimates sector, geography and an order of magnitude for cost and risk. It is not a legal analysis. It is a thermometer so you do not start the RFP in the wrong place.

    Second, a technical audit with depth by plan: security and access, data, CI/CD, infra and, when scope includes it, code. Third, an action plan implemented on cadence (monthly, biweekly or weekly). Fourth, monitoring: what changed in the gazette and what changed in your stack, in the same cycle.

    What we do not do — and why that protects you

    We do not certify compliance. We do not issue opinions. We do not replace the DPO or the firm. If someone sells you “DORA-ready with a stamp”, read the small print. You remain responsible for compliance. We leave the system more aligned and the technical evidence a counsel or auditor can use.

    That honesty shortens sales and avoids surprises in supervision. The client who wants a stamp should go to a body. The one who wants the product to stop being the framework’s blind spot should go to a partner who implements.

    Signals the problem is already technical

    Policies are current and controls nobody can show in the system. The last incident was reconstructed from Slack. A critical vendor is missing from the inventory. Employee onboarding takes longer in access than in the contract. Customer data lives in three stores and nobody knows the source.

    None of those sentences is fixed with another presentation. They are fixed in the cycle: priority, owned delivery, evidence, next priority. That is Orbit for regulated companies.

    Cycle

    From the acronym to a change in the system.

    Phase 01

    Applicable framework

    Sector, markets and an order of magnitude. Orientative diagnostic, not an opinion.

    Phase 02

    Technical audit

    Access, data, CI/CD and infra. Depth by plan. Fixed initial cost.

    Phase 03

    Implementation

    Controls and stack changes on cadence. One owner, not three vendors.

    Phase 04

    Monitoring

    The gazette and the system, in the same cycle. Re-prioritise when the business asks.

    Questions

    Scope, clearly.

    Do you cover every framework at once?

    No. We prioritise the one that moves the most technical risk now. The rest enters later cycles. A “compliance big bang” is the opposite of Orbit.

    Do you only work in Spain?

    We operate from Seville for companies across Spain. The applicable framework may include the EU; local opinion, if needed, is your counsel’s.

    What banking experience do you have?

    A track record in banking and regulated environments. That is not a stamp: it is judgement so we do not treat a Fintech like generic SaaS.

    What if we already have ISO or SOC?

    Good. We use that evidence. Systems still need adapting when the product or the vendor changes. The certificate does not operate the stack.

    Let's put your business in orbit.

    Initial audit, monthly plan and clear cadence to adapt your technology to what the framework requires. Proposal in 48 business hours.