SCRIP Project No. 101145849 — Digital Europe Programme (DIGITAL-ECCC-2022-CYBER-B-03) — SmarTech-IT Sp. z o.o.
One year ago, the SCRIP project set out to close a gap that has quietly undermined European cyber resilience for years: small and medium-sized enterprises are now legally accountable for cybersecurity outcomes under the NIS2 Directive and GDPR Article 32, but almost none of them have access to the continuous, evidence-based visibility that large enterprises take for granted. Twelve months in, that gap is closing — not with a slide deck, but with a working platform, real telemetry, and a team that has treated architecture discipline as a feature rather than a delay.
Here is what that first year delivered.
Rather than racing into feature development, the team spent the opening months doing something less visible but far more durable: freezing the architecture before writing production code. Eighteen work packages, structured around an architecture-first execution model, carried the project from repository setup through eight verifiable delivery milestones. Nineteen architectural nodes were fully defined and documented, and a complete Architecture Decision Record pack locked in every core technology choice the platform depends on. It’s the kind of groundwork that doesn’t show up in a demo but prevents the far more expensive rework that comes from building fast and guessing wrong.
SCRIP’s credibility rests more than architecture diagrams. More than twenty (20) SMEs (Small-Medium-sized Enterprises) concentrated on healthcare, logistics, and critical infrastructure — are under signed SOC Service Agreements today, generating the live evidence base the programme reports against. Behind that pilot sits a deliberately sustainable staffing model: a 24×7 Security Operations Centre with day and evening shifts physically staffed, and overnight coverage handled through automated alerting with senior analysts on call. It’s a design built to hold up under real operational load, not just looking good on a coverage chart.
SCRIP’s roadmap includes a clear path toward predictive, AI-assisted risk forecasting — but the project has deliberately sequenced governance ahead of capability. Any machine-learning output will remain non-authoritative until it clears a formal, multi-stage promotion framework and receives explicit sign-off, with EU AI Act documentation already underway well ahead of the point where it becomes mandatory. It’s a slower path to AI-assisted scoring, and a deliberately more defensible one.
The remainder of this year is about proving the platform under real conditions: bringing pilot tenants’ live telemetry fully onto the platform, running a full penetration test, and assembling the validated deliverable package the EU expects. Beyond that, SCRIP’s roadmap turns toward cross-border interoperability with EU CERTs, full production compliance validation against NIS2, GDPR, and ISO 27001, and the first steps of the predictive analytics phase — always inside the governance guardrails already built.
A year in, the honest summary is this: the unglamorous work of freezing an architecture and building a real pilot before chasing a demo has paid for itself. SCRIP is no longer a proposal. It has real SMEs, a real SOC standing behind them, a European partner path opening up, and a credible route to the scale the Digital Europe Programme funded it to reach.
Funded by the European Union. Views and opinions expressed are those of the author only and do not necessarily reflect those of the European Union or the European Cybersecurity Competence Centre (ECCC). Neither the European Union nor the ECCC can be held responsible for them.