Requirements Detail · Technology, Integration & Security

⚙️ Technology, Integration & Security

Platform & environment, user experience, security & compliance, integrations, reporting & analytics, asset management, and project cost management.

80
Total Requirements
42
Mandatory
32
High
6
Desirable
8
Sections
Back to Requirements Overview

Priority Breakdown

Mandatory
42
42
High
32
32
Desirable
6
6

Jump to Section

PLATFORM & ARCHITECTURE

10
Total
7
Mandatory
3
High
0
Desirable
IDRequirementDescriptionPriority
TEC-001 Cloud Deployment Solution must be available as cloud SaaS or PaaS deployment. NordHav strongly prefers SaaS with vendor-managed infrastructure and updates. On-premises deployment is not preferred. Mandatory
TEC-002 Data Residency All production data must be stored within the EU/EEA. Norwegian data residency preferred. Vendor must specify data center locations. Mandatory
TEC-003 Multi-Tenant vs. Single-Tenant Vendor must specify whether the solution is multi-tenant or single-tenant, and describe data isolation mechanisms. High
TEC-004 Scalability Solution must scale to support NordHav's growth plan (50% volume increase over 5 years) without architectural changes. Describe scaling approach (horizontal/vertical). Mandatory
TEC-005 High Availability Minimum 99.5% uptime SLA (excluding planned maintenance windows). Describe HA architecture, failover mechanisms, and maintenance window policy. Mandatory
TEC-006 Disaster Recovery Disaster recovery with: RPO (Recovery Point Objective) < 1 hour, RTO (Recovery Time Objective) < 4 hours. Describe DR strategy and testing frequency. Mandatory
TEC-007 Backup & Restore Automated daily backups with minimum 30-day retention. Support point-in-time restore. Describe backup strategy and customer restore options. Mandatory
TEC-008 Update & Release Management Describe the update/release cycle: frequency (e.g., monthly, quarterly), notification process, testing/sandbox availability, rollback capability, and customer-specific customization impact. High
TEC-009 Sandbox/Test Environment Provide at least 2 non-production environments (test and UAT/staging) with data refresh capability from production. Mandatory
TEC-010 Performance Requirements Define expected system response times for key operations: screen load < 2 seconds, report generation (standard) < 10 seconds, batch jobs (period-end) < 2 hours. High

USER EXPERIENCE & ACCESS

7
Total
3
Mandatory
2
High
2
Desirable
IDRequirementDescriptionPriority
TEC-011 Web-Based UI Fully web-based user interface accessible via modern browsers (Chrome, Edge, Safari, Firefox) without additional client software installation. Mandatory
TEC-012 Mobile Application Native or responsive mobile application for iOS and Android supporting: time registration, leave requests, approval workflows, operational data entry (mortality, feed, lice counts), photo capture, and basic dashboards. Mandatory
TEC-013 Offline Capability Mobile app must support offline operation for: data entry at sea sites (limited connectivity), queue-and-sync when connectivity is restored. Describe conflict resolution for offline scenarios. High
TEC-014 Multi-Language UI UI available in Norwegian Bokmål and English at minimum. Users should be able to switch language independently. Desirable: Nynorsk. Mandatory
TEC-015 Role-Based UI Role-based user interface customization: different dashboards, menus, and data access based on user role (e.g., site manager sees farming data; accountant sees finance; processing supervisor sees production). High
TEC-016 Personalization Users can personalize their workspace: favorite screens, custom dashboard widgets, saved report filters, and notification preferences. Desirable
TEC-017 Accessibility UI complies with WCAG 2.1 Level AA accessibility standards. Desirable

INTEGRATION

13
Total
6
Mandatory
7
High
0
Desirable
IDRequirementDescriptionPriority
TEC-018 API Architecture Comprehensive, documented REST/OData API for: read/write access to all major entities, integration with third-party systems, and custom reporting. Mandatory
TEC-019 Real-Time Integration Support real-time (event-driven) integration via webhooks, message queues, or similar mechanisms for: feeding system data, production line data, and sensor data. High
TEC-020 Batch Integration Support batch/scheduled integration for: bank file exchange, payroll journal import, regulatory reporting file generation, and periodic data synchronization. Mandatory
TEC-021 Integration Middleware Compatibility Compatible with enterprise integration platforms: Azure Integration Services (Logic Apps, Service Bus, API Management), MuleSoft, or equivalent. High
TEC-022 Feed System Integration Specific integration with AKVA group feed control systems (AKVAcontrol): receive feeding data (kg per pen, pellet type, feeding times) and send feeding plans/parameters. Mandatory
TEC-023 Processing Line Integration Integration with Marel Innova processing control system: receive production data (weights, grades, counts, yields) and send production orders/specifications. High
TEC-024 Banking Integration Integration with Norwegian banks (DNB, Nordea): payment file export (pain.001), bank statement import (camt.053/054), and optionally direct bank connectivity. Mandatory
TEC-025 EHF Invoice Integration Integration with PEPPOL Access Point for sending/receiving EHF invoices (Electronic Trading Format per Norwegian e-invoicing standard). Mandatory
TEC-026 Government Portal Integration Integration or data export capability for Norwegian government portals: Altinn (tax returns, A-melding), BarentsWatch (lice/biomass reporting), Mattilsynet (health certificates), and TVINN (customs). High
TEC-027 Power BI Integration Provide a data model, data warehouse, or data export optimized for consumption by Microsoft Power BI for advanced analytics and custom dashboards. High
TEC-028 IoT Data Ingestion Support ingestion of high-volume IoT/sensor data from: water quality sensors, temperature loggers, environmental monitoring stations. Describe data ingestion architecture and data volume limitations. High
TEC-029 Email Integration Integration with Microsoft 365 / Outlook: email correspondence linked to transactions (purchase orders, sales orders, claims), automated email notifications, and calendar integration for scheduling. High
TEC-030 Document Management Integration with or built-in document management: store, retrieve, and version control documents linked to ERP transactions (invoices, POs, quality records, contracts). Mandatory

MAINTENANCE & ASSET MANAGEMENT (CMMS)

10
Total
3
Mandatory
6
High
1
Desirable
IDRequirementDescriptionPriority
TEC-031 Asset Register (Maintenance) Maintain a technical asset register (linked to financial asset register): asset hierarchy, location, specifications, manufacturer, serial/model numbers, warranty, and criticality classification. Mandatory
TEC-032 Preventive Maintenance Create and manage preventive maintenance schedules: frequency (time-based or usage-based), task descriptions, required spare parts, estimated labor, and safety precautions. Mandatory
TEC-033 Work Order Management Full work order lifecycle: request → creation → planning → scheduling → parts reservation → execution → completion → close-out. Support corrective (reactive) and planned work orders. Mandatory
TEC-034 Mobile Maintenance Mobile capability for maintenance technicians: receive work orders, record tasks completed, register spare parts used, capture photos, and close work orders from the field. High
TEC-035 Equipment Downtime Tracking Record and analyze equipment downtime: planned vs. unplanned, duration, root cause, and production impact. Link to work orders. High
TEC-036 Spare Parts Link Link maintenance work orders to spare parts inventory: automatic reservation upon work order creation, consumption recording, and automatic reorder when stock depletes. High
TEC-037 Maintenance KPIs Report maintenance KPIs: Mean Time Between Failures (MTBF), Mean Time To Repair (MTTR), maintenance cost per asset, and planned vs. unplanned maintenance ratio. High
TEC-038 Net & Mooring Management Specialized asset management for aquaculture: track net pens (dimension, mesh size, antifouling status, repair history), mooring systems (inspection certificates, NYTEK compliance), and feed barges. High
TEC-039 Regulatory Equipment Inspections Track regulatory equipment inspections (electrical, lifting, pressure vessels, NYTEK): inspection dates, certifying body, results, validity period, and upcoming renewal alerts. High
TEC-040 Vessel & Boat Management Track company-owned service boats and vehicles: registration, insurance, class certification, operating hours, fuel consumption, and maintenance schedules. Desirable

PROJECT & COST MANAGEMENT

5
Total
2
Mandatory
3
High
0
Desirable
IDRequirementDescriptionPriority
TEC-041 Project Register Create and manage projects: project name, code, type (CAPEX, OPEX, R&D), responsible person, start/end dates, budget, and status. Mandatory
TEC-042 Project Budgeting Define project budgets by cost category (materials, labor, services, contingency). Track committed, actual, and remaining budget. High
TEC-043 Project Cost Collection Collect costs to projects from: purchase orders, time registration, expense claims, internal labor allocations, and manual journal entries. Mandatory
TEC-044 CAPEX Project to Asset Support capitalization of CAPEX project costs into fixed assets upon project completion (construction-in-progress → fixed asset). High
TEC-045 Project Reporting Report project status: budget vs. actual, cost forecast at completion, milestone progress, and variance analysis. High

REPORTING & ANALYTICS

11
Total
5
Mandatory
6
High
0
Desirable
IDRequirementDescriptionPriority
TEC-046 Standard Report Library Provide a comprehensive library of pre-built reports covering all functional areas: finance, farming, processing, sales, procurement, HR, quality, and maintenance. Mandatory
TEC-047 Ad-Hoc Reporting Users can create ad-hoc reports and queries without IT assistance using a user-friendly report builder or query tool. High
TEC-048 Report Drill-Down Support drill-down in reports: from summary to detail, from financial transaction to source document, from KPI to underlying data. Mandatory
TEC-049 Dashboard Builder Provide configurable dashboards that users can build from available widgets/charts/KPIs. Support role-based default dashboards. High
TEC-050 Scheduled Reports Schedule automated report generation and distribution via email (e.g., daily dispatch report, weekly lice summary, monthly management pack). High
TEC-051 Export Capabilities Export report data to: Excel, PDF, CSV, and optionally Power BI datasets. Mandatory
TEC-052 Data Warehouse / Data Lake Provide a structured data warehouse, data lake, or data export mechanism for enterprise analytics beyond the ERP's native reporting. Document the data model/schema. High
TEC-053 Real-Time Dashboards Support real-time operational dashboards with auto-refresh for: processing plant production status, daily biomass overview, and order fulfillment status. High
TEC-054 KPI Scorecards Provide KPI scorecards with targets, actual values, traffic-light status, and trend indicators for management use. Configurable by role and organizational level. High
TEC-055 Financial Reporting Package Pre-built or easily configurable financial reporting pack: Balance Sheet, P&L, Cash Flow Statement, trial balance, dimension analysis, budget vs actual, and management commentary capability. Mandatory
TEC-056 Regulatory Report Templates Pre-configured templates or easy adaptation for Norwegian regulatory reports: SAF-T, MVA return, A-melding data, and annual financial statements per Norwegian format. Mandatory

SECURITY, ACCESS & DATA PRIVACY

16
Total
10
Mandatory
4
High
2
Desirable
IDRequirementDescriptionPriority
TEC-057 Single Sign-On (SSO) Support SSO via Microsoft Entra ID (Azure Active Directory) using SAML 2.0 or OpenID Connect. Mandatory
TEC-058 Multi-Factor Authentication Support MFA (Multi-Factor Authentication) for all users, integrated with Microsoft Entra ID MFA or comparable mechanism. Mandatory
TEC-059 Role-Based Access Control Comprehensive RBAC: define roles with specific permissions to modules, screens, data records, and actions (create, read, update, delete). Support role hierarchy and role composition. Mandatory
TEC-060 Data-Level Security Support row-level or data-level security: users only see data for their authorized locations, departments, or regions (e.g., site manager sees only their region's farming data). High
TEC-061 Segregation of Duties Support segregation of duties rules: prevent conflict-of-interest combinations (e.g., same user cannot create vendor and approve payment to that vendor). Alert on violations. High
TEC-062 Audit Log Comprehensive audit logging of: all user logins, data changes (who, when, what changed, old/new values), report access, and administrative actions. Logs immutable and retained per configurable policy (minimum 7 years for financial data). Mandatory
TEC-063 GDPR Data Management Support GDPR requirements: data classification, processing purpose registration, consent management, data retention policies with automated deletion/anonymization, right-to-access reporting, and right-to-erasure execution. Mandatory
TEC-064 Data Encryption Data encryption at rest (AES-256 or equivalent) and in transit (TLS 1.2+). Customer-managed encryption keys optional. Mandatory
TEC-065 Penetration Testing Vendor conducts regular penetration testing (minimum annually) by independent third party and shares summary results with customers. High
TEC-066 SOC 2 / ISO 27001 Vendor holds SOC 2 Type II and/or ISO 27001 certification for data center and application operations. Provide evidence. Mandatory
TEC-067 IP Whitelisting Optionally restrict access by IP address range or network (NordHav VPN). Desirable
TEC-068 Session Management Configurable session timeout, concurrent session limits, and forced logout capability. High
TEC-069 Data Export & Portability Ability to export all NordHav data from the system in a standard, machine-readable format (CSV, JSON, XML) for data portability if NordHav changes vendors. Mandatory
TEC-070 Vendor Escrow Source code escrow available for critical proprietary components, or open-source licensing model, to mitigate vendor lock-in risk. Desirable
TEC-071 Incident Response Vendor has documented security incident response plan with: notification SLA (max 24 hours for data breaches), escalation procedures, and post-incident reporting. Mandatory
TEC-072 Norwegian Privacy Compliance Comply with Norwegian implementation of GDPR (Personopplysningsloven) and guidance from Datatilsynet (Norwegian Data Protection Authority). Mandatory

IMPLEMENTATION & SUPPORT

8
Total
6
Mandatory
1
High
1
Desirable
IDRequirementDescriptionPriority
TEC-073 Implementation Methodology Describe the standard implementation methodology: phases, deliverables, governance model, and role responsibilities (vendor and customer). Mandatory
TEC-074 Data Migration Strategy Describe proposed data migration approach: scope of historical data, data cleansing, validation, parallel run, and cutover strategy. Mandatory
TEC-075 Training Approach Describe training strategy: train-the-trainer, end-user training, training materials (language), e-learning availability, and ongoing training for new features/updates. Mandatory
TEC-076 Change Management Describe recommended change management approach to support organizational adoption: communication plan, stakeholder engagement, resistance management, and adoption metrics. High
TEC-077 Go-Live Support Describe go-live support: on-site support during cutover, hyper-care period (duration and staffing), escalation procedures, and transition to steady-state support. Mandatory
TEC-078 Support Model (Post-Go-Live) Describe ongoing support model: support tiers (L1, L2, L3), response time SLAs by severity, support hours (business hours vs. 24/7), support language (Norwegian and English required), and support channels (phone, email, portal). Mandatory
TEC-079 Norwegian Support Team Vendor or implementation partner must have Norwegian-speaking support and consulting resources familiar with Norwegian regulations, language, and business practices. Mandatory
TEC-080 Customer Success Program Describe the customer success or account management program: dedicated account manager, regular business reviews, early access to new features, and user community/user group. Desirable
← Back to Requirements Overview View D365 Coverage →