Home Billing and Plans Plan upgrade decision guide — when to move, when to wait

Plan upgrade decision guide — when to move, when to wait

Last updated on Jun 03, 2026

Why this article exists

Customers often ask the same question: should I upgrade my plan, or can I solve this with an add-on? This article gives a structured answer. We do not push upgrades that are not needed; the goal is to spend on what creates value.

Upgrade vs. add-on — the rule of thumb

  • An upgrade changes the platform's reach: more regulations included, more depth, more advanced features.
  • An add-on extends the operational support or one-off acceleration without changing reach.

If your bottleneck is reach, upgrade. If it is speed, accompaniment, or external sharing, add-ons are usually enough.

Five signals you should upgrade

1. You have a new regulation in scope

Your product evolves; AI is added; you start operating in a critical sector. Suddenly NIS2 or the AI Act applies. Your current plan does not cover them. Upgrade.

2. Your evidence picture became continuous

You used to run a yearly readiness exercise. Now you have to maintain a live picture because customers, auditors, or regulators ask quarterly. The Continuous Scoring module and a higher plan tier make sense.

3. Stakeholders proliferated

At plan start you were one team. Now you have security, compliance, engineering, supply chain, legal, and customer success all touching NexCyber daily. Upgrade for capacity (seat tax does not exist, but workflow tiers do).

4. External sharing became routine

You ship MRCCs to prospects, customers, and auditors weekly. The Trust Passport and MRCC management deserves a more advanced plan tier.

5. The board reviews readiness

Once cybersecurity readiness reaches the management body's cadence, you need governance artefacts at a different depth: history, traceability, comparison over time, escalation paths. Upgrade.

Three signals you do not need to upgrade

1. You need speed on a one-off

Acceleration packages exist for that. Launch Assist or Evidence Enablement deliver the outcome faster than a plan upgrade.

2. You need higher-touch support

That is a Care service: Priority, Enterprise, or Mission-Critical. No plan change needed (Care services do gate by plan, but the upgrade is to the Care tier, not the platform tier).

3. You are in a quiet quarter

Plans are renewable. Adding capacity for a quarter where you will not use it is waste. Wait.

Frequent upgrade paths

  • Starter → Launch: when you start needing onboarding accompaniment and your stakeholder count is rising.
  • Launch → Portfolio: when your product estate crosses ten regulated products and external sharing becomes routine.
  • Portfolio → Command: when you operate in a critical sector with significant customer base and need extended support availability.
  • Command → Strategic: when contractual SLAs are required by your own customers and the cost of a compliance outage is material.

These are typical; your situation may justify a different path.

How to decide — a practical checklist

Run this in 10 minutes:

  1. List the regulations in your scope today vs. in your plan.
  2. List the modules you actually use vs. the ones included.
  3. Count the stakeholders touching NexCyber weekly.
  4. Estimate the number of MRCCs you issue per quarter.
  5. List the named SLAs your customers expect from you.
  6. Check whether the board reviews readiness.
  7. Identify the top three bottlenecks of the last 30 days.

If items 1–6 suggest reach is the bottleneck, upgrade. If item 7 is purely speed or accompaniment, add-ons or a Care tier are enough.

How to upgrade

Talk to us through the widget or the contact form. We:

  • Confirm the scope change you are after.
  • Recommend a plan and any add-ons that actually apply.
  • Quote per regulated product estate, no seat tax.
  • Pro-rate the transition cleanly.

You can also start a Free Scope Review again whenever your product estate changes — it is the fastest way to confirm whether new regulations now apply to you.

How to downgrade

You can downgrade at renewal. We make this easy on purpose:

  • All your data stays.
  • MRCCs remain valid for their stated validity period.
  • Historical readiness reports stay accessible.
  • If you need a lighter plan for a quieter quarter, just ask.

What upgrades do NOT do

  • They do not retroactively make past readiness picture deeper. They unlock future depth.
  • They do not change the legal boundary. Whatever the plan, NexCyber is a readiness platform, not a certifier.

Related articles

  • Pricing philosophy.
  • Support plans and response targets.
  • Add-on modules and Care services — what each one delivers.

Next step

Run the seven-point checklist above. Send us the result if you want a structured recommendation.