What this article covers
This page explains the regulatory update advisory — how NexCyber turns a real-world EU regulatory event (a new act, a new harmonised standard, a national transposition, an EDPB or ENISA guideline) into a change in the platform, and how you find out in time to act.
It is one of the four categories of updates we publish. See Release notes and regulatory updates — what to expect for the wider picture.
The advisory promise
We commit, publicly, to two things:
- Notice: when a regulatory event changes the readiness logic in NexCyber, we publish a regulatory update advisory at least 48 hours before the new logic activates in your workspace — unless a regulator deadline forces faster activation, in which case we publish at activation and explain why.
- Traceability: every advisory carries the references the auditor would expect — the regulator's publication, the version of the harmonised standard, the date and the article number. You can quote it to your own auditor and they can follow the chain themselves.
These two promises map directly to the engagement we make on lex accuracy and traceability.
The lifecycle of a regulatory event
A regulatory event goes through five stages inside NexCyber.
1. Horizon
A draft act, a public consultation, a notified body workshop, or a national transposition draft is published. We capture it as a horizon item in the regulatory tracker (visible to our team) and may publish a horizon note (one of our update categories) if the event is large enough to matter for your planning.
A horizon note is advisory only — nothing changes in your platform yet.
2. Confirmed
The regulator publishes the final act, the harmonised standard goes through CEN-CENELEC, or the national transposition is voted. We move the horizon item to "confirmed" and prepare the transposition into NexCyber.
3. Transposition
Our regulatory team transposes the regulator's text into the parts of NexCyber that depend on it: the scope-applicability rules, the assessment questions, the obligation-to-control mapping, and the evidence-confidence rubric. Each change is reviewed by a second regulatory reviewer; both names are recorded in the advisory's internal audit trail.
4. Pre-publication review
Quality assurance reviews the advisory and the underlying change:
- Logic transposition is faithful.
- Wording aligns with the regulator's terms (no implicit certification claim).
- Customer-facing language is clear and structurally consistent with prior advisories.
- The 48-hour notice window is honoured.
5. Publication
The advisory is published in the Help Center, surfaced in the in-app banner for affected customers, sent to email digest subscribers if they opted in, and added to the RSS / Atom feed. The activation timestamp is set in the future, at minimum 48 hours away.
When the activation timestamp passes, the platform applies the new logic to new assessments. Existing assessments retain their previous logic until you re-run them; the assessment view shows you which version of which regulation it was run under.
Anatomy of a regulatory update advisory
Every advisory uses the same fixed sections — this is how you scan a long history quickly.
- TL;DR — three lines: who is affected, what changes, by when.
- What the regulator changed — neutral summary of the regulator's text, with the official reference (OJ citation, standard reference, transposition act).
- How NexCyber reflects it — the parts of NexCyber that change (scope rules, assessment questions, controls, evidence rubric, MRCC content).
- What changes in your assessments — concrete examples: a new obligation appears under CRA, a question is re-worded, a previously-met item becomes partial, a new evidence type is suggested.
- Action required — concrete steps; if nothing is required, the article says so.
- Effective date — the activation timestamp (CET).
- Affected modules — Scope, Assessment, Evidence, Report, MRCC, Trust Passport.
- Affected regulations — typically one main regulation, sometimes adjacent ones if the change has overlap (e.g., CRA + RED Cyber overlap).
- Plans impacted — which plans see the change.
- Auditor pack — a single block of references an auditor can drop into a workpaper: regulator citation, standard version, NexCyber change ID, transposition reviewer initials, QA gate timestamp. This is the chain of custody for the change.
- Rollback — if the change is reversible, how; if it is not (because the regulator says so), why.
- References — full citations.
How you act on an advisory
There is a simple, three-question routine:
- Does it apply to me? The advisory tells you the affected regulations, sectors, and product types. Cross-check with your Regulated Product Estate.
- What do I do now? The "Action required" section is concrete. Sometimes nothing. Sometimes re-run an assessment. Sometimes attach a new evidence type. Sometimes notify an internal stakeholder.
- What do I tell my auditor? Quote the "Auditor pack" block — it has everything the auditor expects.
That is the entire workflow. There is no separate dashboard to learn.
When 48 hours is not possible
Some changes are activated by a regulator deadline that is shorter than 48 hours from our knowledge of the change. Examples: a sudden EDPB guideline that re-defines a notion of risk; an EU implementing act with a sunset clause that lapses on a fixed date.
In those cases, we activate the change as required and publish the advisory at activation, with an "Emergency activation" marker. The advisory explains why the 48-hour notice could not be honoured.
We monitor regulator timelines specifically to keep emergency activations rare.
Versions, addenda, and corrections
A regulatory advisory is immutable once published: we do not silently edit it. If something needs clarifying, we issue an addendum article that references the original advisory. If the regulator itself amends or corrects its publication, we issue a follow-up advisory rather than rewriting the original.
This is how an auditor can come back six months later and reconstruct exactly what NexCyber communicated and when.
Horizon notes — anticipating
Horizon notes are short articles in this same category, clearly marked "Horizon — not yet effective". They are useful when:
- A regulator publishes a draft act and you want to anticipate.
- A harmonised standard is in consultation and you want to follow its trajectory.
- A national transposition deadline is approaching and you want to know what to track.
Horizon notes are advisory and not binding. They are not citation-grade — wait for the confirmed advisory before quoting to your auditor.
What the advisory does NOT do
- It does not provide a legal opinion on whether a regulator's change applies to your specific case.
- It does not modify your existing assessments retroactively. Existing reports and MRCCs preserve the logic version they were run under, with the version number visible in the metadata.
- It does not replace the regulator's publication. Always read the OJ text or the standard for a binding interpretation.
How this fits with audit-readiness
Auditors love three things: traceability, immutability, and clear language. The advisory format gives them all three.
- Traceability: the auditor pack block gives the chain of references.
- Immutability: advisories are never silently edited.
- Clear language: structurally consistent across advisories, so the auditor builds a mental model after reading two or three.
Related articles
- Release notes and regulatory updates — what to expect — overall update process.
- What NexCyber does NOT replace — the boundary with legal advice.
- What is audit-ready evidence? — how evidence travels with regulatory changes.
Next step
Subscribe to the Product & Regulatory Updates category. Use horizon notes for planning, advisories for action, addenda for clarifications.