Why this page exists
You rely on NexCyber to navigate fast-moving EU cyber regulation. We change the platform regularly to keep that picture accurate, and the regulations themselves change too. This page explains exactly how we communicate those changes, on what cadence, and what action you may need to take.
If you read one section, read "Categories of updates" below — it tells you which updates carry an SLA on advance notice and which do not.
Where to find updates
NexCyber publishes updates through several aligned channels:
| Channel | Best for | Coverage |
|---|---|---|
| This Help Center category ("Product & Regulatory Updates") | Searchable, persistent, structured | Every update — primary source of truth |
| In-app notification (workspace banner) | High-impact changes that affect users at login | Impact-rated changes |
| Email digest | Roll-up for stakeholders not in the workspace daily | Weekly + ad-hoc for critical events |
| RSS / Atom feed | Programmatic consumption (security teams, compliance dashboards) | Every published article |
| Trust Center page (curated) | External stakeholders (auditors, prospects, partners) | Regulatory updates and assurance changes |
The Help Center category is the canonical record. All other channels point back to it.
Categories of updates
We publish four categories. Each carries its own SLA on advance notice and its own format.
1. Platform release notes
Changes to the NexCyber platform itself: new features, improvements, bug fixes, security hardening.
- Cadence: per release train, typically weekly or bi-weekly.
- Advance notice: when a change is opt-in or rollback-safe, no advance notice required. When a change affects an existing workflow, we publish at least 48 hours before activation.
- Format: one article per release version (e.g.,
v1.1.0), with sections: What changed · Why it matters · Action required · Effective date · Related articles.
2. Regulatory updates ("LEX UPDATE")
When the regulatory picture itself changes — a new EU implementing act, a national transposition, a new harmonised standard, an EDPB guideline — NexCyber updates the corresponding readiness logic.
- Cadence: when regulators publish.
- Advance notice: we publish at least 48 hours before the new logic activates in your assessments, when feasible. For regulator-driven hard deadlines we may activate faster and document why.
- Format: one article per regulatory event. Sections: What the regulator changed · How NexCyber reflects it · What changes in your assessments · Action required · Effective date · References.
3. Security updates and advisories
Security-relevant changes to the platform, sub-processors, infrastructure regions, or our vulnerability disclosure policy.
- Cadence: when needed.
- Advance notice: where the change is preventive (e.g., adding a region), at least 7 days. For incident-driven changes (e.g., a sub-processor update following an incident), we publish as soon as accurate information is available.
- Format: separate article. Sections: Scope · Impact · Mitigation · Effective date · References.
4. Policy and legal updates
Changes to terms, data processing addenda, sub-processors list, privacy notice, or trust documents.
- Cadence: when changes are made.
- Advance notice: at least 30 days for material changes to terms or DPA. Sub-processor changes follow the SLA in your DPA.
- Format: separate article + DPA addendum where applicable.
What you can expect on cadence
We aim to make updates predictable. The minimum guarantees we commit to publicly are:
- 48-hour advance notice for any change that affects an existing customer workflow or readiness picture (categories 1 and 2 above).
- Effective date is always stated in the article and in the in-app banner.
- Rollback path is documented when applicable.
- Cross-references to affected Help Center articles, so you can see what to re-read.
These are minimums. Many updates are announced much earlier, especially when we know the change is coming from a published draft regulation.
How updates appear in the platform
Inside the workspace, updates are surfaced in three places:
- A banner at the top of the dashboard for impact-rated changes (one-click dismiss).
- A "What changed" panel on affected pages (e.g., a CRA assessment shows a note when CRA logic was updated since your last visit).
- An update history on each readiness report, so when you re-generate a PDF or MRCC you can see which updates landed since the previous version.
How updates are gated and audited internally
Before we publish an update, our quality assurance team reviews it for accuracy, consistency, and clarity. Regulatory updates pass an additional review to ensure the platform's logic correctly transposes the regulator's change. All published updates are archived with a content hash so you can verify the version you read.
We do not silently change logic without publishing an update.
Article anatomy — what each section means
Every release note article uses the same sections. This consistency lets you scan a long history quickly.
- What changed — short, factual list of changes. No marketing.
- Why it matters — the business and compliance reason for the change.
- Action required — concrete steps you may need to take, with links to the relevant Help Center articles.
- Effective date — the timestamp (CET) when the change activates.
- Affected modules — which parts of NexCyber are impacted (Scope, Assessment, Evidence, MRCC, Trust Passport, etc.).
- Affected regulations — which regulations are touched.
- Plans impacted — which plans see the change.
- References — citations to the regulator, our Help Center, and the underlying decision.
How to subscribe
Pick the channels that fit how you work:
- In-app: enabled by default for all workspace members.
- Email digest: subscribe under Account → Notifications → Updates digest. You can choose: every release, weekly digest, monthly digest, or critical-only.
- RSS / Atom: a feed is exposed at the bottom of this category. Drop the URL in your reader of choice or your monitoring stack.
If your organisation requires a controlled push (e.g., to a security or compliance distribution list), open a support conversation and we will route the right channel for your plan.
What about emergency changes?
When a change must take effect immediately (e.g., a security mitigation), we will:
- Apply the change.
- Publish the update article in this category within 24 hours, with a clear "Emergency change" marker.
- Send an in-app banner and an email to subscribers on the digest.
- Provide rollback context where applicable.
Emergency changes are rare and always justified by a regulator deadline or a security event.
What about regulatory horizon updates?
In addition to changes that are already activated, we publish regulatory horizon notes — short summaries of upcoming EU regulatory events (draft acts in consultation, expected publication dates, member-state transpositions in progress). These are advisory and clearly marked as horizon, not effective.
Use them to anticipate what may land in the next quarter and align internal planning.
What we never do in an update
- No legal opinion. We describe the regulator's change in neutral terms and explain how NexCyber reflects it. We do not interpret the law for your specific case.
- No undisclosed change. If you see logic change without an article, that is a bug — please report it.
- No retroactive removal. Past update articles are not edited silently; we issue addenda or follow-up articles if context evolves.
Related articles
- Pricing philosophy — how plans relate to coverage and updates.
- Data security and confidentiality — how change traceability is preserved.
- Contact support — when you need a human on a change you are reviewing.
Next step
Subscribe to the channel that fits your workflow. Then re-read this article only when something is unclear; the system is designed so you should not need to.