Home Product & Regulatory Updates

Product & Regulatory Updates

Release notes and regulatory updates for NexCyber customers.
By Eliseo Thrope
3 articles

Release notes and regulatory updates — what to expect

Why this page exists You rely on NexCyber to navigate fast-moving EU cyber regulation. We change the platform regularly to keep that picture accurate, and the regulations themselves change too. This page explains exactly how we communicate those changes, on what cadence, and what action you may need to take. If you read one section, read "Categories of updates" below — it tells you which updates carry an SLA on advance notice and which do not. Where to find updates NexCyber publishes updates through several aligned channels: | Channel | Best for | Coverage | |---|---|---| | This Help Center category ("Product & Regulatory Updates") | Searchable, persistent, structured | Every update — primary source of truth | | In-app notification (workspace banner) | High-impact changes that affect users at login | Impact-rated changes | | Email digest | Roll-up for stakeholders not in the workspace daily | Weekly + ad-hoc for critical events | | RSS / Atom feed | Programmatic consumption (security teams, compliance dashboards) | Every published article | | Trust Center page (curated) | External stakeholders (auditors, prospects, partners) | Regulatory updates and assurance changes | The Help Center category is the canonical record. All other channels point back to it. Categories of updates We publish four categories. Each carries its own SLA on advance notice and its own format. 1. Platform release notes Changes to the NexCyber platform itself: new features, improvements, bug fixes, security hardening. - Cadence: per release train, typically weekly or bi-weekly. - Advance notice: when a change is opt-in or rollback-safe, no advance notice required. When a change affects an existing workflow, we publish at least 48 hours before activation. - Format: one article per release version (e.g., v1.1.0), with sections: What changed · Why it matters · Action required · Effective date · Related articles. 2. Regulatory updates ("LEX UPDATE") When the regulatory picture itself changes — a new EU implementing act, a national transposition, a new harmonised standard, an EDPB guideline — NexCyber updates the corresponding readiness logic. - Cadence: when regulators publish. - Advance notice: we publish at least 48 hours before the new logic activates in your assessments, when feasible. For regulator-driven hard deadlines we may activate faster and document why. - Format: one article per regulatory event. Sections: What the regulator changed · How NexCyber reflects it · What changes in your assessments · Action required · Effective date · References. 3. Security updates and advisories Security-relevant changes to the platform, sub-processors, infrastructure regions, or our vulnerability disclosure policy. - Cadence: when needed. - Advance notice: where the change is preventive (e.g., adding a region), at least 7 days. For incident-driven changes (e.g., a sub-processor update following an incident), we publish as soon as accurate information is available. - Format: separate article. Sections: Scope · Impact · Mitigation · Effective date · References. 4. Policy and legal updates Changes to terms, data processing addenda, sub-processors list, privacy notice, or trust documents. - Cadence: when changes are made. - Advance notice: at least 30 days for material changes to terms or DPA. Sub-processor changes follow the SLA in your DPA. - Format: separate article + DPA addendum where applicable. What you can expect on cadence We aim to make updates predictable. The minimum guarantees we commit to publicly are: - 48-hour advance notice for any change that affects an existing customer workflow or readiness picture (categories 1 and 2 above). - Effective date is always stated in the article and in the in-app banner. - Rollback path is documented when applicable. - Cross-references to affected Help Center articles, so you can see what to re-read. These are minimums. Many updates are announced much earlier, especially when we know the change is coming from a published draft regulation. How updates appear in the platform Inside the workspace, updates are surfaced in three places: 1. A banner at the top of the dashboard for impact-rated changes (one-click dismiss). 2. A "What changed" panel on affected pages (e.g., a CRA assessment shows a note when CRA logic was updated since your last visit). 3. An update history on each readiness report, so when you re-generate a PDF or MRCC you can see which updates landed since the previous version. How updates are gated and audited internally Before we publish an update, our quality assurance team reviews it for accuracy, consistency, and clarity. Regulatory updates pass an additional review to ensure the platform's logic correctly transposes the regulator's change. All published updates are archived with a content hash so you can verify the version you read. We do not silently change logic without publishing an update. Article anatomy — what each section means Every release note article uses the same sections. This consistency lets you scan a long history quickly. - What changed — short, factual list of changes. No marketing. - Why it matters — the business and compliance reason for the change. - Action required — concrete steps you may need to take, with links to the relevant Help Center articles. - Effective date — the timestamp (CET) when the change activates. - Affected modules — which parts of NexCyber are impacted (Scope, Assessment, Evidence, MRCC, Trust Passport, etc.). - Affected regulations — which regulations are touched. - Plans impacted — which plans see the change. - References — citations to the regulator, our Help Center, and the underlying decision. How to subscribe Pick the channels that fit how you work: - In-app: enabled by default for all workspace members. - Email digest: subscribe under Account → Notifications → Updates digest. You can choose: every release, weekly digest, monthly digest, or critical-only. - RSS / Atom: a feed is exposed at the bottom of this category. Drop the URL in your reader of choice or your monitoring stack. If your organisation requires a controlled push (e.g., to a security or compliance distribution list), open a support conversation and we will route the right channel for your plan. What about emergency changes? When a change must take effect immediately (e.g., a security mitigation), we will: 1. Apply the change. 2. Publish the update article in this category within 24 hours, with a clear "Emergency change" marker. 3. Send an in-app banner and an email to subscribers on the digest. 4. Provide rollback context where applicable. Emergency changes are rare and always justified by a regulator deadline or a security event. What about regulatory horizon updates? In addition to changes that are already activated, we publish regulatory horizon notes — short summaries of upcoming EU regulatory events (draft acts in consultation, expected publication dates, member-state transpositions in progress). These are advisory and clearly marked as horizon, not effective. Use them to anticipate what may land in the next quarter and align internal planning. What we never do in an update - No legal opinion. We describe the regulator's change in neutral terms and explain how NexCyber reflects it. We do not interpret the law for your specific case. - No undisclosed change. If you see logic change without an article, that is a bug — please report it. - No retroactive removal. Past update articles are not edited silently; we issue addenda or follow-up articles if context evolves. Related articles - Pricing philosophy — how plans relate to coverage and updates. - Data security and confidentiality — how change traceability is preserved. - Contact support — when you need a human on a change you are reviewing. Next step Subscribe to the channel that fits your workflow. Then re-read this article only when something is unclear; the system is designed so you should not need to.

Last updated on Jun 03, 2026

v1.1.0 — 2026-06-03 · Help Center, Captain Nex, regulatory baselines

TL;DR NexCyber v1.1.0 ships the public Help Center, the Captain Nex AI copilot, and the baseline coverage for the five regulations on which NexCyber operates (CRA, NIS2, AI Act, DORA, RED Cyber). It also strengthens the operational support layer (SLA policies, business hours, escalation matrix) and ships a formal vulnerability disclosure policy under RFC 9116. What changed Help Center — public surface - Skin of docs.nexcyber.eu reworked: clear navigation, mobile-ready layout, consistent terminology (NexCyber as the single product name). - 50 articles published across Getting Started, Solution Guides, regulatory basics (CRA · NIS2 · AI Act · DORA · RED Cyber), Billing & Plans, and FAQ — covering the platform end-to-end at bootstrap depth. Customers portal mirrors a complementary set of 25 articles for logged-in users. - Diátaxis structure: every article follows one of tutorial · how-to · reference · explanation. The header tells you which type you are reading; the "Next step" footer points you to the right follow-up. - What NexCyber does NOT replace — a dedicated article makes the boundary with legal advice, notified-body certification, and independent audit explicit. Every regulation page repeats the boundary. Captain Nex — AI copilot in the support widget - Captain Nex is live in the support widget on the docs Help Center. - Language stickiness: Captain replies in the language of your first message and stays in it for the conversation (EN, FR, DE, ES, IT). - Two modes: when you are logged in, Captain operates as a product coach (onboarding, quick-start, scope, assessment, evidence, report). Anonymous visitors see Captain in sales-aware concierge mode (value, plans, modules, regulatory coverage). - Hand-off: Captain hands off to a human for sensitive regulatory questions, billing disputes, security events, or any case where it is not confident. - No legal opinion: Captain explains how NexCyber works, never interprets the law for a specific case. Operational support layer - Five SLA policies active (Standard · Guided · Priority · Enterprise Ops · Premium Success) mapped to plans. - Business hours (Mon–Fri 9–19 CET, Europe/Paris) enabled on every inbox so SLA timers reflect real working time. - Functional inboxes added — Sales, Compliance, Billing, Security — alongside the existing regional support email inboxes. Routing to the right team is automatic. - Escalation runbook L1 → L6 is documented and applied (Captain Nex → human support → product/engineering → regulatory expert → security → executive). Internal-only but the customer-facing effect is that your conversations always land at the right human. Regulatory baselines audited - CRA, NIS2, AI Act, DORA, RED Cyber — baseline coverage is in place. Each regulation has a Help Center page, an assessment scaffold, and clear guidance on what evidence to collect. - The baseline is the floor, not the ceiling. Deeper guides (per Article 21 NIS2 measure, per AI Act Annex III area, per DORA pillar) are scheduled in the next release trains. Vulnerability disclosure policy (RFC 9116) - security.txt is published at the canonical paths: - https://support.nexcyber.eu/.well-known/security.txt - https://docs.nexcyber.eu/.well-known/security.txt - Contact: security@nexcyber.eu. Preferred languages: EN, FR. Policy article published in the FAQ section. - We commit to acknowledge within 2 business days and to provide a triage update within 5 business days. Why it matters A regulated buyer asks four questions early: what does this product cover · how does it work · what does it guarantee · how do I trust the team. This release answers each one in a way you can read, share, and bookmark. - Coverage = Help Center categories + regulation pages. - How it works = the four-step flow (Scope → Assessment → Evidence → Report / MRCC). - Guarantees = the SLA policy + the What NexCyber does NOT replace boundary. - Trust = security.txt + the Data security and confidentiality page + the Responsible vulnerability disclosure page. Action required Nothing mandatory. If you want to take advantage of the release: - Open the Help Center and use it as your in-house knowledge base for the team. - Subscribe to the Product & Regulatory Updates category to be notified of subsequent release notes. - Encourage your security team to review the security.txt policy. If you are an existing customer with an open question that the new content does not yet answer, open the widget and Captain Nex will help. Effective date 2026-06-03, 09:00 CET (Europe/Paris). Affected modules - Help Center (public + customers portal). - Captain Nex (AI copilot in the support widget). - Support operations (SLA, escalation, business hours, functional inboxes). Affected regulations CRA · NIS2 · AI Act · DORA · RED Cyber — baseline coverage activated. Plans impacted All plans. The support level and response targets remain plan-specific (see Support plans and response targets). Rollback The release is additive. No data migration. If a specific article or feature creates a problem, we can disable it surgically without rolling the full release back. References - Release notes and regulatory updates — what to expect — process article. - What is NexCyber? — product overview. - Support plans and response targets — plan / SLA mapping. - Responsible vulnerability disclosure — security reporting. - security.txt — vulnerability disclosure machine-readable policy. Next step Open Subscribe to updates in your workspace notification settings, or just drop our RSS feed in your reader.

Last updated on Jun 03, 2026

Regulatory update advisory — 48-hour notice and traceability

What this article covers This page explains the regulatory update advisory — how NexCyber turns a real-world EU regulatory event (a new act, a new harmonised standard, a national transposition, an EDPB or ENISA guideline) into a change in the platform, and how you find out in time to act. It is one of the four categories of updates we publish. See Release notes and regulatory updates — what to expect for the wider picture. The advisory promise We commit, publicly, to two things: 1. Notice: when a regulatory event changes the readiness logic in NexCyber, we publish a regulatory update advisory at least 48 hours before the new logic activates in your workspace — unless a regulator deadline forces faster activation, in which case we publish at activation and explain why. 2. Traceability: every advisory carries the references the auditor would expect — the regulator's publication, the version of the harmonised standard, the date and the article number. You can quote it to your own auditor and they can follow the chain themselves. These two promises map directly to the engagement we make on lex accuracy and traceability. The lifecycle of a regulatory event A regulatory event goes through five stages inside NexCyber. 1. Horizon A draft act, a public consultation, a notified body workshop, or a national transposition draft is published. We capture it as a horizon item in the regulatory tracker (visible to our team) and may publish a horizon note (one of our update categories) if the event is large enough to matter for your planning. A horizon note is advisory only — nothing changes in your platform yet. 2. Confirmed The regulator publishes the final act, the harmonised standard goes through CEN-CENELEC, or the national transposition is voted. We move the horizon item to "confirmed" and prepare the transposition into NexCyber. 3. Transposition Our regulatory team transposes the regulator's text into the parts of NexCyber that depend on it: the scope-applicability rules, the assessment questions, the obligation-to-control mapping, and the evidence-confidence rubric. Each change is reviewed by a second regulatory reviewer; both names are recorded in the advisory's internal audit trail. 4. Pre-publication review Quality assurance reviews the advisory and the underlying change: - Logic transposition is faithful. - Wording aligns with the regulator's terms (no implicit certification claim). - Customer-facing language is clear and structurally consistent with prior advisories. - The 48-hour notice window is honoured. 5. Publication The advisory is published in the Help Center, surfaced in the in-app banner for affected customers, sent to email digest subscribers if they opted in, and added to the RSS / Atom feed. The activation timestamp is set in the future, at minimum 48 hours away. When the activation timestamp passes, the platform applies the new logic to new assessments. Existing assessments retain their previous logic until you re-run them; the assessment view shows you which version of which regulation it was run under. Anatomy of a regulatory update advisory Every advisory uses the same fixed sections — this is how you scan a long history quickly. - TL;DR — three lines: who is affected, what changes, by when. - What the regulator changed — neutral summary of the regulator's text, with the official reference (OJ citation, standard reference, transposition act). - How NexCyber reflects it — the parts of NexCyber that change (scope rules, assessment questions, controls, evidence rubric, MRCC content). - What changes in your assessments — concrete examples: a new obligation appears under CRA, a question is re-worded, a previously-met item becomes partial, a new evidence type is suggested. - Action required — concrete steps; if nothing is required, the article says so. - Effective date — the activation timestamp (CET). - Affected modules — Scope, Assessment, Evidence, Report, MRCC, Trust Passport. - Affected regulations — typically one main regulation, sometimes adjacent ones if the change has overlap (e.g., CRA + RED Cyber overlap). - Plans impacted — which plans see the change. - Auditor pack — a single block of references an auditor can drop into a workpaper: regulator citation, standard version, NexCyber change ID, transposition reviewer initials, QA gate timestamp. This is the chain of custody for the change. - Rollback — if the change is reversible, how; if it is not (because the regulator says so), why. - References — full citations. How you act on an advisory There is a simple, three-question routine: 1. Does it apply to me? The advisory tells you the affected regulations, sectors, and product types. Cross-check with your Regulated Product Estate. 2. What do I do now? The "Action required" section is concrete. Sometimes nothing. Sometimes re-run an assessment. Sometimes attach a new evidence type. Sometimes notify an internal stakeholder. 3. What do I tell my auditor? Quote the "Auditor pack" block — it has everything the auditor expects. That is the entire workflow. There is no separate dashboard to learn. When 48 hours is not possible Some changes are activated by a regulator deadline that is shorter than 48 hours from our knowledge of the change. Examples: a sudden EDPB guideline that re-defines a notion of risk; an EU implementing act with a sunset clause that lapses on a fixed date. In those cases, we activate the change as required and publish the advisory at activation, with an "Emergency activation" marker. The advisory explains why the 48-hour notice could not be honoured. We monitor regulator timelines specifically to keep emergency activations rare. Versions, addenda, and corrections A regulatory advisory is immutable once published: we do not silently edit it. If something needs clarifying, we issue an addendum article that references the original advisory. If the regulator itself amends or corrects its publication, we issue a follow-up advisory rather than rewriting the original. This is how an auditor can come back six months later and reconstruct exactly what NexCyber communicated and when. Horizon notes — anticipating Horizon notes are short articles in this same category, clearly marked "Horizon — not yet effective". They are useful when: - A regulator publishes a draft act and you want to anticipate. - A harmonised standard is in consultation and you want to follow its trajectory. - A national transposition deadline is approaching and you want to know what to track. Horizon notes are advisory and not binding. They are not citation-grade — wait for the confirmed advisory before quoting to your auditor. What the advisory does NOT do - It does not provide a legal opinion on whether a regulator's change applies to your specific case. - It does not modify your existing assessments retroactively. Existing reports and MRCCs preserve the logic version they were run under, with the version number visible in the metadata. - It does not replace the regulator's publication. Always read the OJ text or the standard for a binding interpretation. How this fits with audit-readiness Auditors love three things: traceability, immutability, and clear language. The advisory format gives them all three. - Traceability: the auditor pack block gives the chain of references. - Immutability: advisories are never silently edited. - Clear language: structurally consistent across advisories, so the auditor builds a mental model after reading two or three. Related articles - Release notes and regulatory updates — what to expect — overall update process. - What NexCyber does NOT replace — the boundary with legal advice. - What is audit-ready evidence? — how evidence travels with regulatory changes. Next step Subscribe to the Product & Regulatory Updates category. Use horizon notes for planning, advisories for action, addenda for clarifications.

Last updated on Jun 03, 2026