TL;DR
🪜 The 7-step workflow our top customers use to ship a clean first assessment in 2-3 working sessions.
🪜 The workflow
1️⃣ Define your estate clearly (15 min)
- One product, one codebase-SBOM lineage, one EU market exposure
- Avoid mixing: 2 distinct products = 2 estates
2️⃣ Bring your CISO / compliance lead into the room (30 min)
- They'll answer the scope questions faster
- Pre-warn legal / DPO they'll be looped in later
3️⃣ Run the Scope Review (10 min)
- Don't second-guess: pick the closest answer
- Refine in step 6
4️⃣ Capture the gap before uploading (20 min)
- Take a snapshot of the gap result
- Prioritize: critical → high → medium → info
5️⃣ Upload evidence in batch (60 min)
- Have SBOM, security policies, supplier attestations ready
- Drag-and-drop, don't upload one by one
6️⃣ Refine scope based on what NexCyber infers (20 min)
- If NexCyber classified something unexpected, dig into the obligation
- Adjust your inputs
7️⃣ Re-read the gap, plan your next 30 days (20 min)
- Pick your top 3 gap items
- Assign owners
- Schedule re-assessment in 30 days
➡️ Next
💬 Need help?
Reach out via our live chat (bottom-right) — Captain AI replies instantly, human experts within business hours.
Email support@nexcyber.eu with [P1] for Command/Strategic priority issues.
ℹ️ Disclaimer — NexCyber provides a readiness analysis, not legal advice. Final compliance may require legal review or notified body certification.
Last reviewed: 2026-06-02 · NexCyber Help Center