Home Best Practices & Workflows Run an assessment end-to-end

Run an assessment end-to-end

Last updated on Jun 03, 2026

TL;DR

🪜 The 7-step workflow our top customers use to ship a clean first assessment in 2-3 working sessions.


🪜 The workflow

1️⃣ Define your estate clearly (15 min)

  • One product, one codebase-SBOM lineage, one EU market exposure
  • Avoid mixing: 2 distinct products = 2 estates

2️⃣ Bring your CISO / compliance lead into the room (30 min)

  • They'll answer the scope questions faster
  • Pre-warn legal / DPO they'll be looped in later

3️⃣ Run the Scope Review (10 min)

  • Don't second-guess: pick the closest answer
  • Refine in step 6

4️⃣ Capture the gap before uploading (20 min)

  • Take a snapshot of the gap result
  • Prioritize: critical → high → medium → info

5️⃣ Upload evidence in batch (60 min)

  • Have SBOM, security policies, supplier attestations ready
  • Drag-and-drop, don't upload one by one

6️⃣ Refine scope based on what NexCyber infers (20 min)

  • If NexCyber classified something unexpected, dig into the obligation
  • Adjust your inputs

7️⃣ Re-read the gap, plan your next 30 days (20 min)

  • Pick your top 3 gap items
  • Assign owners
  • Schedule re-assessment in 30 days

➡️ Next


💬 Need help?

Reach out via our live chat (bottom-right) — Captain AI replies instantly, human experts within business hours. Email support@nexcyber.eu with [P1] for Command/Strategic priority issues.

ℹ️ Disclaimer — NexCyber provides a readiness analysis, not legal advice. Final compliance may require legal review or notified body certification.

Last reviewed: 2026-06-02 · NexCyber Help Center