Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager

previous version on gdrive

N.6.12 Coordination with customers on new software and updates

Control Overview

This control mandates that organizations developing and delivering software establish, document, and execute structured communication and rollout processes when deploying new software versions, major features, or security patches. Uncoordinated deployments can destabilize client operational workflows, trigger unexpected downtime, or conflict with customer-side change freezes. The organization must ensure that customers are proactively informed about the timeline, operational impact, and technical contents of a release, with a standardized roadmap governing the identification, notification, and distribution phases.

note

Applicability Note: This control is fully applicable to the anDREa platform and directly shapes how platform wide upgrades, maintenance windows, and security hotfixes are coordinated with our research institution tenant bases.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, aligning public SaaS deployment velocity with predictable enterprise communication.

Because anDREa operates as a single-version Software-as-a-Service (SaaS) platform, changes are applied systematically across the infrastructure plane. To balance this with customer operational predictability, coordination is managed through a multi-tiered governance and communication framework:

  • Proactive Public Documentation: Planned iterations, technical feature sets, and platform enhancements are made continuously available via the public-facing myDRE Feature Release and Roadmap portal hosted on our insights platform.
  • Structured Institutional Syncs: For key organizational customers and academic research sites, rollouts and deployment timelines are formally discussed and documented in the minutes of recurring Research Support Meetings. This allows customer teams to align internal workflows prior to platform modifications.
  • Out-of-SLA & Emergency Escalations: In the rare event that a high-priority security vulnerability requires a deployment outside standard maintenance windows, anDREa triggers an automated, high-priority notification protocol. Impacted tenant accountables are directly contacted to coordinate emergency mitigation paths, minimizing functional disruption while meeting strict patching timelines.

Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.32 - Change managementRegulates the planning, impact analysis, and deployment approval loops applied to system updates.
ISO/IEC 27001A.05.22 - Monitoring, review and change management of supplier servicesGoverns downstream tracking, monitoring, and communication of operational adjustments across service architectures.
Legal FrameworkService Level AgreementContractual baselines defining mandated notification windows, maintenance time blocks, and emergency patching pathways.
Public TelemetryRoadmapPublic roadmap portal outlining platform improvements and maintenance releases.
Operational RecordsResearch Support Meeting NotesFormal logs capturing active alignment, release feedback, and rollout timing discussions with customer institutional stakeholders.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. A structured, multi-channel release-communication model is fully active, binding contractual SLAs are enforced, and emergency direct-notification workflows are fully operationalized.