Home MRCC & Trust Passport Fastest path to your first MRCC Certificate

Fastest path to your first MRCC Certificate

Last updated on Jun 02, 2026

TL;DR

๐Ÿš€ The most direct route from signup to a signed MRCC, optimised by NexCyber experts.


โšก Express path (Launch plan or above)

Week 1 โ€” Foundation

  • โœ… Create your account ยท invite your compliance lead
  • โœ… Add your Regulated Product Estate (start with your flagship product)
  • โœ… Run the Scope Review โ†’ see which frameworks apply

Week 2 โ€” Evidence ingestion

  • โœ… Upload your SBOM (CycloneDX 1.4+ / SPDX 2.3+)
  • โœ… Map existing policies (security, vuln handling, incident response)
  • โœ… Add supplier attestations for tier-1 dependencies

Week 3 โ€” Close the gap

  • โœ… Address top 3 gap priorities surfaced by RICE
  • โœ… Re-upload refreshed evidence as needed
  • โœ… Reach confidence threshold on at least 1 framework

Week 4 โ€” Request MRCC

  • โœ… Click Request MRCC on your estate
  • โœ… Regulatory expert review + sign-off
  • โœ… Receive signed PDF + public verify URL

๐Ÿšฆ Confidence thresholds (functional view)

Framework What you need at minimum
๐Ÿ›ก๏ธ CRA SBOM + vuln-handling policy + tech-doc skeleton
๐ŸŒ NIS2 10 minimum measures mapped + supplier register
๐Ÿค– AI Act Risk tier classification + technical documentation
๐Ÿ“ก RED Cyber 3.3.d/e/f sub-requirements evidence
๐Ÿฆ DORA ICT third-party register + incident classification template

Specific scoring methodology is part of our private model. Public-facing confidence is summarised in bands (preview / computed / evidence-backed / externally-linked).

๐Ÿ’ก Pro tips

  • ๐ŸŽฏ Start with one framework, not all five
  • ๐Ÿ“Š Aim for evidence-backed band before requesting MRCC
  • ๐Ÿค Loop in your auditor early โ€” share Trust Passport URL

โžก๏ธ Next


๐Ÿ’ฌ Need help?

  • Reach out via our live chat (bottom-right) โ€” Captain AI replies instantly, human experts within business hours.
  • Email support@nexcyber.eu with [P1] for Command/Strategic priority issues.

โ„น๏ธ Disclaimer โ€” RICE provides a readiness analysis, not legal advice. Final compliance may require legal review or notified body certification.

Last reviewed: 2026-06-02 ยท NexCyber Help Center