Home MRCC & Trust Passport How the MRCC process works step by step

How the MRCC process works step by step

Last updated on Jun 02, 2026

TL;DR

๐Ÿ“œ Five steps from assessment to issued MRCC Certificate.


๐Ÿชœ The 5 steps

1๏ธโƒฃ Define your Product Estate

One estate = one product / one codebase-SBOM lineage / one EU market exposure. ๐Ÿ‘‰ Add your first regulated product

2๏ธโƒฃ Run your Scope Review

RICE maps which EU frameworks apply (CRA, NIS2, AI Act, RED, DORA, combos). ๐Ÿ‘‰ How NexCyber decides which regulations apply

3๏ธโƒฃ Close your Compliance Gap

Upload evidence (SBOM, policies, test reports, supplier attestations). Confidence levels update automatically. ๐Ÿ‘‰ Build your evidence library

4๏ธโƒฃ Reach the confidence threshold

Each framework has a confidence threshold. When you cross it, your estate becomes MRCC-eligible. ๐Ÿ‘‰ Reading your assessment results

5๏ธโƒฃ Request the MRCC

  • Open your estate
  • Click Request MRCC
  • Our regulatory team reviews and signs
  • You receive a signed PDF + a public verify URL

โฑ๏ธ Typical timeline

Plan First MRCC turnaround
Launch 5-10 business days
Portfolio 3-5 business days
Command 1-3 business days (priority queue)
Strategic Contractual SLA

โžก๏ธ Next


๐Ÿ’ฌ Need help?

  • Reach out via our live chat (bottom-right) โ€” Captain AI replies instantly, human experts within business hours.
  • Email support@nexcyber.eu with [P1] for Command/Strategic priority issues.

โ„น๏ธ Disclaimer โ€” RICE provides a readiness analysis, not legal advice. Final compliance may require legal review or notified body certification.

Last reviewed: 2026-06-02 ยท NexCyber Help Center