Three artifacts often confused. We clarify the SBOM (technical inventory), Evidence (audit trail), and the MRCC (machine-readable readiness attestation).
SBOM — what is inside your product
A Software Bill of Materials is a machine-readable inventory of the components and dependencies that make up your product. It answers 'what is in the box?' and is the basis for vulnerability management: you cannot patch what you cannot see.
Evidence — proof that you meet an obligation
Evidence is the audit trail: policies, test results, attestations, configuration records and other artefacts that demonstrate a specific obligation is met. Good evidence is current, verifiable, and linked to the obligation it supports — not a folder of unsorted documents.
MRCC — a signed readiness attestation
A Machine-Readable Compliance Certificate summarises your assessed readiness in a signed, verifiable form. It is an automated readiness attestation — not a legal conformity certificate, and not a replacement for a notified body where one is required.
How they fit together
- The SBOM feeds vulnerability and component obligations.
- Evidence substantiates each obligation across regulations.
- The MRCC is the trustworthy summary on top — only as strong as the admissible evidence beneath it.
This is an educational explainer. For the canonical regulation reference, see the dedicated ★ NEXCYBER page — or run an assessment to see how it applies to your product.