Back to Knowledge Base
Knowledge Base · fundamentals

SBOM vs Evidence vs MRCC — what's the difference ?

8 May 2026 5 min read ★ NEXCYBER

Three artifacts often confused. We clarify the SBOM (technical inventory), Evidence (audit trail), and the MRCC (machine-readable readiness attestation).

SBOM — what is inside your product

A Software Bill of Materials is a machine-readable inventory of the components and dependencies that make up your product. It answers 'what is in the box?' and is the basis for vulnerability management: you cannot patch what you cannot see.

Evidence — proof that you meet an obligation

Evidence is the audit trail: policies, test results, attestations, configuration records and other artefacts that demonstrate a specific obligation is met. Good evidence is current, verifiable, and linked to the obligation it supports — not a folder of unsorted documents.

MRCC — a signed readiness attestation

A Machine-Readable Compliance Certificate summarises your assessed readiness in a signed, verifiable form. It is an automated readiness attestation — not a legal conformity certificate, and not a replacement for a notified body where one is required.

How they fit together

  • The SBOM feeds vulnerability and component obligations.
  • Evidence substantiates each obligation across regulations.
  • The MRCC is the trustworthy summary on top — only as strong as the admissible evidence beneath it.

This is an educational explainer. For the canonical regulation reference, see the dedicated ★ NEXCYBER page — or run an assessment to see how it applies to your product.