The compliance officer problem
Five EU regulations. Overlapping scopes. Different timelines. Different evidence formats. Different regulators. CRA is a product regulation enforced by market surveillance authorities. NIS2 is an entity obligation enforced by national cybersecurity agencies. DORA is enforced by financial supervisors. The AI Act by national AI authorities and the European AI Office.
You cannot manage this with a spreadsheet. You need: scope determination per regulation, obligation mapping per article, gap identification, evidence collection, and an audit-ready package that can be handed to any of the five regulatory regimes on demand.
What NexCyber gives compliance officers
Gap assessment — 144 obligations, article-level
The NexCyber Engine assesses your organisation against 144 obligations across CRA, NIS2, AI Act, DORA, and RED. Each obligation is traceable to its source article — not to a framework category.
Output: a gap assessment report that identifies:
- Obligations not yet satisfied
- Obligations partially satisfied (with evidence gaps)
- Obligations satisfied with evidence
- Obligations not applicable (with scope rationale)
This is the input to your remediation roadmap. It is also the structure your auditor will use.
Evidence collection — not a checklist
Compliance programmes fail at audit when the evidence does not match the assertion. "We have a CVD policy" fails if the policy is a PDF that no one monitors. "We have an SBOM" fails if the SBOM is incomplete, unsigned, or stale.
NexCyber's Evidence Layer:
- Stores artefacts with hash verification (tamper-evident)
- Tracks completeness per obligation
- Flags stale evidence (SBOM not updated since last release, CVD policy not reviewed in 12 months)
- Retains all artefacts for 10 years (CRA Article 31 requirement)
Regulation-by-regulation posture
CRA posture checklist for compliance officers:
- [ ] Product scope confirmed (Default / Important Class I / Important Class II)
- [ ] Annex I Part I security requirements gap-assessed
- [ ] SBOM generated and complete (transitive depth, signed)
- [ ] CVD policy published and operationally active
- [ ] Vulnerability log maintained
- [ ] Conformity assessment route selected
- [ ] Technical file compiled (9 artefacts)
- [ ] EU Declaration of Conformity drafted
- [ ] ENISA notification workflow documented and tested (before Sept 2026)
NIS2 posture checklist:
- [ ] Entity scope confirmed (essential / important)
- [ ] Art. 21(2) 10 security measures gap-assessed
- [ ] Art. 20 management approval documented
- [ ] Incident reporting workflow (24h/72h/30d) tested
- [ ] Supply chain security measures evidenced
- [ ] Evidence retained per national transposition requirements
→ NIS2 implementation guide — 8 steps → CRA audit-ready evidence — 9-artefact technical file
Cross-regulation overlap — one evidence set
NIS2 and CRA share 6 obligation areas. One SBOM can satisfy both CRA Annex I Part II §1 and NIS2 Article 21(d). One CVD policy — structured correctly — satisfies both CRA Article 14 and ETSI EN 303 645 §5.2 (RED).
NexCyber maps overlaps explicitly so your evidence is not duplicated unnecessarily. The NexCyber Engine identifies which artefacts satisfy multiple obligations.
→ NIS2 × CRA overlap — shared evidence strategy
MRCC — the auditable attestation
Once your evidence layer is complete, NexCyber issues a Machine-Readable Compliance Certificate (MRCC) — a cryptographically signed readiness attestation per product × regulation × version.
For compliance officers: the MRCC is your external-facing compliance artefact. It is verifiable in 30 seconds by buyers and regulators. It is not an official EU certification — it is a NexCyber-issued readiness attestation that your technical file and evidence layer support.
Penalty exposure — what you are managing against
| Regulation | Maximum penalty | Trigger | |---|---|---| | AI Act | €35M / 7% global turnover | Prohibited practice (Art. 5) or high-risk non-compliance | | CRA | €15M / 2.5% global turnover | Annex I essential requirement violation | | NIS2 | €10M / 2% turnover | Art. 21 security measures or Art. 23 reporting failure | | GDPR | €20M / 4% global turnover | Data protection violation | | DORA | Competent authority discretion | ICT risk management failure |
→ CRA penalty exposure calculator → CRA penalties — full breakdown
Tools
- CRA Scope Checker — product scope determination
- NIS2 Applicability Checker — entity classification
- DORA Applicability Checker — financial entity scope
- Penalty Calculator — maximum exposure by regulation
- Responsibility Mapper — RACI across 5 regulations by role
Related answers
- Audit-ready evidence for CRA
- NIS2 × CRA overlap
- CRA penalties
- NIS2 implementation guide
- DORA TLPT guide
NexCyber — EU Market Access Compliance Platform