What NexCyber does not replace
TL;DR — NexCyber is a readiness platform. It makes the structured side of EU compliance fast, evidenced, and reusable. It is deliberately not a law firm, a notified body, or an auditor — and it does not issue legal certificates of conformity. Knowing this boundary is what lets you trust what it does provide.
Why we state this plainly
Compliance software that blurs the line between "readiness" and "certified compliance" does its customers a disservice. NexCyber is precise about its boundary so that the signals it produces — reports, the MRCC, the Trust Passport — mean exactly what they say and can be relied upon.
What NexCyber does NOT replace
Your legal counsel. Binding interpretation of how an obligation applies to your specific situation stays with your lawyers. NexCyber gives a neutral, product-perspective view of the frameworks; it does not give legal advice.
A notified body. Where a regulation requires conformity assessment by an accredited body (for example, higher-risk AI systems, certain critical products, or radio equipment), that assessment goes through the notified body — not through NexCyber.
Your CE declaration. The declaration of conformity is yours to sign. NexCyber helps you assemble the readiness evidence behind it; it does not issue it for you.
An independent audit verdict. An accredited auditor's opinion is theirs to give. NexCyber structures and evidences your posture; it does not substitute for the audit.
Your incident and breach notifications. You — or your CSIRT/DPO — file regulatory notifications. NexCyber can help you prepare the workflow; it does not file on your behalf.
Your internal security judgement. NexCyber informs decisions; it does not make them for your CISO.
What NexCyber DOES provide
Within that boundary, NexCyber provides real value:
- A structured, evidenced, reusable readiness posture across five EU frameworks
- A prioritised gap you can act on
- Verifiable proof — reports, the MRCC, the Trust Passport — that buyers and regulators can check in seconds
- A continuous view that stays current as regulations and your product change
The MRCC and Trust Passport are readiness artefacts, not legal certificates of conformity. They demonstrate that your compliance programme is real and live; they do not certify legal compliance.
The boundary at a glance
| We provide | We do not replace |
|---|---|
| ▸ Structured readiness analysis | Your legal counsel |
| ▸ Prioritised gap assessment | A notified body's conformity assessment |
| ▸ Verifiable proof (report, MRCC, Passport) | Your CE declaration |
| ▸ Continuous, current posture | An independent auditor's verdict |
| ▸ Evidence organisation and reuse | Your regulatory notifications |
| ▸ Support and guidance | Your CISO's judgement |
Read the left column as "what we make fast and reusable," and the right as "what remains a human or accredited-body responsibility."
Where readiness ends and certification begins
── NexCyber's zone ──────────▶│◀────── Outside our zone ──────
Scope · Gap · Evidence · │ Legal interpretation ·
Readiness proof (MRCC, │ Notified-body assessment ·
Trust Passport) │ CE declaration · Audit verdict
│
"structured, evidenced, │ "binding, accredited,
reusable, verifiable" │ legally conclusive"
We make everything to the left of the line fast and credible. Everything to the right stays where accountability requires it to be.
Frequently asked questions
So is a NexCyber MRCC worthless for audits? The opposite. A verifiable MRCC gives an auditor or buyer a fast, credible starting point — it just is not itself the audit verdict or a legal certificate. It shortens the process without pretending to be the destination.
Why be so explicit about limits? Because over-claiming would make our signals meaningless. Precision is what makes a verifiable MRCC worth trusting.
Can NexCyber help us prepare for a notified-body assessment? Yes — organising the readiness evidence behind it is exactly what the platform does. The assessment itself remains with the accredited body.
If NexCyber does not certify compliance, what is the point? The point is speed and credibility on the large, structured part of compliance: knowing what applies, seeing your gap, organising evidence, and producing proof buyers can verify. That work is real, time-consuming, and reusable — and it is where a platform adds the most value. The accredited, legally-conclusive steps stay with the right authorities, which is what keeps the whole system trustworthy.
Does using NexCyber reduce our legal risk? It helps you understand and evidence your posture, which supports better decisions — but it does not transfer or remove legal responsibility. Final accountability, and any binding interpretation, stays with you and your advisors.
How this protects you as a buyer of NexCyber
A vendor that is honest about what it does not do is easier to trust with what it does. When you present a NexCyber MRCC or Trust Passport to your own customers and regulators, the clarity of this boundary works in your favour: your stakeholders understand exactly what the signal asserts and what it does not, which makes it more credible, not less. Over-claiming vendors create downstream risk for their customers when a "certificate" turns out to mean less than it implied. NexCyber's precision means the artefacts you share never over-promise on your behalf.
Key takeaways
- ▸ NexCyber is a readiness platform, not a law firm, notified body, or auditor.
- ▸ It does not issue your CE declaration, legal interpretation, or an audit verdict.
- ▸ It does provide structured, evidenced, reusable, verifiable readiness.
- ▸ The MRCC and Trust Passport are readiness signals, not legal certificates of conformity.
- ▸ Clear limits are what make the signals credible.
Why the boundary is a feature
Because NexCyber does not over-claim, the signals it produces are credible. A verifiable MRCC means something precisely because it does not pretend to be a notified-body certificate. Clear boundaries make trust possible.
→ Related: What is the MRCC? · What is NexCyber?
NexCyber provides a readiness analysis, not legal advice. Final compliance may require legal review, formal testing, and certification depending on your products and sector.
Last reviewed 2026-07-10.