Solutions · By Role · Compliance Officer

Compliance Officer

Gap assessment to audit-ready posture across CRA, NIS2, DORA, AI Act and RED — one platform, article-level traceability.

Pain

Five regulations, five timelines, five evidence formats — cannot be managed with a spreadsheet.

What you want

Scope determination per regulation, gap identification, and an audit-ready package on demand.

What you get

144-obligation gap assessment, article-level traceability, evidence layer with 10-year retention.

The compliance officer problem

Five EU regulations. Overlapping scopes. Different timelines. Different evidence formats. Different regulators. CRA is a product regulation enforced by market surveillance authorities. NIS2 is an entity obligation enforced by national cybersecurity agencies. DORA is enforced by financial supervisors. The AI Act by national AI authorities and the European AI Office.

You cannot manage this with a spreadsheet. You need: scope determination per regulation, obligation mapping per article, gap identification, evidence collection, and an audit-ready package that can be handed to any of the five regulatory regimes on demand.


What NexCyber gives compliance officers

Gap assessment — 144 obligations, article-level

The NexCyber Engine assesses your organisation against 144 obligations across CRA, NIS2, AI Act, DORA, and RED. Each obligation is traceable to its source article — not to a framework category.

Output: a gap assessment report that identifies:

  • Obligations not yet satisfied
  • Obligations partially satisfied (with evidence gaps)
  • Obligations satisfied with evidence
  • Obligations not applicable (with scope rationale)

This is the input to your remediation roadmap. It is also the structure your auditor will use.

Evidence collection — not a checklist

Compliance programmes fail at audit when the evidence does not match the assertion. "We have a CVD policy" fails if the policy is a PDF that no one monitors. "We have an SBOM" fails if the SBOM is incomplete, unsigned, or stale.

NexCyber's Evidence Layer:

  • Stores artefacts with hash verification (tamper-evident)
  • Tracks completeness per obligation
  • Flags stale evidence (SBOM not updated since last release, CVD policy not reviewed in 12 months)
  • Retains all artefacts for 10 years (CRA Article 31 requirement)

Regulation-by-regulation posture

CRA posture checklist for compliance officers:

  • [ ] Product scope confirmed (Default / Important Class I / Important Class II)
  • [ ] Annex I Part I security requirements gap-assessed
  • [ ] SBOM generated and complete (transitive depth, signed)
  • [ ] CVD policy published and operationally active
  • [ ] Vulnerability log maintained
  • [ ] Conformity assessment route selected
  • [ ] Technical file compiled (9 artefacts)
  • [ ] EU Declaration of Conformity drafted
  • [ ] ENISA notification workflow documented and tested (before Sept 2026)

NIS2 posture checklist:

  • [ ] Entity scope confirmed (essential / important)
  • [ ] Art. 21(2) 10 security measures gap-assessed
  • [ ] Art. 20 management approval documented
  • [ ] Incident reporting workflow (24h/72h/30d) tested
  • [ ] Supply chain security measures evidenced
  • [ ] Evidence retained per national transposition requirements

NIS2 implementation guide — 8 stepsCRA audit-ready evidence — 9-artefact technical file

Cross-regulation overlap — one evidence set

NIS2 and CRA share 6 obligation areas. One SBOM can satisfy both CRA Annex I Part II §1 and NIS2 Article 21(d). One CVD policy — structured correctly — satisfies both CRA Article 14 and ETSI EN 303 645 §5.2 (RED).

NexCyber maps overlaps explicitly so your evidence is not duplicated unnecessarily. The NexCyber Engine identifies which artefacts satisfy multiple obligations.

NIS2 × CRA overlap — shared evidence strategy

MRCC — the auditable attestation

Once your evidence layer is complete, NexCyber issues a Machine-Readable Compliance Certificate (MRCC) — a cryptographically signed readiness attestation per product × regulation × version.

For compliance officers: the MRCC is your external-facing compliance artefact. It is verifiable in 30 seconds by buyers and regulators. It is not an official EU certification — it is a NexCyber-issued readiness attestation that your technical file and evidence layer support.

MRCC platform


Penalty exposure — what you are managing against

| Regulation | Maximum penalty | Trigger | |---|---|---| | AI Act | €35M / 7% global turnover | Prohibited practice (Art. 5) or high-risk non-compliance | | CRA | €15M / 2.5% global turnover | Annex I essential requirement violation | | NIS2 | €10M / 2% turnover | Art. 21 security measures or Art. 23 reporting failure | | GDPR | €20M / 4% global turnover | Data protection violation | | DORA | Competent authority discretion | ICT risk management failure |

CRA penalty exposure calculatorCRA penalties — full breakdown


Tools


Related answers


NexCyber — EU Market Access Compliance Platform

Versus what you do today

Big4 consulting · In-house spreadsheet · NexCyber.

DimensionBig4 / ConsultingIn-house spreadsheetNexCyber
First assessment delay
4–8 weeks
2–6 weeks
5 minutes
Cost per regulation cycle
€90k–170k
€30k+ hidden
Included
Reproducibility
Slide deck of the day
Depends on editor
Deterministic, identical re-runs
Article-level traceability
Footnote
Often missing
Live link to EUR-Lex
Update when law changes
Re-billed mission
Restart from scratch
Automatic, MRCC re-signed
Deliverable format
Static PDF
XLSX/Word
PDF + MRCC machine-verifiable
Auditor verification
Email + chase
Not verifiable
sha256 verified in seconds
Multi-regulation simultaneous
1 mission per regulation
Duplicates & conflicts
5 regulations, 1 source of truth
New product line evolution
Re-billed mission
Full re-entry
Clone + delta
Run free assessment