Software, consultant, or both?
A consultant is strongest where judgment, interpretation, organisational work or third-party conformity expertise is needed. Software is strongest where evidence, releases, dependencies and records have to remain current repeatedly. Many manufacturers need both, but not necessarily for the same work.
Where each earns its place.
| Work to be done | CRA compliance software | CRA consultant |
|---|---|---|
| Choose by the work, not by the label | ||
| Scope and classification | Structures product facts and highlights questions to resolve. Cannot approve the final legal conclusion. | Can investigate intended use, market role and category, challenge assumptions and advise on interpretation. |
| Risk assessment | Organises technical evidence, unresolved questions and recorded decisions. Cannot accept risk for the manufacturer. | Can facilitate threat and risk workshops and help assess the adequacy of controls with engineering teams. |
| Evidence collection | Collects supported repository material and keeps provenance attached to the release and assessment. | Can identify evidence the organisation needs, assess its substance and obtain material outside repositories. |
| SBOM and dependencies | Ingests supported inventories and correlates identifiable exact versions with vulnerability intelligence. Completeness and affectedness still need review. | Can review inventory coverage and vulnerability processes. Depth depends on the consultant's technical expertise and tooling. |
| New releases | Repeats supported collection and comparisons, exposing changed evidence and decisions that need review. | Can review material changes and revisit assumptions at agreed milestones. Continuous upkeep must be in the engagement scope. |
| Organisational work | Records owners, actions and history. A record alone does not establish an effective process. | Can help establish responsibilities, support policies, supplier processes, training and incident exercises. |
| Technical documentation | Drafts and regenerates structured records from available inputs. Missing evidence remains missing. | Can review whether the technical file tells a defensible, complete story and commission missing specialist work. |
| Article 14 reporting | Can calculate clocks from recorded inputs and organise case evidence. ConformOps records events; it does not submit reports. | Can advise on triggering conditions and help prepare a response under an agreed incident engagement. The manufacturer retains its duties. |
| Conformity assessment | Tracks route facts, required approvals and external evidence. Cannot perform notified-body assessment. | Can advise on the route and prepare for external assessment. A consultant is not automatically a notified body. |
| Cost and procurement | Compare published plan scope, product coverage, source access, ongoing updates and exports. | Request a scoped quote covering deliverables, specialist work, update cadence and incident availability. No universal labour estimate is assumed here. |
Connect CI/CD evidence, a release gate and signed webhooks with the Continuous CLI and API.
When a consultant should come first
Start with qualified help when your main uncertainty is whether the product is in scope, how it should be classified, which conformity route applies, or whether your security and organisational processes are adequate. Ask about experience with your product category and who will perform any legal or specialist assessment. Software cannot resolve uncertainty merely by filling a checklist.
When software should come first
If accountable people already own the scope and process, but evidence is scattered across repositories and releases, software can make recurring collection and record keeping more manageable. Engineering still has to fix vulnerabilities, test controls and supply evidence that a repository does not contain. Choose a tool whose collection limits and failure states you can inspect.
How to use both without paying for the same work twice
Agree the evidence model with your consultant: product boundary, required records, owners, review triggers and acceptance criteria. Keep release evidence in ConformOps between engagements. At the next review, share the completed baseline, changed evidence, unresolved gaps and recorded decisions. Ask the consultant to review the material changes and specialist questions. This is a workflow proposal, not a promise of billable hours saved.
What stays with the manufacturer?
Appointing a consultant or buying software does not transfer the manufacturer's CRA obligations. Article 13 places risk assessment, technical documentation and conformity duties on the manufacturer; Article 14 addresses reporting. A general consultancy engagement does not satisfy an applicable requirement for notified-body work under Article 32.
The duties belong to the manufacturer.
Regulation (EU) 2024/2847 is binding law. This page explains task boundaries; it is not a legal opinion on your product.
- Article 13(2), (3) and (12): manufacturer risk assessment, documentation and conformity obligations.
- Article 14: reporting of actively exploited vulnerabilities and severe incidents.
- Articles 28, 30 and 32; Annexes V and VII: declaration, CE marking, assessment procedures and technical documentation.
Reporting clocks depend on the event and recorded awareness facts. Read the Article 14 reporting guide for the distinct deadlines.