- Tell you spreadsheets are unprofessional.
- Invent hours saved or a cost-of-manual-work figure. We publish no hour estimates, because we have no defensible basis for one.
- Suggest software makes anyone CRA compliant.
Your spreadsheet is a real compliance system. Until it isn't.
Most CRA work today runs on a shared sheet, a folder of documents and one person who remembers everything. That is a legitimate starting point, and for some products it is genuinely enough. This page is about the specific point where it stops being enough - and about the parts no software takes off your hands.
Why a spreadsheet is a perfectly rational starting point.
Start without procurement.
No procurement, no security review, no vendor. You can start on a Tuesday afternoon and have something by Wednesday.
One grid, no training.
Engineering, legal, sales and an external consultant can all read the same grid without training or a licence.
Add the column you need.
No product's data model constrains you. When your understanding of the regulation changes, you add a column.
Nothing is derived behind your back.
Every cell was typed by someone, and you can see all of it at once.
A spreadsheet can carry a lot. It cannot carry everything forever.
For one small product with few releases, a slow dependency profile and one person genuinely accountable, a well-kept spreadsheet can carry CRA evidence work for a long time. The boundary is specific: a second product, a second person who has to answer for the record, or the first reviewer who asks where a claim came from and when it was last true.
One product
A narrow, stable scope is easy to keep visible.
One owner
One person can still explain every cell.
One release rhythm
Manual updates are still proportional.
Then the record needs lineage
Evidence, approvals and changes must survive the next release and the next reviewer. ConformOps offers an inspectable lineage view with release, run and artifact selection, bidirectional recorded links and visible missing or invalidated state. Older runs require retained Continuous history access.
The same twelve jobs, done two ways.
Left column: a disciplined manual system, not a bad one. Right column: implemented ConformOps behaviour.
On narrow screens each job becomes a card with both answers stacked beneath it. Nothing is hidden behind a horizontal scroll.
Two lists. Read them honestly and you will know.
The scope is small, stable and owned.
- You have one small product, in one CRA scope.
- Releases are infrequent, and dependencies barely move between them.
- One person owns compliance, knows the product, and is not about to leave.
- Nobody outside the company has yet asked to see the evidence.
- You are still mapping initial scope, and the shape of the work keeps changing.
- You do not need automation yet - you need to understand the obligation.
The record has to outlive a person and a release.
- There are several products, or several active releases of one.
- Evidence is scattered across repositories, CI systems and wikis.
- Vulnerability handling has become continuous rather than occasional.
- SBOMs and affectedness decisions change with every release.
- More than one person approves things, and you need to know who did.
- Customers or auditors have started requesting evidence directly.
- Article 14 operational readiness has to actually exist, not be a plan.
- You need to reproduce, months later, why a decision was made and on what basis.
What does not change
Software does not absorb your accountability. This is the part of the comparison a vendor is tempted to blur. Moving off a spreadsheet changes how evidence is collected and kept. It does not move a single legal responsibility.
Still you
Deciding final scope, classification and substantial modification
Performing and signing off the cybersecurity risk assessment
Judging whether a vulnerability affects your release
Still you
Deciding a report is due, and submitting it to a CSIRT or ENISA
Completing the technical documentation and issuing the declaration
Notified-body assessment, certification and CE marking are outside both.
Read the units before the numbers.
One side has a price. Both sides have a cost. You can compare the licence honestly. You cannot compare the labour honestly without knowing your own team, so we have left that arithmetic to you.
Spreadsheet and manual process
€0
Finding evidence again each release · Transcribing SBOM and vulnerability data by hand · Chasing owners for status, then re-checking it · Reconstructing the reasoning when someone asks later · The cost of a gap nobody noticed had re-opened
ConformOps · published prices
Archiving releases the active Free allocation.
No seats, no scan credits. Releases are unlimited within a product. Cancelling never deletes evidence - the product becomes a read-only historical record.
A manual system is still a system.
The page compares a disciplined spreadsheet process with implemented ConformOps behaviour. It does not claim a licence replaces the work only a manufacturer can do.
No invented savings
We do not publish hours saved or a cost-of-manual-work estimate. Your team is the only defensible source for that arithmetic.
No compliance shortcut
Software changes evidence operations. It does not decide scope, classification, risk, affectedness, reporting or declaration for you.
Use the smallest thing that works
If a well-kept sheet is enough for your product and your accountability model, keep it. Move when the record's demands change.
Readiness assistance, not legal certification. ConformOps does not give legal advice, issue declarations of conformity or remove manufacturer accountability.