On this page
- Keep the assessment tied to an identifiable product and release.
- Review evidence gaps, security findings and approval gates separately.
- Use Continuous for named releases, ongoing monitoring and reporting operations.
- The manufacturer retains legal decisions, external submissions and declaration responsibility.
What problem does ConformOps solve?
A typical team already has useful material: source control, test outputs, an SBOM, a security policy and product specifications. The difficulty is showing which material supports which claim for which version. A current policy can describe a future process; a successful test can belong to a different build. Putting both in a shared folder does not resolve those differences.
ConformOps holds a release-bound assessment record. It connects source evidence, component information, requirement findings, recorded approvals and exported artifacts. Its purpose is technical evidence management and an accountable workflow around that evidence. It is not a replacement for engineering tests or an automatic determination that a product complies with the CRA.
Start with the product, then collect evidence
Record intended purpose, distribution, market role, proposed category and support-period facts. Product classification and applicability assessment depend on what you supply and how it functions, not just its programming language. ConformOps can support the assessment and expose missing facts; an accountable reviewer must settle the legal conclusion.
The Commission's manufacturer guidance places risk assessment, implementation, documentation and conformity assessment within the manufacturer's work. In ConformOps, source findings are inputs to that work. They cannot establish a commercial supply arrangement or prove how a deployed system behaves.
A useful first exercise is one real product with a bounded set of evidence. Open an unresolved requirement and check whether its supporting material is relevant, current and sufficient. Assign the missing work instead of trying to improve a headline percentage.
Bring the software bill of materials into the same record
You can supply CycloneDX JSON or SPDX JSON as release evidence. When usable, the supplied software bill of materials (SBOM) becomes the assessment's release inventory; repository-derived information remains a separate source of observations. ConformOps shows document quality and discrepancies without claiming that an accepted file is a complete account of the shipped product.
Vulnerability monitoring adds another kind of evidence. An OSV package match and CISA KEV exploitation context help a reviewer investigate, but do not decide product affectedness or Article 14 reportability. Failed or stale intelligence remains visible. This matters when a dashboard would otherwise look reassuring simply because a lookup did not finish.
Turn readiness into named work
The readiness overview separates evidence coverage and unresolved requirements, human approvals, intelligence health, reporting operations and access state. A missing support decision and an affected library call for different actions. Teams can assign gaps, inspect recorded decisions and follow the corresponding workflow instead of treating every issue as the same kind of risk.
Owner and Admin roles hold accountable approval authority; an ordinary Member can work on product evidence without gaining the right to approve a legal gate. AI assistance may propose explanations or mappings. It does not approve classifications, accept residual risk or sign a declaration.
Prepare Article 14 operations and controlled documents
Continuous provides reporting cases, case events and a named runbook. These support Article 14 vulnerability reporting readiness, including responsibility and deadline records. ConformOps does not submit notifications to ENISA or a CSIRT. A named person must perform that external step and retain the receipt. See the deadline-tracking guide for the distinct reporting clocks.
Exports include working documentation and evidence records with release and assessment provenance. Annex II instructions, Annex VII working records and an unsigned Annex V declaration template have different purposes. A generated artifact is not a conformity assessment, and the necessary approval and external-assessment work remains explicit.
Choose a starting point that matches your work
Use the free preview to inspect a focused evidence sample. Full Assessment supports the initial premium repository assessment. Continuous adds named release updates, ongoing monitoring, CI/CD integration and Article 14 operations. Check current plans before assuming a particular workflow is included.
ConformOps fits a team that needs its engineering and compliance records connected. Keep specialist security testing and legal or conformity expertise where required. Review the data-residency disclosure, which does not claim EU-only processing. Then see the workflow using a product whose evidence you are authorised to share.
Frequently asked questions
Is ConformOps a CRA certification service?
No. It supports evidence collection, assessment workflows and controlled documentation. The manufacturer retains conformity responsibility, and any required external assessment or certification must be completed through the appropriate process.
Does ConformOps replace an SBOM generator?
It can derive component information from supported repository files and accept a supplied CycloneDX JSON or SPDX JSON SBOM. Build and artifact tools may observe shipped components that repository evidence cannot, so keep them where they add coverage.
Does ConformOps send Article 14 reports?
No. Continuous supports the case record, deadlines and runbook. An authorised person submits through the applicable reporting channel and records the submission evidence.