Continuous CRA Monitoring

CRA compliance doesn't stop after the audit.

Know when a new vulnerability changes the status of your product.

Built for manufacturers of embedded, IoT and connected products. KONFORMA monitors your releases, helps you decide what's affected, and keeps CRA evidence ready for customers and reporting.

4 questions · 1 minute · no signup · no upload needed

Already have a CRA assessment? Keep it current.

Gateway XMonitoring active

1 finding needs attention

OpenSSL

Firmware 2.5

Actively exploited

Review impact →

3 releases monitoredLast checked 14 min ago

OSV · NVD · CISA KEV

Monitoring example · sample data
OSV + NVD + CISA KEV CycloneDX + SPDX EU hosted No source code uploaded Release-specific monitoring SHA-256 evidence

CRA reporting obligations start on 11 September 2026.

Actively exploited vulnerabilities and severe security incidents can trigger 24h and 72h reporting timelines.

Source: European Commission
Prepare your reporting workflow →

From a new vulnerability to a documented decision.

Connect once. Keep monitoring, deciding and updating evidence throughout each release's support period.

1
Connect

Upload a CycloneDX or SPDX SBOM, or connect GitHub.

2
Monitor

Check release components against OSV, NVD and CISA KEV on your plan’s schedule.

3
Decide

Investigate findings. Record affected or not affected, with a reason.

4
Report

Assess reporting duties and prepare the 24h / 72h notifications.

5
Prove

Generate a release-specific CRA report and verifiable Evidence Pack.

New finding → review the affected release → update the evidence → keep monitoring.

Upload an SBOM or connect GitHub when you're ready. We never fetch your source code.

The difference

Your old releases don't disappear when you ship a new one.

KONFORMA monitors every supported release against its own inventory, vulnerabilities and decisions.

Built for real products, not just repositories.

own inventory
own decisions
own incidents
own support period
own Evidence Pack
own report
PRODUCT MODEL
Gateway X
Rev A · Firmware 2.4 Support until 2029
Rev A · Firmware 2.5 3 findings · 1 active
Rev B · Firmware 3.1 No open findings
Evidence Pack · YOU → CUSTOMER

Your customer asks for evidence.

Generate an Evidence Pack from your monitored release data and share it with your customer. No gathering the same files again.

  1. Your release data

    Gateway X · Firmware 3.1

    • SBOM
    • Vulnerability decisions
    • Support period
    • Incident evidence
    • Product information
  2. Generate Evidence Pack

    From the data you already maintain.

  3. Evidence Pack

    Gateway X

    Firmware 3.1

    Generated today · SHA-256

    Authenticity verifiable ✓

    Share with customers →

From monitored product data to customer-ready evidence. Flow with sample data.
How Evidence Packs work →
KONFORMA Exchange · SUPPLIER → YOU

You ask your supplier for evidence.

Stop chasing SBOMs and CRA evidence by email. Send a request, let your supplier respond for free, and follow the shared status over time.

  1. You request evidence

    One link for the evidence you need.

  2. Supplier responds

    Upload an SBOM or connect GitHub. A free account is all it takes.

  3. KONFORMA validates

    Validate the inventory and check for vulnerabilities.

  4. You see live status

    See what is shared, missing or needs renewal.

One inventory. Multiple customers.

Suppliers maintain product data once and reuse it for further requests.

One request. Live status.

Buyers see when shared evidence is missing or needs renewal.

Explore Exchange →

Already completed your CRA assessment? Keep it current.

Your consultant helps assess the product. KONFORMA monitors releases between assessments, records new decisions and gives your next review up-to-date evidence.

A CRA report is a snapshot. Your products keep changing.

Working with a consultant? See how it fits →

Pricing

Continuous monitoring, priced by your product portfolio.

One annual subscription. No per-seat pricing. No extra monitoring fees.

Free Check

€0

One-time check · no ongoing monitoring

Understand your first product.

  • 1 product · 1 release
  • SBOM upload / GitHub import
  • Vulnerability snapshot
  • Product overview
  • Sample report & Evidence Pack
Check my product →
Recommended plan

Professional

€7,500 / year

Billed annually

For manufacturers operating connected products.

  • 10 products · 50 active releases
  • Daily vulnerability monitoring
  • VEX + Incident Cockpit
  • Unlimited reports & Evidence Packs
  • Teams · API · audit trail
Choose Professional →

Business

€15,000 / year

Billed annually

For larger portfolios and security teams.

Everything in Professional, plus:

  • 30 products · 200 active releases
  • Monitoring every 6 hours
  • Unlimited users
  • SSO & advanced roles
  • SLA + priority support
Talk to Sales →

Prices exclude applicable VAT.

Enterprise

More products, multiple organizations or specific requirements? We tailor volumes, onboarding and SLA to your environment.

Contact Sales →

KONFORMA Exchange

Supplier evidence workflows for manufacturers and OEMs. Available separately; suppliers respond for free.

Discuss Exchange →

Frequently asked

What happens in the free check?+

Answer four questions about your product and software inventory in about a minute. No signup or upload is required. You get a recommended next step: upload an SBOM, connect GitHub, create an inventory or get help with onboarding.

We already have a CRA consultant. Where does KONFORMA fit?+

Your consultant helps assess your product and plan compliance. KONFORMA monitors supported releases between assessments, helps your team triage new findings and keeps evidence ready for the next review.

How often are my releases monitored?+

Paid plans check release inventories against OSV, NVD and CISA KEV: daily on Professional and every six hours on Business. The Free Check is a starting assessment; ongoing monitoring requires a paid plan.

Does KONFORMA guarantee legal compliance?+

No. KONFORMA provides structure, monitoring and evidence. Responsibility for placing a product on the market stays with the manufacturer.

Does my source code leave my environment?+

On GitHub import we fetch the inventory GitHub generates, not your code.

Is KONFORMA suitable for embedded products?+

Yes, firmware, C/C++ libraries and long support periods are the core case.

Where is the data hosted?+

In the European Union. Details are in the security documentation.

Does KONFORMA replace a notified body?+

No. KONFORMA supports the process and the evidence, but does not replace a conformity assessment body.

Your next vulnerability won't wait for the next audit.

Start with four questions. Get a practical path to monitoring your first product.

Free · 1 minute · no signup · no upload needed