Know when a new vulnerability changes the status of your product.
Built for manufacturers of embedded, IoT and connected products. KONFORMA monitors your releases, helps you decide what's affected, and keeps CRA evidence ready for customers and reporting.
4 questions · 1 minute · no signup · no upload needed
Already have a CRA assessment? Keep it current.
1 finding needs attention
Firmware 2.5
Actively exploited
Review impact →
OSV · NVD · CISA KEV
Catch and assess new vulnerabilities for each release.
Use the product data you already maintain.
One request by link. Shared status in one place.
Actively exploited vulnerabilities and severe security incidents can trigger 24h and 72h reporting timelines.
Source: European CommissionConnect once. Keep monitoring, deciding and updating evidence throughout each release's support period.
Upload a CycloneDX or SPDX SBOM, or connect GitHub.
Check release components against OSV, NVD and CISA KEV on your plan’s schedule.
Investigate findings. Record affected or not affected, with a reason.
Assess reporting duties and prepare the 24h / 72h notifications.
Generate a release-specific CRA report and verifiable Evidence Pack.
New finding → review the affected release → update the evidence → keep monitoring.
Upload an SBOM or connect GitHub when you're ready. We never fetch your source code.
KONFORMA monitors every supported release against its own inventory, vulnerabilities and decisions.
Built for real products, not just repositories.
Generate an Evidence Pack from your monitored release data and share it with your customer. No gathering the same files again.
Gateway X · Firmware 3.1
From the data you already maintain.
Gateway X
Firmware 3.1
Generated today · SHA-256
Authenticity verifiable ✓
Share with customers →
Stop chasing SBOMs and CRA evidence by email. Send a request, let your supplier respond for free, and follow the shared status over time.
One link for the evidence you need.
Upload an SBOM or connect GitHub. A free account is all it takes.
Validate the inventory and check for vulnerabilities.
See what is shared, missing or needs renewal.
Suppliers maintain product data once and reuse it for further requests.
Buyers see when shared evidence is missing or needs renewal.
Your consultant helps assess the product. KONFORMA monitors releases between assessments, records new decisions and gives your next review up-to-date evidence.
A CRA report is a snapshot. Your products keep changing.
Working with a consultant? See how it fits →Pricing
One annual subscription. No per-seat pricing. No extra monitoring fees.
€0
One-time check · no ongoing monitoring
Understand your first product.
€7,500 / year
Billed annually
For manufacturers operating connected products.
€15,000 / year
Billed annually
For larger portfolios and security teams.
Everything in Professional, plus:
Prices exclude applicable VAT.
More products, multiple organizations or specific requirements? We tailor volumes, onboarding and SLA to your environment.
Contact Sales →Supplier evidence workflows for manufacturers and OEMs. Available separately; suppliers respond for free.
Discuss Exchange →Answer four questions about your product and software inventory in about a minute. No signup or upload is required. You get a recommended next step: upload an SBOM, connect GitHub, create an inventory or get help with onboarding.
Your consultant helps assess your product and plan compliance. KONFORMA monitors supported releases between assessments, helps your team triage new findings and keeps evidence ready for the next review.
Paid plans check release inventories against OSV, NVD and CISA KEV: daily on Professional and every six hours on Business. The Free Check is a starting assessment; ongoing monitoring requires a paid plan.
No. KONFORMA provides structure, monitoring and evidence. Responsibility for placing a product on the market stays with the manufacturer.
On GitHub import we fetch the inventory GitHub generates, not your code.
Yes, firmware, C/C++ libraries and long support periods are the core case.
In the European Union. Details are in the security documentation.
No. KONFORMA supports the process and the evidence, but does not replace a conformity assessment body.
Start with four questions. Get a practical path to monitoring your first product.
Free · 1 minute · no signup · no upload needed