Documentation software explains the Cyber Resilience Act. Consulting walks you through it. KONFORMA gets it done, with live data from your real releases. Here's the sober comparison.
KONFORMA | Regulus | activeMind (CRA SaaS) | |
|---|---|---|---|
| Availability | ✔ Live, usable today, self-service | Early-access waitlist | Available, tied to a consulting offer |
| Approach | Operational cockpit: continuous monitoring of real product data per release | Applicability check, classification, annex documentation with templates | Product classification, vulnerability management, conformity documentation |
| Pricing (public) | €0 / €299 / €499 / €999 per month, transparent | n/a | n/a |
| SBOM import (CycloneDX/SPDX) with quality score & drift detection | ✔ incl. GitHub auto-import | explains SBOM requirements; import n/a | n/a |
| Nightly vulnerability monitoring (OSV, NVD, CISA KEV) | ✔ three sources, automatic | n/a | "vulnerability management" per website; sources/depth n/a |
| C/firmware library matching (alias normalisation) | ✔ openssl/libssl/OpenSSL → one match | n/a | n/a |
| Incident cockpit with 24h/72h deadlines & pre-filled ENISA report drafts | ✔ | workflow explained editorially | n/a |
| EU Declaration of Conformity (Annex V) from live data per release | ✔ with a draft gate until every obligation is met | document templates | ✔ conformity documentation |
| Publicly verifiable evidence (SHA-256, verification link for buyers) | ✔ | n/a | n/a |
| Supply-chain exchange: OEM requests, supplier delivers, status live | ✔ unique | n/a | n/a |
| Onboarding | Minutes, upload the inventory, done | Waitlist | Consulting call |
Sources: publicly accessible websites of the named vendors (goregulus.com, activemind.cloud), as of July 2026. "n/a" = not evident on the vendor's website. No guarantee; vendors evolve their products. Regulus® and activeMind® are trademarks of their respective owners.
A filled-in questionnaire documents the day it was filled in. KONFORMA checks your components against OSV, NVD and CISA KEV every night, your Declaration of Conformity reflects last night’s data, not last quarter’s.
The same C library ships as openssl, libssl or OpenSSL depending on the source. Generic scanners miss that. KONFORMA normalises aliases and finds the match. For makers of controllers, sensors and devices, that’s the difference between "looks clean" and "is clean".
Every evidence pack carries a SHA-256 hash and a public verification link. Your buyer doesn’t have to trust you, they can verify it. No other CRA tool we know of offers that.
The CRA is a supply-chain law: your OEM asks you for evidence, you ask your suppliers. KONFORMA Exchange maps exactly this flow: request by link, free upload for the supplier, live status for the buyer. Instead of PDFs in inboxes.
Upload your software inventory, instantly see components and actively exploited vulnerabilities. Free, no sign-up.