Short, practical guides for manufacturers of connected and embedded products: no legalese, no jargon. Written by the team behind KONFORMA. Also relevant if you are based outside the EU and sell into it.
Ready-to-copy commands for Syft, Trivy, Yocto and GitHub, forward it to your engineers.
Guide →The first EU law that makes cybersecurity mandatory for connected products.
Read →The "ingredients list" of your software, mandatory under the CRA.
Read →From 11 Sept 2026: actively exploited vulnerabilities must be reported to ENISA fast.
Read →Your classification decides how demanding the conformity assessment is.
Read →Two dates you need to remember.
Read →The one document the CRA formally requires, and what belongs in it.
Read →The CRA requires a public channel for vulnerability reports. Done in an hour.
Read →UK, US, Switzerland: if you sell into the EU, you are fully in scope, often without knowing it.
Read →Upload your software inventory, instantly see components, vulnerabilities and actively exploited risks. Free, no sign-up, nothing is stored.