← Product

Monitoring & assessments

Know why an assessment needs another review.

Monitor vulnerabilities, assess their impact on a release and keep the supporting evidence with the decision. When the recorded basis changes, review the assessment again.

01

Find

Track vulnerability information from OSV, NVD and CISA KEV. Coverage follows those sources; scans run daily on Professional and every six hours on Business.

02

Assess

Review guided questions, record reasoning and evidence, then approve the assessment explicitly. KONFORMA does not approve impact or conformity automatically.

03

Review again

See the specific change that made a decision need review, and compare it with the component, release context and evidence recorded when it was approved.

Assessment excerpt

Review required · OpenSSL 3.0.11

Earlier decision
Not affected · approved for Firmware 2.4
Why review again?
Required supplier evidence expired
Next step
Renew the evidence and review the assessment for Firmware 2.5
Illustrative example · sample data. A KEV listing does not by itself determine a CRA reporting duty.