ConformOps

Static repository analysis that produces EU Cyber Resilience Act evidence, SBOM inventory and draft technical documentation.

CompanyCyber Resilience Act ComplianceCloud

Pricing: Free preview for up to 2 products; Full Assessment EUR 99 one-time per product; Continuous EUR 79 per month or EUR 790 per year per product; Portfolio EUR 249 per month or EUR 2,490 per year for 5 products, then EUR 49 per month per additional product.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed September 2026 · How we review listings

What is ConformOps?

ConformOps is a cloud-hosted service that reads a software repository's manifests, lockfiles, CI configuration, SBOMs and security documentation, maps what it finds to the EU Cyber Resilience Act and returns an evidence package. Analysis is static; the site states that no code is executed and that detected secrets are redacted before storage. Input is via a read-only GitHub App, a ZIP upload or individual files, and outputs include a CycloneDX inventory, Annex-oriented working documents, traceability and register CSVs and an evidence workbook, with each finding classified as evidenced, partial, gap or not applicable. The site states that ConformOps does not certify products, issue declarations, replace a notified body or make legal conclusions. Pricing is published: a free preview for up to two products, a one-time Full Assessment at EUR 99 per product, Continuous monitoring at EUR 79 per month per product, and a Portfolio plan at EUR 249 per month for five products. The legal page states the service is operated by Simone Laudani in Italy; no company registration or VAT number is published.

Best for: Small software teams that want a first, evidence-led CRA readiness pass on a repository at a fixed published price.
Pros
  • Published pricing with a free preview tier and a EUR 99 one-off entry point
  • Read-only, non-executing analysis with secrets redacted before storage
  • Clear published statement of what the product does not do (no certification, no legal conclusions)
Things to check
  • Operated by an individual in Italy; no company registration, VAT number or founding date is published
  • No EU-only data residency promised, no SOC 2 or ISO 27001 mentioned, and no independent reviews found

Reported in public reviews and vendor documentation. See sources below.

Key Features

Static analysis of manifests, lockfiles, CI configuration and security documentation; no code executed
Repository input via read-only GitHub App, ZIP upload or individual files, with secrets redacted before storage
CycloneDX inventory output; accepts supplied CycloneDX or SPDX SBOMs as input
Findings classified as evidenced, partial, gap or not applicable, with file and line level evidence links
Annex-oriented working documents, traceability and register CSVs and an evidence workbook
Release delta re-runs showing changed coverage and invalidated conclusions
Daily dependency and OSV vulnerability monitoring on the Continuous plan
Optional AI (OpenAI) can propose evidence mappings but cannot mark a requirement as met

Do you work at ConformOps? to confirm the details or send us a correction.

Quick Info
PricingFree preview for up to 2 products; Full Assessment EUR 99 one-time per product; Continuous EUR 79 per month or EUR 790 per year per product; Portfolio EUR 249 per month or EUR 2,490 per year for 5 products, then EUR 49 per month per additional product.
ModelOne-off assessment plus subscription, with free preview tier
CloudYes
Self-HostedNo

Last updated: Sep 8, 2026