Supported coverage.
Conformoo does not hide partial implementation behind marketing language. Every pack declares what is implemented, partial, unsupported and interpretation-sensitive.
Australia Security Standards for Smart Devices
Mandatory cybersecurity standards for most consumer-grade relevant connectable products manufactured on/from 4 March 2026.
Ruleset 1.0.0 · reviewed 2026-09-22
Implemented
- core scope
- manufacture-date gate
- password/security-reporting/support-period standards
- manufacturer/supplier role
- Statement of Compliance readiness
Partial
- all product exemptions and nuanced supply-chain cases
Not yet supported
- regulator submission
EU Artificial Intelligence Act
Risk-based requirements for AI systems and general-purpose AI models in the EU.
Ruleset 1.0.0 · reviewed 2026-09-22
Implemented
- AI/GPAI scope screen
- actor-role capture
- prohibited-practice escalation
- Article 50 screen
- Annex III/Annex I high-risk timing screen
- GPAI/systemic-risk screen
Partial
- detailed Article 6 exemption analysis
- all Annex III exceptions
- all sector-specific Annex I interactions
Not yet supported
- legal clearance for prohibited practices
- conformity assessment execution
EU Cyber Resilience Act
Cybersecurity obligations for products with digital elements placed on the EU market. CRA scope, role, Annex III/IV classification, conformity route and timing are evaluated by the pinned CEMarque canonical engine.
Ruleset cemarque-r25-429f565 · reviewed 2026-09-10
Implemented
- CEMarque canonical market/product scope
- commercial-activity and open-source handling
- remote data processing scope
- sector exclusions
- manufacturer/importer/distributor/open-source steward role
- Annex III/IV item-derived classification
- conformity route
- Article 14 timing
- existing-product and CE-marking transition logic
- canonical obligation fact mapping
Partial
- Conformoo-specific control/evidence mappings beyond the canonical CEMarque verdict
- expert review for interpretation-sensitive edge cases
Not yet supported
- regulator filing submission
- certification/conformity approval
EU Data Act
Rules on access to and use of data from connected products/related services and other data-economy obligations.
Ruleset 1.0.0 · reviewed 2026-09-22
Implemented
- connected-product screen
- related-service screen
- Article 3(1) transition
- role capture
- core Chapter II obligation mapping
Partial
- trade-secret exception workflow
- unfair contract term analysis
- data-processing-service switching/interoperability
Not yet supported
- transaction-specific legal adjudication
UK PSTI Product Security Regime
Baseline product-security obligations for relevant consumer connectable products supplied to UK consumers.
Ruleset 1.0.0 · reviewed 2026-09-22
Implemented
- core consumer/connectable scope
- three baseline security requirements
- economic actor role
- Statement of Compliance readiness
Partial
- all sector-specific and Northern Ireland interaction edge cases
Not yet supported
- regulator submission