Machine-readable truth, human-readable limits

Supported coverage.

Conformoo does not hide partial implementation behind marketing language. Every pack declares what is implemented, partial, unsupported and interpretation-sensitive.

beta

Australia Security Standards for Smart Devices

Mandatory cybersecurity standards for most consumer-grade relevant connectable products manufactured on/from 4 March 2026.

Ruleset 1.0.0 · reviewed 2026-09-22

Implemented

  • core scope
  • manufacture-date gate
  • password/security-reporting/support-period standards
  • manufacturer/supplier role
  • Statement of Compliance readiness

Partial

  • all product exemptions and nuanced supply-chain cases

Not yet supported

  • regulator submission
beta

EU Artificial Intelligence Act

Risk-based requirements for AI systems and general-purpose AI models in the EU.

Ruleset 1.0.0 · reviewed 2026-09-22

Implemented

  • AI/GPAI scope screen
  • actor-role capture
  • prohibited-practice escalation
  • Article 50 screen
  • Annex III/Annex I high-risk timing screen
  • GPAI/systemic-risk screen

Partial

  • detailed Article 6 exemption analysis
  • all Annex III exceptions
  • all sector-specific Annex I interactions

Not yet supported

  • legal clearance for prohibited practices
  • conformity assessment execution
beta

EU Cyber Resilience Act

Cybersecurity obligations for products with digital elements placed on the EU market. CRA scope, role, Annex III/IV classification, conformity route and timing are evaluated by the pinned CEMarque canonical engine.

Ruleset cemarque-r25-429f565 · reviewed 2026-09-10

Implemented

  • CEMarque canonical market/product scope
  • commercial-activity and open-source handling
  • remote data processing scope
  • sector exclusions
  • manufacturer/importer/distributor/open-source steward role
  • Annex III/IV item-derived classification
  • conformity route
  • Article 14 timing
  • existing-product and CE-marking transition logic
  • canonical obligation fact mapping

Partial

  • Conformoo-specific control/evidence mappings beyond the canonical CEMarque verdict
  • expert review for interpretation-sensitive edge cases

Not yet supported

  • regulator filing submission
  • certification/conformity approval
beta

EU Data Act

Rules on access to and use of data from connected products/related services and other data-economy obligations.

Ruleset 1.0.0 · reviewed 2026-09-22

Implemented

  • connected-product screen
  • related-service screen
  • Article 3(1) transition
  • role capture
  • core Chapter II obligation mapping

Partial

  • trade-secret exception workflow
  • unfair contract term analysis
  • data-processing-service switching/interoperability

Not yet supported

  • transaction-specific legal adjudication
beta

UK PSTI Product Security Regime

Baseline product-security obligations for relevant consumer connectable products supplied to UK consumers.

Ruleset 1.0.0 · reviewed 2026-09-22

Implemented

  • core consumer/connectable scope
  • three baseline security requirements
  • economic actor role
  • Statement of Compliance readiness

Partial

  • all sector-specific and Northern Ireland interaction edge cases

Not yet supported

  • regulator submission