First obligations from September 2026
Evidence & Compliance

From conformity assessment to the EU Declaration of Conformity — with reliable evidence

Assessment frameworks, evidence upload, an immutable audit trail, and the EU DoC, generated automatically

The EU Cyber Resilience Act demands not just implementation but proof: conformity assessment per Annex VIII, the EU Declaration of Conformity per Art. 28, and documentation that holds up in an inspection. Kunnus guides you through the assessment, collects evidence on every criterion, logs every change in the immutable audit trail — and generates the EU Declaration of Conformity automatically once a product is fully conformant.

Art. 28 · 32Legal basis
Annex VIIIProcedures
Audit trailField-level diff
EU DoCGenerated automatically
app.kunnus.tech/reports

Reports & Evidence

Audit-ready
247
Documents
18
Generated this month
63%
Auto-collected
4
Audit packages
DocumentTagTypeUpdatedSize
EU Declaration of Conformity — SmartSensor XR Pro
DoCPDF2026-06-18412 KB
CRA Annex VII Technical Documentation
Annex VIIPDF2026-06-158.2 MB
Penetration Test Report Q2 2026
EvidencePDF2026-06-101.8 MB
SAST Scan — main@a3f2d1b
CI/CDJSON2026-06-0994 KB
Threat Model — Gateway Hub GH-200
STRIDEPDF2026-06-04276 KB

Key Benefits

Structured Conformity Assessment

Assessments for products, components, and vendors with a full lifecycle: configurable criteria, evidence upload, review dates, and approvals.

EU Declaration of Conformity, Automatically

Once a product reaches full conformity, Kunnus generates the EU Declaration of Conformity — pre-filled with metadata and classification.

Immutable Audit Trail

Every change is logged with timestamp, user, and field-level diff. Export to CSV or JSON. Access restricted to Owner, Admin, and Auditor.

Compliance & Security Dashboards

Compliance status across the whole portfolio: risk distribution, approval rates, open items, and SLA status — in real time, for management and auditors.

Capabilities

Assessment Frameworks

Annex VIII

Global and editable organization frameworks, pre-built for CRA vendor and component assessment. Extensible with custom criteria.

Evidence Upload & Review Workflow

Upload evidence directly on each assessment criterion. Review dates ensure timely approvals — with a complete history.

EU Declaration of Conformity

Art. 28

Generated automatically once a product reaches full conformity. Pre-filled with product metadata and classification per Annex V.

Immutable Audit Trail

Art. 32

Every change with timestamp, user, and field-level diff. Export to CSV or JSON — evidence that carries for ten years.

Policy Library with Approval Workflow

Six templates — Vulnerability Handling, CVD, Secure Development Lifecycle, Incident Response, Access Control, Data Protection — with editor, versioning, and approval process.

Portfolio Dashboards

Compliance status per product, risk distribution, approval rates, and SLA status — filtered by product, framework, and time range.

Use Cases

01

Audit Preparation

The auditor receives the Auditor role with read access to assessments and the audit trail, and exports the history as CSV — every change traceable with timestamp and field-level diff.

02

Path to the EU Declaration of Conformity

A manufacturer works through the assessment of a class I product criterion by criterion, attaches evidence, and reaches full conformity — the EU Declaration of Conformity is generated automatically.

03

Management Reporting

Leadership sees the compliance status of the entire portfolio in real time: risk distribution, approval rates, and open items — directly from the dashboards.

Make your conformity provable

See how Kunnus connects assessment, evidence, and the EU Declaration of Conformity. We'll walk you through the workflow in a personalized demo.