Who writes this, and how
One person, in Melbourne. Not a law firm, not a notified body, and not a consultancy with a day rate. If you are going to put your name on a declaration of conformity partly because of something you read here, you should know exactly who wrote it and how carefully.
The person
Conformance House is written and built by Andy Dial, trading as Graycord, an independent software business in Melbourne, Australia. I am a software developer; before that I spent years as an IT project manager, with financial-domain experience across investment banking, retail banking and wealth management. I write every guide on this site and I build the generator behind it.
I am not a lawyer. Nothing on this site is legal advice, and that is not a disclaimer bolted on at the bottom — it shapes how the pages are written. Where the regulation is clear I say so and quote it. Where it is genuinely unresolved I say that instead of picking the answer that sells better.
How a page gets written
Every guide follows the same method, and the method is the product as much as the documents are.
- Read the operative text, in the Official Journal. Not a summary, not a law firm's briefing, not another vendor's page. The wording quoted on this site is taken from Regulation (EU) 2024/2847 as published in the Official Journal of the European Union.
- Cite the Article or Annex, by number. Every substantive claim names the provision it comes from, so you can check it yourself in minutes. A page that asks you to trust it without telling you where to look is not worth reading on a subject like this.
- Say what the source grade is. Where something rests on a Commission FAQ, an ENISA announcement or a single secondary source rather than on the Regulation itself, the page says so in terms. Those are different grades of evidence and collapsing them is how confident-sounding misinformation gets made.
- State what we could not verify. Every guide carries a note naming our own confidence and what you should check for yourself. Several pages openly record questions nobody has settled — the SBOM hash algorithm, what counts as “monetised” open source, the boundary between an open-source steward and a manufacturer.
- Test it. The applicability checker's verdict logic is covered by 173 automated tests, and the site as a whole by about 2,200 checks that run before anything is published. That exists because two early versions of the checker gave wrong answers, and a tool that contradicts itself is worth less than no tool.
What this site will not claim
A short list, because in compliance the refusals tell you more than the promises.
- We will not tell you a penalty figure we have not verified against the operative text. Fine numbers circulate widely and are frequently wrong.
- We will not say we file anything for you. Reports under Article 14 are submitted by a person, on ENISA's own web form. There is no API at the time of writing, so nobody can automate the submission — and any vendor implying otherwise is describing something that does not exist.
- We will not certify your product or your classification. The checker gives you a reasoned answer with the rule and your own inputs printed next to it. Article 14(7), for example, makes the CSIRT determination expressly one made “based on the information available to the manufacturer” — so the defensible artefact is your reasoning, not somebody else's verdict.
- We will not withhold your records. You export every document version with every date, one button, any time, no conditions — including if you cancel, and including if this business ever stops operating. A vendor who holds a manufacturer's retained legal record hostage has made that manufacturer non-compliant as an exit fee.
- We will not ask you to get on a call. There are none. Everything is self-serve and written, which is also why the price is published on the site instead of quoted on enquiry.
Corrections we have published
A page that has never been corrected has either never been checked or never admitted to it. These are real changes made to this site after the research turned out differently from what we first wrote.
| What changed | Why |
|---|---|
| The Radio Equipment Directive overlap | Widely described, including in the Commission's own published FAQ, as something the Commission aims to repeal. It has in fact already been repealed — Commission Delegated Regulation (EU) 2026/339 of 16 February 2026, Official Journal 29 April 2026, with effect from 11 December 2027. We read the repealing act itself and corrected the page. |
| Retention of the information supplied to users | We had it as a flat ten years from placing on the market. Article 13(18) in fact says “or for the support period, whichever is longer”, and says it twice. For a product with a long support period our earlier reading understated the retention date. Corrected in the guide and in the generator. |
| Free and open-source software | An early version of the checker gave the wrong answer to a maintainer who monetises their project through paid support. The commercial-activity test from Recital 18 is now modelled properly, and the old behaviour is pinned by a regression test. |
| Class I products and self-assessment | We told Class I manufacturers they may self-assess if they apply the harmonised standards in full. True as far as it went, but it did not say that those standards do not yet exist — which, under Article 32(2), puts them on a notified-body route today. The reassurance was corrected. |
If you find something wrong on this site, write to andy@graycord.com and quote the provision. Corrections get made and recorded here. That is the only reputation a one-person compliance tool can have.
What this site does with you
Nothing, as far as is practical. These pages set no cookies and store nothing on your device. Visits are counted without cookies, without a consent banner and without building a profile of you, on infrastructure in the EU. The free applicability check asks for no email and stores none of your answers. Signing in to the generator does store a session token in your browser, so that you stay signed in.
That posture is deliberate and slightly awkward to build, and the reason is simple: a site selling compliance which measured its visitors in a way that needed a consent banner would be arguing against itself.
Getting in touch
Email andy@graycord.com. A person reads it and a person replies — there is only one of us, so it is not a queue behind a chatbot. If your question is about whether the regulation applies to your product, the free check answers that in two minutes and costs nothing.
Start with the part that is free
Eight questions, no email, nothing stored. You get your conformity route, the documents you owe, and the Article behind each one — and if the regulation does not apply to you, it says so and stops.
Or read the guides — twenty-three of them, each cited to the text.