Private beta

DossierForge drafts your Cyber Resilience Act documents on your own desktop.

For the developer or CTO at an EU maker of connected products. Turn your answers and component list into a technical file you can review and edit.

Checkout is not open yet.

A recording of the application: the product name is typed in, a source tree is scanned and the component inventory lands.

Read the sample dossier

Who this applies to

If you place a product on the EU market and it connects to a device or a network, directly or indirectly, the Cyber Resilience Act, Regulation (EU) 2024/2847, applies to you, unless a sector regime already covers it, such as medical devices, vehicles or aviation. Roughly 90% of products are self-assessed: you do the assessment and sign it yourself, no external auditor involved.

Run the free scope check

The Commission guidance, in plain language

What a free template leaves you to write

DossierForge fills the technical file from your answers and component list. Review the draft and add the evidence your product needs.

Free template

A blank risk-assessment template beside a generated technical-file section with its legal references.

3.4 Assessment of cybersecurity risks

[Describe how each essential requirement in Annex I, Part I applies to the product.]

[List the requirements that do not apply and state why.]

[Attach evidence.]

Drafted from your answers

3. Assessment of the cybersecurity risks

Regulation (EU) 2024/2847, Annex VII, point 3; Article 13(3); Article 13(4)

Documented cybersecurity risk assessment:

product file doc/security/vx-100-risk-assessment.md, revision 4, reviewed at every minor release

Every essential requirement in Annex I Part I applies to this product. Section 4 of the risk assessment records, for each requirement, how it is met and which evidence demonstrates it.

How it works

Point it at your product

Scan a source tree, import an SBOM in CycloneDX or SPDX format, or enter components by hand.

Answer the questions

Answer questions about your product to identify its requirements.

Get the dossier

Your answers fill four documents: information and instructions for your users, the Annex VII technical file the Regulation requires, your vulnerability handling policy and the declaration you sign. Save them as PDF and Word files.

Keep it current

Scan or import your next release to compare components added, removed or changed in version. Update your answers and generate the revised dossier.

How it works

What it does, and what it leaves to you

What it leaves to you

What it does

It does not guarantee an outcome. The exposure stays yours.

Saves each generated dossier with its date and file hash.

It approves nothing. You make the self assessment and you sign it.

Uses your product answers across all four documents.

It is not legal advice about your particular product.

Prints legal references under the document section headings.

Two dates

11 September 2026

Reporting applies. An actively exploited vulnerability or a severe incident goes to your national incident authority (CSIRT) and the EU cybersecurity agency (ENISA) within 24 hours, including for products already on the market.

11 December 2027

The Regulation applies in full: the technical file, the declaration and the product requirements behind them.

Penalties reach EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher.

Pricing

Preview

Free

one product, when the first build ships

Use one product and generate watermarked first pages of its documents.

Dossier

EUR 299 once

per product

Buy it once and keep the documents.

RECOMMENDED

Maintain

EUR 82,50 per month

billed annually as EUR 990, excl. VAT, per product

Dossier generation, rule updates and scheduled vulnerability checks.

Launch pricing. These are the prices the product launches at; buying at them locks them in for your product.

Excludes VAT. A product is anything that needs its own CRA technical file. Windows and Linux at launch, macOS planned.

Full pricing detail

Ruben Plantinga, who builds DossierForge.

Who builds this

Ruben Plantinga, Den Haag. I own Skoft Software and work as a tech lead: I design systems, build applications, lead development teams and I answer for the products we ship. Proven experience across Java, C#, Rust, Python and TypeScript, on backend services, developer tooling and CI/CD pipelines. DossierForge is that work applied to one problem.

FAQ

What gets generated?

The dossier contains four documents: information and instructions for your users, the Annex VII technical file the Regulation requires, your vulnerability handling policy and the declaration you sign. You can also draft a separate 24 hour early warning. The four documents are generated in English as PDF and Word files. The technical file may stay English, although an authority can require the parts it names translated. The information and instructions must be in a language your users and authorities can easily understand. The declaration must exist in the languages required by each country you sell in. Those translations are yours to make.

What leaves my machine?
  • Licence checks send your key to license.skoft.app.
  • Update checks contact updates.skoft.app for new app versions.
  • The app downloads the scanner vulnerability database from its publisher.
  • Vulnerability checks send component names and versions to the public OSV database, then CVE identifiers to the public NVD database. If you set an NVD API key, it goes to NVD too. Checks also download the public list of known exploited vulnerabilities from cisa.gov when needed. No product information is sent to CISA.
  • If you connect GitHub or GitLab, the app sends your access token to that service to read releases and SBOM files.
  • Sending feedback delivers your message, attachments and app version, operating system and processor architecture to Skoft Software. You choose whether to include diagnostics and a reply address.

Licence checks, update checks and scanner database downloads run automatically. The other connections run when you use or enable them. Scanning and document generation run on your machine.

Can I try it before I buy?

The free preview comes with the first public build. It covers one product, including the questions, scan and full list of missing information. It generates watermarked first pages of each document. A licence adds the remaining pages and Word files. You can use the browser scope check now.

Which SBOM formats and ecosystems does it read?

Import CycloneDX or SPDX 2.2 and 2.3 in JSON format. XML, SPDX tag-value and SPDX 3.0 are not supported. Scanning covers language ecosystems, Linux packages and compiled binaries; the full list is on How it works.

What happens if I release a new version of my product?

Scan or import the new release, review the component changes and update your answers before generating its dossier. The comparison lists added and removed components, version changes and newly matched vulnerabilities.

What does the vulnerability watch do and how often?

Turn it on and choose a schedule from hourly to weekly. It checks public vulnerability databases and notifies you of new matches or newly flagged active exploitation. Whether your product is actually affected, and so whether you owe the 24 hour report, is still your call.

Does it work offline?

Scanning and document generation run locally. Generating a final dossier needs a purchase behind it and rules that are still current. Drafts and copies of documents you already generated survive an outage of any length. Licence validation, updates and vulnerability database checks need an internet connection.

What happens when the law or standards change?

Maintain includes updates to the rules used to generate your dossier. Each document identifies the rules version used. Without Maintain you keep the rules your purchase was sold.

What happens to my documents if I stop paying or you disappear?

Your saved PDF and Word files remain on your disk. You can open and edit them without DossierForge. A Dossier purchase keeps producing its documents after a Maintain subscription ends. If our licence service goes away, your documents and your rules stay as they are.

Join the waitlist

Get the weekly DossierForge build log and an email when the beta opens.