How it works

From your components to a draft technical file

Build your component list, answer questions about your product and review the generated documents.

Step 1

Point it at your product

Start with a scan, an existing SBOM or a list you enter by hand.

Three ways to get your component list

Scan

Scan a folder containing your source code or built binaries.

Import

Import CycloneDX or SPDX 2.2 and 2.3 in JSON format.

By hand

Enter the name, version, licence and supplier of missing components.

Example scan results

Example component counts for conan, cargo and npm, with vendored C and C++ sources missing.
Ecosystem

Components

Result
conan

22

resolved
cargo

19

resolved
npm

12

resolved
vendored C and C++

none

named gap

What the scan recognises

The bundled scanner supports these ecosystems:

  • C and C++ (Conan, vcpkg)
  • Rust (Cargo)
  • Go
  • Python
  • JavaScript (npm, Deno)
  • Java (Maven, Gradle)
  • .NET
  • PHP (Composer)
  • Ruby (gems)
  • Swift (CocoaPods, Swift Package Manager)
  • Dart
  • Elixir
  • Erlang
  • Haskell
  • Lua
  • OCaml (opam)
  • R
  • SWI-Prolog packs
  • Linux packages (dpkg, RPM, apk, pacman, Portage)
  • Linux kernel and its modules
  • Nix, Snap, Homebrew and Conda
  • Compiled binaries (ELF, PE)
  • Apple app bundles
  • Terraform
  • WordPress plugins
  • AI model files (GGUF, safetensors)

What the scan can miss

A scan can miss vendored C or C++ sources without package manifests. Review the component list and add missing components by hand or import them from an SBOM.

Step 2

Answer the questions

Answer questions about what your product does and how you sell it. Your answers determine the requirements shown for your product.

Your answers are saved with your product. Review them when you prepare its next release.

Example product question with a recorded answer and the resulting assessment route.

Is the core function of your product one of the listed higher-risk categories? Core function means what the product is placed on the market to do, not something it happens to be able to do.

Answer

No. The product is a sensor node.

Recorded
Consequence

Not a higher-risk product. Self-assessment route. No third party involved.

Applied

You give the answers

Check that your answers accurately describe your product before relying on its classification.

Step 3

Get the dossier

Use the same product answers to generate four documents: information and instructions for your users, the Annex VII technical file the Regulation requires, your vulnerability handling policy and the EU declaration of conformity. Save each dossier as PDF and Word files for the selected release.

Review the declaration and enter the place, date and signatory details. You sign it yourself.

Example dossier for a sensor node

Example dossier containing four documents: information and instructions for users, a technical file, a vulnerability handling policy and a declaration. Each is available as PDF and Word.
Dossier 0007 / sensor node / generated 2026-07-28
User instructions

Information and instructions to the user under Annex II.

PDF and Word
Technical file

Technical documentation under Article 31 and Annex VII.

PDF and Word
Policy

Vulnerability handling policy under Part II of Annex I.

PDF and Word
Declaration

EU declaration of conformity under Article 28 and Annex V.

PDF and Word

What is still missing

See which requirements still need work and what you need to provide.

Example requirements that still need work

Three missing items with legal references and the documents they belong in.
Provision

Gap

What closes it
Annex I, Part II, point (5)

No coordinated vulnerability disclosure policy that an outside reporter can find and follow.

Policy
Article 13(8), second subparagraph

No support period has been determined for this product, or it does not rest on a view of how long the product will be in use.

Technical file
Annex I, Part II, point (6)

No contact address is on record for reporting vulnerabilities in this product.

Policy

After you ship

Prepare your next release

Compare the new component list with your previous release to see additions, removals, version changes and newly matched vulnerabilities.

If you become aware of an actively exploited vulnerability in your product, send an early warning to the relevant CSIRT and ENISA without undue delay and within 24 hours at the latest. Record when you became aware of it. A database match alone does not establish that it has been exploited in your product. Review the watch results and record your assessment. DossierForge uses that assessment to prepare an early warning draft and list its missing information.

Example component changes between patch releases

Component changes between two firmware releases, with additions, removals, version changes and newly matched vulnerabilities.
Release comparison / firmware 2.4.0 to 2.4.1

61 components in this release, 59 in the last

Added

tracing 0.1.44 and tracing-core 0.1.36

2 components
Removed

No components removed.

none
Version bumps

openssl changed from 3.0.13.

1 component
New matches

One newly matched vulnerability to assess.

1 to assess

The watch runs on your machine

Run a check yourself or enable scheduled checks. Scheduled checks need your machine to be running and connected to the internet.

Review the early warning and submit it yourself. DossierForge does not send it.

Rules and updates

Keep the rules current

Your dossier is generated from one set of rules. That set carries the date it was last checked. Maintain moves you on to a newer set while the subscription runs.

A one-time Dossier keeps the rules it was sold. Once those rules are too old to stand behind, the app stops generating new final dossiers on them.

Security and compatibility updates reach every licence state, including the free preview. Installing one never changes your rules or the date they were checked.

Build status

Availability

DossierForge is in private beta. The first public build will be available for Windows and Linux.

Downloads and checkout are not open yet. macOS is planned without a release date.

Join the waitlist

Get the weekly DossierForge build log and an email when the beta opens.