How it works
From your components to a draft technical file
Build your component list, answer questions about your product and review the generated documents.
Step 1
Point it at your product
Start with a scan, an existing SBOM or a list you enter by hand.
Three ways to get your component list
Scan a folder containing your source code or built binaries.
Import CycloneDX or SPDX 2.2 and 2.3 in JSON format.
Enter the name, version, licence and supplier of missing components.
Example scan results
Components
Result22
resolved19
resolved12
resolvednone
named gapWhat the scan recognises
The bundled scanner supports these ecosystems:
- C and C++ (Conan, vcpkg)
- Rust (Cargo)
- Go
- Python
- JavaScript (npm, Deno)
- Java (Maven, Gradle)
- .NET
- PHP (Composer)
- Ruby (gems)
- Swift (CocoaPods, Swift Package Manager)
- Dart
- Elixir
- Erlang
- Haskell
- Lua
- OCaml (opam)
- R
- SWI-Prolog packs
- Linux packages (dpkg, RPM, apk, pacman, Portage)
- Linux kernel and its modules
- Nix, Snap, Homebrew and Conda
- Compiled binaries (ELF, PE)
- Apple app bundles
- Terraform
- WordPress plugins
- AI model files (GGUF, safetensors)
What the scan can miss
A scan can miss vendored C or C++ sources without package manifests. Review the component list and add missing components by hand or import them from an SBOM.
Step 2
Answer the questions
Answer questions about what your product does and how you sell it. Your answers determine the requirements shown for your product.
Your answers are saved with your product. Review them when you prepare its next release.
Is the core function of your product one of the listed higher-risk categories? Core function means what the product is placed on the market to do, not something it happens to be able to do.
No. The product is a sensor node.
RecordedNot a higher-risk product. Self-assessment route. No third party involved.
AppliedYou give the answers
Check that your answers accurately describe your product before relying on its classification.
Step 3
Get the dossier
Use the same product answers to generate four documents: information and instructions for your users, the Annex VII technical file the Regulation requires, your vulnerability handling policy and the EU declaration of conformity. Save each dossier as PDF and Word files for the selected release.
Review the declaration and enter the place, date and signatory details. You sign it yourself.
Example dossier for a sensor node
Information and instructions to the user under Annex II.
PDF and WordTechnical documentation under Article 31 and Annex VII.
PDF and WordVulnerability handling policy under Part II of Annex I.
PDF and WordEU declaration of conformity under Article 28 and Annex V.
PDF and WordWhat is still missing
See which requirements still need work and what you need to provide.
Example requirements that still need work
Gap
What closes itNo coordinated vulnerability disclosure policy that an outside reporter can find and follow.
PolicyNo support period has been determined for this product, or it does not rest on a view of how long the product will be in use.
Technical fileNo contact address is on record for reporting vulnerabilities in this product.
PolicyAfter you ship
Prepare your next release
Compare the new component list with your previous release to see additions, removals, version changes and newly matched vulnerabilities.
If you become aware of an actively exploited vulnerability in your product, send an early warning to the relevant CSIRT and ENISA without undue delay and within 24 hours at the latest. Record when you became aware of it. A database match alone does not establish that it has been exploited in your product. Review the watch results and record your assessment. DossierForge uses that assessment to prepare an early warning draft and list its missing information.
Example component changes between patch releases
61 components in this release, 59 in the last
tracing 0.1.44 and tracing-core 0.1.36
2 componentsNo components removed.
noneopenssl changed from 3.0.13.
1 componentOne newly matched vulnerability to assess.
1 to assessThe watch runs on your machine
Run a check yourself or enable scheduled checks. Scheduled checks need your machine to be running and connected to the internet.
Review the early warning and submit it yourself. DossierForge does not send it.
Rules and updates
Keep the rules current
Your dossier is generated from one set of rules. That set carries the date it was last checked. Maintain moves you on to a newer set while the subscription runs.
A one-time Dossier keeps the rules it was sold. Once those rules are too old to stand behind, the app stops generating new final dossiers on them.
Security and compatibility updates reach every licence state, including the free preview. Installing one never changes your rules or the date they were checked.
Build status
Availability
DossierForge is in private beta. The first public build will be available for Windows and Linux.
Downloads and checkout are not open yet. macOS is planned without a release date.
Join the waitlist
Get the weekly DossierForge build log and an email when the beta opens.