Sample output

A sample dossier generated by DossierForge

This dossier has four documents and 17 pages. Read the contents and first page of each below.

This sample uses a fictional company and product. The text is unedited output from DossierForge.

Missing answers remain marked in the sample.

What is in the dossier

Information and instructions to the user under Annex II

  1. Identification of these information and instructions 1
  2. 1. Manufacturer and contact details 1
  3. 2. Vulnerability reporting contact 1
  4. 3. Product identification 1
  5. 4. Intended purpose and security properties 2
  6. 5. Circumstances that may create significant cybersecurity risks 2
  7. 6. EU declaration of conformity 2
  8. 7. Technical security support and support period 2
  9. 8. Detailed instructions for secure use 2
  10. 9. Software bill of materials access 3

Technical documentation under Article 31 and Annex VII

  1. Identification of this technical documentation 1
  2. 1. General description of the product with digital elements 1
  3. 2. Design, development and production of the product and the vulnerability handling processes 2
  4. 3. Assessment of the cybersecurity risks 3
  5. 4. Information taken into account to determine the support period 3
  6. 5. Harmonised standards, common specifications and certification schemes applied 3
  7. 6. Reports of the tests carried out 4
  8. 7. Copy of the EU declaration of conformity 4
  9. 8. Software bill of materials 4

Vulnerability handling policy under Part II of Annex I

  1. Scope and basis of this policy 1
  2. 1. Identification and documentation of vulnerabilities and components 1
  3. 2. Addressing and remediating vulnerabilities 2
  4. 3. Tests and reviews of the security of the product 2
  5. 4. Public disclosure of information about fixed vulnerabilities 2
  6. 5. Policy on coordinated vulnerability disclosure 3
  7. 6. Contact address for reporting and sharing of information on vulnerabilities 3
  8. 7. Secure distribution of updates 3
  9. 8. Dissemination of security updates 4
  10. Notification of actively exploited vulnerabilities and severe incidents 4
  11. Documentation of cybersecurity aspects and updating of the risk assessment 6
  12. Availability of issued security updates 6

EU declaration of conformity under Article 28 and Annex V

  1. EU declaration of conformity 1
  2. 1. Name, type and unique identification of the product with digital elements 1
  3. 2. Name and address of the manufacturer 1
  4. 3. Statement of sole responsibility 1
  5. 4. Object of the declaration 2
  6. 5. Statement of conformity with Union harmonisation legislation 2
  7. 6. References to harmonised standards, common specifications and certification 2
  8. 7. Conformity assessment procedure, notified body and certificate 2
  9. 8. Additional information 2
  10. Signed for and on behalf of the manufacturer 2
  11. Simplified EU declaration of conformity, for provision with the product 3

The first page of each

Sample output Information and instructions to the user under Annex II
Information and instructions to the user
under Annex II
Document doc-annex-ii-information-and-instructions · Requirement definitions version 1.0.2
Identification of these information and instructions
Regulation (EU) 2024/2847, Annex II, introductory sentence
Product: Voltix ChargerType designation: VX-100Release covered: fw-2.1.0Dossier version: 17Generated: 2026-07-30T11:45:00ZDefinition version: 1.0.2
1. Manufacturer and contact details
Regulation (EU) 2024/2847, Annex II, point 1
Manufacturer: Voltix BVPostal address: Kanaalweg 12, 3526 KL Utrecht, NetherlandsEmail address or other digital contact, including website where available:compliance@voltix.example
2. Vulnerability reporting contact
Regulation (EU) 2024/2847, Annex II, point 2
Single point of contact for users: support@voltix.example, answered by a personduring office hours, with a postal address and a telephone number published athttps://voltix.example/contactAddress for reporting vulnerabilities: security@voltix.example, with the PGP keyfingerprint published at https://voltix.example/security/disclosureCoordinated vulnerability disclosure policy:https://voltix.example/security/disclosure, also linked from the product page andfrom the user documentation
3. Product identification
Regulation (EU) 2024/2847, Annex II, point 3
Name: Voltix ChargerType: VX-100Additional information enabling unique identification: Model VX-100, hardwarerevision C, firmware series 2.x. Serial numbers VX100-2600001 and above.
Information and instructions to the user under Annex IIPage 1 of 3
Sample output Technical documentation under Article 31 and Annex VII
Technical documentation under Article 31
and Annex VII
Document doc-annex-vii-technical-documentation · Requirement definitions version 7.1.1
Identification of this technical documentation
Regulation (EU) 2024/2847, Article 31(1); Article 31(2); Article 13(13)
This document is the technical documentation drawn up for the product with digitalelements identified below, in accordance with Article 31 of Regulation (EU)2024/2847. It contains at least the elements set out in Annex VII to that Regulation.
Product name: Voltix ChargerType designation: VX-100Manufacturer: Voltix BVProduct category under Regulation (EU) 2024/2847: Product with digital elements,neither important nor criticalCore functionality under Annex III and Annex IV: None of theseRelease covered by this documentation: fw-2.1.0
Documentation reference: 17Date generated: 2026-07-30T11:45:00ZVersion of the requirement definitions applied: 7.1.1
This technical documentation is drawn up before the product with digital elements isplaced on the market and is updated, where appropriate, at least during the supportperiod. It is kept at the disposal of the market surveillance authorities together withthe EU declaration of conformity.
1. General description of the product with digital elements
Regulation (EU) 2024/2847, Annex VII, point 1; Annex VII, point 1(a); Annex VII, point 1(b); AnnexVII, point 1(c); Annex VII, point 1(d)
(a) Intended purpose
An 11 kW alternating current wall charger for electric vehicles, installed at privatehomes and small commercial parking locations. It joins the local network over Wi-Fiand connects to the Voltix cloud service for charge scheduling and firmwareupdates.
(b) Versions of software affecting compliance with the essential cybersecurityrequirements
Firmware 2.1.0 for the charging controller, firmware 2.1.0 for the connectivitymodule, and mobile application 2.1. The 1.x firmware series is out of support.
(c) Photographs or illustrations showing external features, marking and internallayout
This item applies where the product with digital elements is a hardware product.
Technical documentation under Article 31 and Annex VIIPage 1 of 5
Sample output Vulnerability handling policy under Part II of Annex I
Vulnerability handling policy under Part
II of Annex I
Document doc-vulnerability-handling-policy · Requirement definitions version 4.3.2
Scope and basis of this policy
Regulation (EU) 2024/2847, Annex I, Part II, introductory sentence; Article 13(8), firstsubparagraph; Article 13(8), sixth subparagraph
This document is the vulnerability handling policy of Voltix BV for the product withdigital elements identified below. It sets out the processes put in place to meet thevulnerability handling requirements in Part II of Annex I to Regulation (EU)2024/2847, and the policies and procedures required by Article 13(8) of thatRegulation for processing and remediating potential vulnerabilities reported frominternal or external sources.
Product: Voltix ChargerType designation: VX-100End of the support period: 2031-12-31
Policy reference: 17Date generated: 2026-07-30T11:45:00ZVersion of the requirement definitions applied: 4.3.2
1. Identification and documentation of vulnerabilities and
components
Regulation (EU) 2024/2847, Annex I, Part II, point (1)
Vulnerabilities and components contained in the product with digital elements areidentified and documented, including by drawing up a software bill of materials in acommonly used and machine readable format covering at least the top leveldependencies of the product.
Process applied:
The component inventory of every release is checked against OSV and the NationalVulnerability Database at build time and weekly thereafter. Reports from users andresearchers arrive at the contact address below and are triaged within two workingdays.
Current software bill of materials
Inventory source: automated dependency scan.Compiled on: 2026-07-29T14:12:07ZComponents recorded: 184Source file hash:9f2c1b7e4a6d8035c1ef4a2b7d90c3185ea4f7b62d0c9a3f8e1b5d7c4a6f2093State of vulnerability matching for this bill of materials: a vulnerability matcher ranover this exact inventory and its findings are recorded with this documentation.
Vulnerability handling policy under Part II of Annex IPage 1 of 6
Sample output EU declaration of conformity under Article 28 and Annex V
EU declaration of conformity under
Article 28 and Annex V
Document doc-eu-declaration-of-conformity · Requirement definitions version 1.2.2
EU declaration of conformity
Regulation (EU) 2024/2847, Article 28(1); Article 28(2), first subparagraph; Annex V, introductorysentence
This EU declaration of conformity is drawn up in accordance with Article 28 ofRegulation (EU) 2024/2847 of the European Parliament and of the Council of 23October 2024 on horizontal cybersecurity requirements for products with digitalelements. It follows the model structure set out in Annex V to that Regulation andstates that the fulfilment of the applicable essential cybersecurity requirements setout in Annex I has been demonstrated.
Product covered: Voltix ChargerDeclaration reference: 17Date generated: 2026-07-30T11:45:00ZVersion of the requirement definitions applied: 1.2.2
1. Name, type and unique identification of the product with
digital elements
Regulation (EU) 2024/2847, Annex V, point 1; Annex VIII, Part I, point 4.2; Article 13(15)
Name: Voltix Charger
Type: VX-100
Additional information enabling the unique identification of the product with digitalelements: Model VX-100, hardware revision C, firmware series 2.x. Serial numbersVX100-2600001 and above.
2. Name and address of the manufacturer
Regulation (EU) 2024/2847, Annex V, point 2; Article 13(16)
Manufacturer: Voltix BV
Postal address: Kanaalweg 12, 3526 KL Utrecht, Netherlands
Electronic contact: compliance@voltix.example
3. Statement of sole responsibility
Regulation (EU) 2024/2847, Annex V, point 3; Article 28(4)
This EU declaration of conformity is issued under the sole responsibility of themanufacturer identified in point 2. By drawing up this declaration, the manufacturerassumes responsibility for the compliance of the product with digital elements.
EU declaration of conformity under Article 28 and Annex VPage 1 of 3

Generate a dossier for your product

The desktop app is in private beta. Join the waitlist for the first public build.