EU Cyber Resilience Act — Regulation (EU) 2024/2847

The SBOM scan is free everywhere.
The dossier is the work.

If you ship downloadable software to EU users — plugins, desktop or mobile apps, CLI tools, firmware, monetised open source — the CRA applies to you. Reporting obligations start 11 September 2026. Full obligations follow on 11 December 2027.

CRA-Dossier turns a structured questionnaire into the self-assessment dossier default-class products need — the documents, not another scanner.

Pure SaaS? You’re likely out of scope — the free check tells you why, with the legal basis.

11 Sep 2026

Notify actively exploited vulnerabilities and severe incidents to ENISA — 24h early warning, 72h notification, final report.

11 Dec 2027

Full application: essential requirements, technical documentation, CE marking, EU declaration of conformity.

10 years

How long the technical documentation and declaration must stay at the disposal of market surveillance authorities.

One questionnaire. Six documents you actually need.

Everything is generated from your answers and the regulation itself — pre-written, reviewed regulatory content. No AI-improvised legal text.

Self-assessment (Module A)

Your product assessed against every Annex I requirement — Part I security properties, Part II vulnerability handling. Declared / partial / gap, with an action plan per gap.

Technical documentation skeleton

The Annex VII structure pre-filled from your answers, with [complete] markers where only you can fill the blank. 10-year retention, audit-ready shape.

CVD policy, ready to publish

The coordinated vulnerability disclosure policy Annex I Part II (5) requires — as a Markdown page for your site, plus security.txt (RFC 9116). Publishing it is the fastest real win in the pack.

ENISA notification runbook

The 24h / 72h / 14-day procedure for actively exploited vulnerabilities and severe incidents, with trigger tests, checklists and pre-filled report templates. Obligations start 11 September 2026.

Evidence register

A 10-year retention index (PDF + living CSV): what to keep, which CRA article asks for it, where it lives. Seeded with every evidence item your dossier expects.

EU declaration of conformity draft

The Annex V declaration pre-filled — clearly marked draft, to sign only once your gaps are closed.

Optional: attach your SBOM (CycloneDX/SPDX — e.g. from syft, Apache-2.0) and the dossier integrates it into the technical documentation. We don’t sell you a scanner — free ones are excellent.

Built for the default class — honestly

Around 90% of products with digital elements are default class: they can self-assess under Module A (internal control) — no notified body, no third-party audit. That’s the product this dossier serves.

Password managers, VPNs, antivirus, OSes and other Annex III/IV categories follow stricter routes. If that’s you, our scope check says so and we don’t sell you a dossier that wouldn’t fit.

No harmonised CRA standard has been cited in the Official Journal yet — which means there is no presumption of conformity to hide behind. Your documentation is your evidence. The dossier is designed to be extended the day the standards land.

An EU SME? The SECURE programme co-funds cybersecurity compliance costs for SMEs (up to €30k) — compliance preparation work like this dossier is exactly the kind of cost it targets. Worth checking before you budget.

One-time. No subscription.

Compliance monitoring subscriptions make sense for enterprises. For an indie software maker, the dossier is a deliverable — pay once, own it, keep it alive yourself with the evidence register.

One product

€149 one-time

  • · Full dossier — all six documents
  • · SBOM integration
  • · Re-download anytime, regenerated on the latest templates
Build your dossier

Up to 5 products

€490 one-time

  • · Per-product self-assessment, tech doc and declaration draft
  • · One CVD policy, runbook and register covering the portfolio
  • · For studios and agencies shipping several products
Build for 5 products

CRA fines can reach €15M or 2.5% of worldwide turnover — which is exactly why we don’t promise compliance. This dossier structures and documents your self-assessment; it does not replace it. If your situation is unusual, talk to a lawyer — and our scope check will tell you when we think you should.