DevKit Dossier

The EU is asking what is inside your software. We keep the record for you.

The Cyber Resilience Act already requires companies that sell software, apps or devices with firmware in the EU to send an early warning within 24 hours when a vulnerability in their product is actively exploited; from December 2027 they must also know the components of every version they ship and watch them for vulnerabilities. DevKit Dossier does the record keeping: your developer connects it once, and every release is archived, checked every day and ready to show to a customer or an authority.

Join the waitlist

Early access opens in stages. No spam, one confirmation email, unsubscribe any time.

Built for teams of 5–50 that ship installable software, firmware, mobile apps or SDKs to the EU market.

Is this about you?

  • You sell software that customers install, a mobile app, an SDK, or a device that runs firmware.
  • Some of your customers are in the EU, wherever your own company is based.
  • You have developers, not a compliance department.

Then the Cyber Resilience Act very likely covers your product, and this page is for you. Pure online services (SaaS) are outside the Act, and some products, such as medical devices and motor vehicles, fall under their own EU rules instead.

What the law asks, in plain words

Know what is inside

Keep a list of the components in each product you ship, at the very least its top-level dependencies. The list is called an SBOM, a software bill of materials, and free build tools can produce it.

Keep watching

New vulnerabilities are found in existing components every day. You are expected to notice when one affects a product you still support, and to deal with it without delay.

Report fast

If a vulnerability in your product is being actively exploited, an early warning is due within 24 hours of your becoming aware of it, a notification within 72 hours, and a final report within 14 days after a corrective or mitigating measure is available. This has applied since 11 September 2026.

Keep the proof

The technical documentation has to stay available to the authorities for at least 10 years after the product is placed on the market, or for the support period if that is longer.

The remaining obligations apply from 11 December 2027. From then on, a product may be made available on the EU market only if it meets the Act's essential requirements, and the CE marking is affixed on that basis.

The Act allows fines of up to EUR 15 million or 2.5 % of worldwide annual turnover, whichever is higher, for breaking its core obligations (Article 64). Micro and small enterprises are not fined for missing the 24-hour deadline itself.

The Act applies to anyone placing such products on the EU market, whether the company sits in Berlin, Bologna or Boston.

Large vendors have compliance teams. Small software companies have a CI pipeline and a Friday afternoon. DevKit Dossier is built for the second group.

Three steps, then it runs on its own

1. Your build sends the component list

Your developer adds one step to the release build, once. From then on every release sends its component list to DevKit Dossier on its own. For developers: a CycloneDX or SPDX® JSON SBOM from the free tool you already use (Syft, Trivy, cdxgen, or your build system), posted with one curl call, tagged with the version.

2. We check it every day

Every version you have sent us is compared with public vulnerability data every day. For developers: every component is matched daily against OSV advisories (the GitHub Advisory Database included); CISA KEV and EPSS data are added to the findings. The advisory data comes to our EU servers; your component list never leaves them.

3. You hear from us when it matters

A new vulnerability in a shipped release goes into the day's summary email for everyone on your team who has turned alerts on: which releases, how severe, whether it is being exploited, and whether a reporting clock is running. Every finding is kept with its timestamp; reporting-clock entries are never changed, only added to.

For your developers: what is in the dossier

SBOM archive per release

CycloneDX 1.4 to 1.7 and SPDX 2.3 JSON, stored unchanged, with a hash and an upload timestamp. Machine-readable, exportable, shareable with customers on request.

Continuous vulnerability monitoring

Daily re-scan of every supported release. Sources: OSV.dev (including GitHub Advisory Database), CISA Known Exploited Vulnerabilities, EPSS exploit probability. Findings link to the original advisory.

Article 14 reporting clocks

When you mark a vulnerability as actively exploited, DevKit Dossier records the moment of awareness, starts the 24-hour and 72-hour timers, and opens the 14-day final-report window once you record the corrective or mitigating measure. Each step is kept with its time and your reference. Submission to the authorities stays with you.

License inventory

SPDX license IDs per component, taken from your SBOM, with copyleft flags for review.

Evidence pack

PDF and JSON export per product and period: SBOMs, findings, handling timeline, third-party data notices. Designed to be attached to Annex VII technical documentation. The same records export as an SBOM in the format expected in FDA section 524B premarket submissions.

What we deliberately do not do

  • We are not a scanner. Your CI generates the SBOM with free tools; we keep and watch the records.
  • We are not lawyers. DevKit Dossier supports your evidence; it does not certify compliance or give legal advice.
  • We do not submit reports to authorities. DevKit Dossier prepares the timeline and the checklist; you file the notification.
  • Pure SaaS products are outside the Act's scope, and outside ours.

Where your data lives

Hosted in the EU (Frankfurt, Germany). Operated by DevKit Srl, an Italian company.

Vulnerability data is pulled into our database in bulk. We never send your component list, package names or component versions to third-party APIs.

Records stay as long as your subscription runs, and you can export everything at any time.

Full list of data sources, licenses and notices on the About page.

What it costs

A flat price per organisation: 49, 99 or 249 EUR per month, excluding VAT, with a 14-day trial. Self-serve: no sales call and no onboarding project.

See the plans

Get early access

Questions we get

Does DevKit Dossier make us CRA compliant?

No product can. Compliance is your conformity assessment as a manufacturer. DevKit Dossier keeps the evidence that the assessment and your customers will ask for: SBOMs per release, vulnerability handling records, reporting timelines.

Which SBOM formats do you accept?

CycloneDX 1.4 to 1.7 and SPDX 2.3, both as JSON; SPDX 3.0 JSON-LD is read on a best-effort basis. A newer CycloneDX 1.x is read as far as 1.7 goes and flagged. Other versions and formats (XML, tag-value) are refused with the reason.

We already run Trivy or Dependency-Track. Why this?

Scanners answer "what is vulnerable today". DevKit Dossier answers "what did we ship, what did we know, when, and what did we do about it" for every release, years later. If you self-host Dependency-Track and like it, keep it; DevKit Dossier is the hosted, zero-maintenance alternative.

Where is the data hosted?

In Frankfurt, Germany, on servers we run in DigitalOcean's Frankfurt datacenter. Backups stay in the EU.

Do you send our data to OSV, GitHub or NVD?

No. We download their advisory databases and match locally. No query containing your package names leaves our servers.

Is there a free plan?

No. Every plan starts with a 14-day trial. A credit card is required at the start of the trial; you are not charged if you cancel before it ends.

Can our customers see our SBOM?

Not unless you send it to them. Nobody outside your organisation can open your data in DevKit Dossier; to hand evidence to a customer, export the evidence pack and pass it on. Sharing links are not available yet.

Cyber Resilience Act guides

Plain readings of what the Cyber Resilience Act and FDA 524B ask manufacturers to record: SBOMs, reporting deadlines, technical documentation.

CRA SBOM requirements: what the Act asks for

What the Cyber Resilience Act says about the SBOM: format, depth, where it is filed and who may ask for it. Quoted from the regulation and read plainly.

CRA Article 14 reporting: 24-hour, 72-hour, 14-day deadlines

CRA Article 14 applies since 11 September 2026: early warning in 24 hours, notification in 72 hours, final report 14 days after a measure is available.

CRA Annex VII: what the technical documentation contains

Annex VII of the Cyber Resilience Act lists eight items for the technical documentation. The list, quoted and read plainly, with the records to keep.

Cyber Resilience Act timeline: key dates and deadlines

CRA timeline from the regulation: in force since 10 December 2024, Article 14 reporting since 11 September 2026, main obligations from 11 December 2027.

A hosted alternative to Dependency-Track: what each keeps

Dependency-Track is an OWASP platform you run yourself; DevKit Dossier is a hosted evidence ledger. What each one keeps, from their documentation.

FDA 524B SBOM requirements for premarket submissions

Section 524B of the FD&C Act asks for an SBOM in premarket submissions for cyber devices. The statute and FDA's February 2026 guidance, quoted.

Guides