DevKit Dossier

Cyber Resilience Act guides

These guides quote the law word for word, read it plainly and list the records worth keeping. They are written for small software manufacturers that place products on the EU market.

CRA SBOM requirements: what the Act asks for

What the Cyber Resilience Act says about the SBOM: format, depth, where it is filed and who may ask for it. Quoted from the regulation and read plainly.

CRA Article 14 reporting: 24-hour, 72-hour, 14-day deadlines

CRA Article 14 applies since 11 September 2026: early warning in 24 hours, notification in 72 hours, final report 14 days after a measure is available.

CRA Annex VII: what the technical documentation contains

Annex VII of the Cyber Resilience Act lists eight items for the technical documentation. The list, quoted and read plainly, with the records to keep.

Cyber Resilience Act timeline: key dates and deadlines

CRA timeline from the regulation: in force since 10 December 2024, Article 14 reporting since 11 September 2026, main obligations from 11 December 2027.

A hosted alternative to Dependency-Track: what each keeps

Dependency-Track is an OWASP platform you run yourself; DevKit Dossier is a hosted evidence ledger. What each one keeps, from their documentation.

FDA 524B SBOM requirements for premarket submissions

Section 524B of the FD&C Act asks for an SBOM in premarket submissions for cyber devices. The statute and FDA's February 2026 guidance, quoted.