ceproof reads your repository and maps it against every item the EU Cyber Resilience Act's Annex VII and Annex V require — deriving what it can evidence from your code, and telling you plainly which items only you can answer. Free scan and gap checklist. Audit-ready documentation pack when you need it.
npx ceproof scanA distributor asks for your Declaration of Conformity. A customer's procurement team asks for technical documentation. Your own release goes out and the documentation you assembled by hand six months ago now describes a product that no longer exists. The CRA treats technical documentation as a living obligation, not a one-time filing — ceproof turns it into a command you re-run on every release.
npx ceproof scan inspects your repo: security policy, vulnerability disclosure, update mechanism, VCS release identity, declared licence, and the full npm/Python dependency tree. It maps those facts against all 21 Annex VII and Annex V items, each carrying its exact citation, traced verbatim to the regulation text.
ceproof init writes a config file with one entry per item that genuinely needs a human: manufacturer identity, support period, vulnerability-handling process. It never guesses and never writes plausible-sounding filler into a legal document.
ceproof report renders the Annex VII technical documentation pack and the Annex V Declaration of Conformity draft as HTML or PDF, stamped with the release it was generated against. Offline. Your code never leaves your machine.
The full scanner — gap checklist across all 21 items, init, JSON output, CI exit codes, and both SBOM formats (CycloneDX 1.6, SPDX 2.3). No account, no telemetry, no network calls.
$99 perpetual
Unlocks the Annex VII technical documentation pack and the Annex V DoC draft, HTML and PDF. Includes 1 year of CRA reference-data updates. The tool never stops working — ever.
Buy$299 perpetual
Everything in Individual, licensed for client work — generate packs for unlimited client projects. Includes 1 year of data updates.
BuyKeys are delivered by email, usually within a few hours. Perpetual means perpetual: past your update year, everything keeps working; you just don't pull newer reference data unless you renew.
ceproof does not make you CRA-compliant, and no tool can. Conformity is a legal process involving your own assessment and, for some product classes, a notified body.
What ceproof gives you: the complete Annex VII and Annex V structure with every requirement cited to the regulation text, the evidence it can genuinely derive from your repository, your own answers assembled into a consistent document, and an explicit, honest list of what is still open. When it cannot evidence something, it says so out loud rather than filling the gap with something that reads well.
No spam — release notes and CRA deadline reminders you'd actually want. Unsubscribe anytime.
No. It assembles and structures your technical documentation and DoC draft with traceable citations. Compliance is a legal determination; have it reviewed.
A minority, honestly. On a typical repository with a tagged release and a resolved dependency tree, 2 of 13 Annex VII items resolve fully from scan evidence alone, and a third gets partial evidence that still needs review — the rest describe things only a human can state honestly: intended purpose, design rationale, risk assessment, support-period reasoning, standards applied, test reports. The value isn't autofill — it's the structure, the citations, the evidence it can prove, and regenerating the whole pack in one command every release.
The Cyber Resilience Act applies from 11 December 2027 — that's when the essential cybersecurity requirements, including the Annex VII technical documentation and Annex V Declaration of Conformity obligations, take effect for products placed on the market (Article 71). Two provisions apply earlier: Article 14's reporting obligation for actively exploited vulnerabilities and severe incidents applies from 11 September 2026, and Chapter IV (notified bodies / conformity assessment) applies from 11 June 2026.
Source-available under the Elastic License 2.0: the complete source is public on GitHub — free to use, audit, and modify; not licensed for resale. (The published npm package itself ships only the compiled tool and reference data, not the raw source — read the source on GitHub.) The scanner tier is free forever.
No. Zero network calls, zero telemetry — verifiable in the source. Everything generates on your machine.
npm, pnpm, yarn (classic + berry) · Python: uv, poetry, requirements.txt, pyproject. Mixed repos scan both at once.
CycloneDX 1.6, which meets BSI TR-03183-2 v2.1.0's stated version floor, and SPDX 2.3. BSI's floor for SPDX is 3.0.1 — a different data model, not a version bump — and support for it is on the roadmap, not shipped. Both formats are free.
If the pack doesn't do what this page says, email within 14 days for a full refund.
No — a real print-rendered document with provenance (tool version, CRA data version, release identifier, timestamp). Built to be filed.