ProofwrightWalkthrough

Generating a CRA dossier

How SBOMs, scans, and decisions compile into audit-ready technical documentation.

ProofwrightCRA Technical Dossier
Console · dossier v14
SBOMVulnerabilitiesVEXDossier
SectionEvidenceStatus
Component inventoryCycloneDX SBOMLinked
Vulnerability handlingOSV + VEX logLinked
Readiness assessment94 / 100Passed
Secure updatesSigned · ≥5 yr supportDocumented
Incident process24h / 72h / 14dDocumented
Illustrative Proofwright screen — demo data, not a live capture.

How the evidence you already collect compiles into audit-ready technical documentation. Related demos: Secure-by-default, requirement by requirement and The CRA incident-reporting clock.

1

Pull the SBOM

The current release's component inventory — the foundation the rest of the dossier references.

2

Attach vulnerability status

Every finding with its VEX decision — what's affected, what's not, and why.

3

Include the readiness assessment

Score against the CRA essential requirements, with gaps and how they were closed.

4

Compile the dossier

One document assembled from live evidence — regenerating as the product changes.

this is Proofwright

It's live.

See the real thing at Proofwright.