Draw up and maintain technical documentation (Annex VII)
- Se aplica a
- Manufacturer
- Citas de fuentes
- Art. 13(3)Art. 13(13)Annex VII
- Clases de productos
- default, important-class-i, important-class-ii, critical
Lenguaje claro
You must keep a technical file that proves your product meets CRA requirements. Annex VII lists exactly what must be in it — the risk assessment, design documents, testing records, and more. Keep it up to date for the life of the product and for at least ten years after you sell the first unit.
Legal text
Article 13(3) of Regulation (EU) 2024/2847 requires that, before placing a product with digital elements on the market, manufacturers shall draw up the technical documentation referred to in Annex VII.
Article 13(13) requires that manufacturers keep the technical documentation and EU Declaration of Conformity at the disposal of the market surveillance authorities for ten years from the date the product is placed on the market, or for the expected lifetime of the product, whichever is longer.
Required contents (Annex VII)
Annex VII specifies the technical documentation must include:
- General description of the product — name, version, intended use
- Design and development documents — architecture, data flows, security-relevant design decisions
- Cybersecurity risk assessment (see OBL-ART13-02)
- Vulnerability handling policy — description of the process
- List of cybersecurity standards applied — or description of solutions adopted to meet essential requirements where no standards exist
- EU Declaration of Conformity (or a draft thereof)
- SBOM — software bill of materials for the product
- Testing and verification records — evidence that the Annex I requirements are met
Key requirements
- Completeness — all Annex VII elements must be present
- Up to date — documentation must be updated when the product is modified
- 10-year retention — from first placement on the market or product expected lifetime, whichever is longer
- Available to authorities — must be produced on request from market surveillance
Evidence you may need
- Compiled Annex VII technical file
- Change-management records showing when documentation was updated
- Version history of all included documents
- SBOM in CycloneDX or SPDX format