Independent information resource Product security · EU CRA
CRA readiness, templates, tools and software / 09

CRA Technical Documentation Checklist

A practical Cyber Resilience Act technical documentation checklist based on Article 31 and Annex VII, covering product description, architecture, cybersecurity risk assessment, vulnerability handling, SBOM, standards, testing and the EU declaration of conformity.

IN BRIEF

Treat the technical file as a controlled evidence set rather than one final document. Link each Annex VII item to current product and version evidence, preserve not-applicable reasoning, make the cybersecurity risk assessment and vulnerability-handling records reviewable, and maintain version history as the product changes.

01 / 12

Confirm the Technical File Is Product and Version Specific

Start with the exact product, family and versions covered by the file. Article 31 requires technical documentation for the product with digital elements, so a generic corporate cybersecurity binder is not enough. The file should make clear which architecture, software versions and evidence support the conformity case.

02 / 12

Include the Annex VII General Product Description

Annex VII requires a general description including intended purpose, software versions affecting compliance and, for hardware, relevant photographs or illustrations. Link the description to controlled product identifiers so reviewers can match the file to the product placed on the market.

03 / 12

Include User Information and Instructions

Annex VII incorporates the Annex II user information and instructions into the technical documentation set. Check that user-facing security information, support-period information and product instructions remain consistent with the actual product and support model.

04 / 12

Document Design, Development and System Architecture

Describe the design and development of the product and, where applicable, provide drawings, schemes and system architecture showing how software components build on or feed into each other and integrate into overall processing. The goal is reviewable architecture evidence, not unnecessary disclosure of every internal development artifact.

05 / 12

Document Vulnerability-Handling Processes

Annex VII requires information and specifications for the manufacturer's vulnerability-handling processes, including the SBOM, coordinated vulnerability disclosure policy, evidence of a vulnerability contact address and the technical solutions chosen for secure update distribution.

06 / 12

Include Production and Monitoring Process Evidence

Where applicable, document the production and monitoring processes used for the product and the validation of those processes. This helps show that the product placed on the market is connected to the controlled design and security evidence rather than an uncontrolled production state.

07 / 12

Include the Article 13 Cybersecurity Risk Assessment

The cybersecurity risk assessment belongs in the technical documentation. Confirm that it reflects intended purpose, reasonably foreseeable use, conditions of use, operational environment and assets to be protected, and that it explains how Annex I requirements apply. Preserve clear reasoning where an essential cybersecurity requirement is considered not applicable.

08 / 12

Record Support-Period Reasoning

Annex VII requires relevant information used to determine the support period. Keep the rationale aligned with the support period communicated for the product and with the vulnerability-handling resources expected throughout that period.

09 / 12

Record Standards, Common Specifications and Other Technical Solutions

Document harmonised standards, common specifications or applicable certification schemes used in full or in part. Where those are not used, describe the technical solutions adopted to meet the essential cybersecurity requirements. If a standard is applied only partly, identify the parts used.

10 / 12

Include Test Reports Supporting Conformity

Annex VII requires reports of tests carried out to verify conformity of the product and vulnerability-handling processes with applicable Annex I requirements. Link test evidence to the product version and requirements it supports so the file remains traceable.

11 / 12

Include the EU Declaration of Conformity

The technical documentation set should include a copy of the EU declaration of conformity. Keep the declaration consistent with the product identity, conformity route and any notified-body information that applies.

12 / 12

Maintain and Retain the Documentation

Article 31 requires the technical documentation to be drawn up before market placement and continuously updated where appropriate, at least during the support period. Article 13 also requires the manufacturer to keep the technical documentation and EU declaration available to market surveillance authorities for at least 10 years after market placement or for the support period, whichever is longer.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.