CRA guide
What goes in CRA Annex VII technical documentation? (with a checklist)
CRA Annex VII (Article 31) sets out, item by item, what the technical documentation must contain “as applicable to the relevant product.” Here's that list as a working checklist.
1. General product description
Its intended purpose; the software versions affecting compliance with the essential requirements; for hardware, photographs or illustrations of external features, marking and internal layout; and the user information and instructions required by Annex II.
2. Design, development, production and vulnerability handling
Design/development information (architecture, how components integrate); the specifics of your vulnerability-handling process — including the SBOM, coordinated vulnerability disclosure policy, evidence of a published reporting contact, and the technical solution for secure update distribution; and information on your production and monitoring processes.
3. Cybersecurity risk assessment
An assessment of the risks the product is designed, developed, produced and maintained against, including how the Annex I, Part I essential requirements apply to it.
4. Support-period justification
The information taken into account to determine the product's support period (the period you'll provide security updates for).
5. Standards applied
The harmonised standards, common specifications, or European cybersecurity certification schemes applied — in full or in part — or, where none were applied, a description of the alternative solution adopted to meet the essential requirements.
6. Test reports
Reports of the tests carried out to verify conformity with the Annex I, Part I and Part II requirements.
7. A copy of the EU Declaration of Conformity
See the worked Declaration-of-Conformity example for what this contains.
8. The SBOM, on reasoned request
Made available to a market surveillance authority further to a reasoned request, where necessary to check compliance with Annex I.
Key points
- Drawn from CRA Annex VII (Article 31) — 8 required items, some with sub-items.
- Must be drawn up before the product is placed on the EU market.
- Kept up to date across the product's support period, not a one-time document.
- Item 7 (the signed declaration) and item 8 (the SBOM) tie this directly to the other guides in this series.
Frequently asked questions
- What is CRA Annex VII technical documentation?
- The structured dossier that shows how a product meets the CRA essential requirements: product description, design/vulnerability-handling information, risk assessment, standards applied, test reports, and the signed declaration of conformity.
- When must the technical documentation be ready?
- Before the product is placed on the EU market, and kept current for as long as the product is supported.
Related
General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.