Stavenor

Guides

CRA Technical Documentation: The Annex VII Checklist

Updated 20 September 20263 min read

Before a product with digital elements is placed on the EU market under the Cyber Resilience Act, its manufacturer must draw up technical documentation. The content is set by Annex VII, referred to in Article 31.

A common error: the European Commission's own CRA summary page states that the technical documentation elements are in Annex VI. They are not. Annex VI is the simplified EU declaration of conformity. The technical documentation is Annex VII.


The eight items

# Item What it covers
1 General description Intended purpose; software versions affecting compliance; for hardware, photographs or illustrations of external features, marking and internal layout; the user information required by Annex II
2 Design, development, production and vulnerability handling Architecture and how software components build on or feed into each other; the vulnerability handling process, including the SBOM, the coordinated vulnerability disclosure policy, evidence of a contact address for reports, and the technical solution for secure update distribution; production and monitoring processes
3 Cybersecurity risk assessment The assessment under Article 13, including how each Annex I Part I requirement applies
4 Support period The information taken into account to determine it under Article 13(8)
5 Harmonised standards Those applied in full or in part, whose references have been published in the Official Journal
6 Test reports Tests verifying conformity of the product and of the vulnerability handling processes with Annex I Parts I and II
7 EU declaration of conformity A copy
8 SBOM on request Further to a reasoned request from a market surveillance authority

Four rules around the checklist

Annex VII is a floor, not a ceiling. Article 31(1): the documentation must contain all relevant data or details of the means used to ensure compliance, and at least the Annex VII elements.

It must exist before you ship. Article 31(2): drawn up before the product is placed on the market, and continuously updated, where appropriate, at least during the support period.

One file, not several. Article 31(3): where other Union acts also require technical documentation, draw up a single set covering all of them.

Language matters if a notified body is involved. Article 31(4): the documentation must be in an official language of the Member State where the notified body is established, or a language acceptable to it. Budget for translation when you choose your conformity route.


How long to keep it

The EU declaration of conformity and the technical documentation must be kept at the disposal of national authorities for 10 years after the product is placed on the market, or for the support period, whichever is longer (Annex VIII).


Item 5 and the standards gap

Item 5 lists harmonised standards whose references have been published in the Official Journal. Sector standards such as IEC 62443-4-1, IEC 62443-4-2 or ETSI EN 303 645 are useful for structuring evidence, but unless cited in the Official Journal for the CRA they belong under item 2 as solutions adopted — not under item 5. Check the Official Journal for current citations before relying on any standard for presumption of conformity.

Sources

Position as at 20 September 2026. General information, not legal advice.