Article 31, Annex VII ยท Regulation (EU) 2024/2847

What technical documentation does the CRA require?

Verified against the Official Journal text on

Technical documentation is the evidence file behind your CE marking. Article 31 requires it to show that the product and your processes meet the essential requirements, and Annex VII lists what it must contain: a product description, information on design and vulnerability-handling processes (including the SBOM and the coordinated disclosure policy), the cybersecurity risk assessment, the support-period reasoning, the standards applied, test reports, and a copy of the declaration of conformity. You draw it up before placing the product on the market and keep it updated, at least during the support period.

Basis: Art. 31, Annex VII

Judgment call: Annex VII items apply "as applicable to the relevant product", so a software-only product will fill some items (such as hardware photographs) with a justification of non-applicability rather than content.

What Article 31 asks for Art. 31(1), Art. 31(2), Art. 31(3)

Article 31 sets the purpose and the timing. The documentation must contain all relevant data on the means used to ensure the product and the manufacturer's processes comply with the essential requirements in Annex I, and it must contain at least the elements listed in Annex VII. It has to be drawn up before the product is placed on the market and continuously updated, where appropriate, at least during the support period.

Where the product is also subject to other Union legal acts that require technical documentation, you draw up a single set covering Annex VII and the other acts, rather than duplicating files.

The Annex VII contents Annex VII

Annex VII lists the content of the technical documentation, to be included as applicable to the relevant product. The eight items run from a general description through to the declaration of conformity, and they are the backbone of what an internal-control (module A) assessment produces.

  • A general description of the product: its intended purpose, software versions affecting compliance, for hardware the external and internal layout, and the Annex II user information and instructions. (Annex VII (1))
  • A description of design, development, production, and vulnerability handling, including system architecture, the SBOM, the coordinated vulnerability disclosure policy, the reporting contact address, and the secure-update approach. (Annex VII (2))
  • The cybersecurity risk assessment against which the product is designed and maintained under Article 13, including how the Part I essential requirements apply. (Annex VII (3))
  • The information taken into account to determine the support period under Article 13(8). (Annex VII (4))
  • A list of the harmonised standards, common specifications, or certification schemes applied, and where they were not applied, a description of the solutions adopted to meet the requirements. (Annex VII (5))
  • Reports of the tests carried out to verify conformity of the product and the vulnerability handling processes with the applicable essential requirements. (Annex VII (6))
  • A copy of the EU declaration of conformity. (Annex VII (7))
  • Where applicable, the SBOM, provided further to a reasoned request from a market surveillance authority where necessary to check compliance. (Annex VII (8))

How long you keep it Art. 13(13)

The documentation is not just for launch; it has a retention period. Manufacturers must keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market, or for the support period, whichever is longer. So a product with a long support period carries a correspondingly long documentation obligation.

A simplified form for small companies Art. 33(5)

The CRA anticipates that Annex VII is heavy for the smallest firms. Microenterprises and small enterprises may provide all the Annex VII elements using a simplified format, and the Commission is to specify that simplified technical documentation form by implementing act. Where a small company opts for it, notified bodies must accept that form for the purposes of conformity assessment. It is a lighter presentation of the same content, not a lighter set of requirements.

What you must do

  • Draw up technical documentation containing at least the Annex VII elements before placing the product on the market, and keep it updated at least during the support period. (Art. 31(1), Art. 31(2), Annex VII)
  • Keep the technical documentation and EU declaration of conformity available to market surveillance authorities for at least 10 years after placing on the market, or the support period if longer. (Art. 13(13))

The dates that decide your planning

11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

How long must I keep the technical documentation?

At least 10 years after the product is placed on the market, or for the support period if that is longer. The EU declaration of conformity is kept for the same period, at the disposal of market surveillance authorities. (Art. 13(13))

When does the documentation have to be ready?

Before the product with digital elements is placed on the market. After that it must be continuously updated where appropriate, at least during the support period, so it stays an accurate record of the product as it changes. (Art. 31(2))

Is there a simpler version for small companies?

Yes. Microenterprises and small enterprises may provide all Annex VII elements using a simplified form that the Commission specifies by implementing act, and notified bodies must accept that form. It covers the same content in a lighter presentation. (Art. 33(5))

Does the SBOM go inside the technical documentation?

Yes. The software bill of materials is part of the description of the vulnerability handling processes in Annex VII, alongside the coordinated vulnerability disclosure policy and the secure-update approach. (Annex VII (2))

Documentation follows from being a manufacturer

The free Vexwatch Scope Checker confirms whether you carry the manufacturer obligations, which is what triggers the technical documentation duty, before you start assembling the file.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.