This document is under active development and has not been finalised.
Skip to content

Chapter 7: Technical Documentation

7.1 Overview

The Technical Documentation pursuant to Annex VII CRA constitutes the central evidence documentation for the conformity of a product with digital elements. It must be prepared prior to placing on the market and retained for at least 10 years.

LEGAL BASIS

Art. 31 CRA: "The technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be updated continuously during the expected product lifetime or during a period of five years after the placing on the market, whichever is shorter."

Annex VII CRA defines the minimum content of the Technical Documentation.

Chapter Structure

SectionTopicAnnex VII Reference
7.1Product Description (Template)No. 1: General description
7.2Security ArchitectureNo. 3: Architecture and design
7.3Update MechanismNo. 4: Update provision
7.4Support & Lifecycle PolicyArt. 13(8), Annex II No. 5
7.5Security Requirements (Annex I)Annex I Part I: 13 essential requirements
7.6Annex VII – GuideAnnex VII: Complete documentation guide

Additional Mandatory Content (in Cross-Cutting Chapters)

Annex VII RequirementDocumentation LocationChapter
SBOM (machine-readable)SBOM & SigningCh. 2
Cybersecurity risk assessmentRisk AssessmentCh. 3
Vulnerability handlingVulnerability ManagementCh. 3
Coordinated disclosureDisclosure PolicyCh. 5
Conformity assessment resultsConformity AssessmentCh. 8
EU Declaration of ConformityEU DoCCh. 8
User information (Annex II)User InformationAnnex

Retention Obligation

Art. 10(13) CRA: The Technical Documentation shall be retained for 10 years after the product is placed on the market or for the duration of the Support Period — whichever period is longer.

Documentation TypeStorage LocationRetention Period
Technical DocumentationThis repository (Git)10 years
SBOM per versionRelease assets + sbom/10 years
Declaration of ConformityThis repository10 years
Risk assessmentsThis repository10 years
Test resultsGitHub Actions Artifacts / Archive10 years

Product-Specific Documentation

ACTION REQUIRED

For each CRA-relevant product, an individual Technical Documentation must be prepared. The templates provided in this chapter (in particular 7.1 Product Description) serve as a template.

Product-specific documentation is maintained in separate directories under docs/products/<productname>/.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT