DevKit Dossier

Cyber Resilience Act guides

CRA Annex VII: what the technical documentation contains

Last updated: 2026-09-29

Annex VII of the Cyber Resilience Act lists what the technical documentation contains as a minimum: eight points, from a general description of the product to the software bill of materials. It is a list of contents, not a form, and the regulation itself holds no template. Article 33(5) provides for a simplified format for microenterprises and small enterprises, which the Commission is to specify.

What the text says

Article 31(1), second sentence:

"It shall at least contain the elements set out in Annex VII."

Article 31(2):

"The technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be continuously updated, where appropriate, at least during the support period."

Annex VII, opening sentence:

"The technical documentation referred to in Article 31 shall contain at least the following information, as applicable to the relevant product with digital elements:"

The eight points, in short (our summary, not a quote):

  1. A general description of the product: its intended purpose, the "versions of software affecting compliance with essential cybersecurity requirements", photographs or illustrations for hardware products, and the user information and instructions of Annex II.
  2. A description of design, development and production and of the vulnerability handling processes: the system architecture, the vulnerability handling processes (point 2(b), quoted below), and the production and monitoring processes with their validation.
  3. The cybersecurity risk assessment under Article 13, including how the requirements of Annex I, Part I, are applicable.
  4. The information taken into account to determine the support period.
  5. A list of the harmonised standards, common specifications or European cybersecurity certification schemes applied in full or in part; where they were not applied, descriptions of the solutions adopted.
  6. Reports of the tests carried out on the product and on the vulnerability handling processes.
  7. A copy of the EU declaration of conformity.
  8. Where applicable, the software bill of materials, further to a reasoned request from a market surveillance authority.

Annex VII, point 2(b):

"necessary information and specifications of the vulnerability handling processes put in place by the manufacturer, including the software bill of materials, the coordinated vulnerability disclosure policy, evidence of the provision of a contact address for the reporting of the vulnerabilities and a description of the technical solutions chosen for the secure distribution of updates;"

Article 13(13):

"Manufacturers shall keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer."

What this means in practice

What to keep as evidence

Where DevKit Dossier fits

DevKit Dossier produces an evidence pack to attach to Annex VII technical documentation: a ZIP with pack.json, pack.pdf, the SBOMs byte for byte and a README.txt. Its records come from the SBOM archive per release, which your CI fills with CycloneDX or SPDX JSON from Syft or Trivy; from the daily vulnerability watch against OSV and GitHub advisories, CISA KEV, EPSS and NVD scores; and from the Article 14 reporting clock and the license inventory. The pack is one attachment, not the technical documentation: the risk assessment, the design description, the test reports and the EU declaration of conformity remain yours to write. DevKit Dossier supports your evidence; it gives no legal advice, does not certify anything and submits nothing to ENISA's single reporting platform. It is hosted in the EU and self-serve, at a flat price per organisation of 49, 99 or 249 EUR per month with a 14-day trial.

Join the waitlist

Sources

This guide is general information, not legal advice.