CRA Annex VII: what the technical documentation contains
Last updated: 2026-09-29
Annex VII of the Cyber Resilience Act lists what the technical documentation contains as a minimum: eight points, from a general description of the product to the software bill of materials. It is a list of contents, not a form, and the regulation itself holds no template. Article 33(5) provides for a simplified format for microenterprises and small enterprises, which the Commission is to specify.
What the text says
Article 31(1), second sentence:
"It shall at least contain the elements set out in Annex VII."
Article 31(2):
"The technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be continuously updated, where appropriate, at least during the support period."
Annex VII, opening sentence:
"The technical documentation referred to in Article 31 shall contain at least the following information, as applicable to the relevant product with digital elements:"
The eight points, in short (our summary, not a quote):
- A general description of the product: its intended purpose, the "versions of software affecting compliance with essential cybersecurity requirements", photographs or illustrations for hardware products, and the user information and instructions of Annex II.
- A description of design, development and production and of the vulnerability handling processes: the system architecture, the vulnerability handling processes (point 2(b), quoted below), and the production and monitoring processes with their validation.
- The cybersecurity risk assessment under Article 13, including how the requirements of Annex I, Part I, are applicable.
- The information taken into account to determine the support period.
- A list of the harmonised standards, common specifications or European cybersecurity certification schemes applied in full or in part; where they were not applied, descriptions of the solutions adopted.
- Reports of the tests carried out on the product and on the vulnerability handling processes.
- A copy of the EU declaration of conformity.
- Where applicable, the software bill of materials, further to a reasoned request from a market surveillance authority.
Annex VII, point 2(b):
"necessary information and specifications of the vulnerability handling processes put in place by the manufacturer, including the software bill of materials, the coordinated vulnerability disclosure policy, evidence of the provision of a contact address for the reporting of the vulnerabilities and a description of the technical solutions chosen for the secure distribution of updates;"
Article 13(13):
"Manufacturers shall keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer."
What this means in practice
- As written, the list applies "as applicable to the relevant product". Photographs, for example, are asked of hardware products only.
- The text asks for the documentation before the product is placed on the market, and for updates at least during the support period. Under Article 13(8) the support period is at least five years, unless the product is expected to be in use for less.
- On a plain reading, some items change with every release: the software versions, the software bill of materials, the vulnerabilities handled and the test reports.
- The simplified format for microenterprises and small enterprises is to be specified by the Commission through implementing acts (Article 33(5)). As of 29 September 2026 the Commission has not adopted the simplified technical documentation form under Article 33(5).
- Article 13(22) asks manufacturers to provide the documentation to a market surveillance authority on a reasoned request.
What to keep as evidence
- One dated set of technical documentation per product, with a record of what changed and when.
- For each version: the software bill of materials, the vulnerabilities known and handled, and the test reports.
- The coordinated vulnerability disclosure policy and evidence that the contact address is provided.
- The information behind the support period.
- The EU declaration of conformity.
Where DevKit Dossier fits
DevKit Dossier produces an evidence pack to attach to Annex VII technical documentation: a ZIP with pack.json, pack.pdf, the SBOMs byte for byte and a README.txt. Its records come from the SBOM archive per release, which your CI fills with CycloneDX or SPDX JSON from Syft or Trivy; from the daily vulnerability watch against OSV and GitHub advisories, CISA KEV, EPSS and NVD scores; and from the Article 14 reporting clock and the license inventory. The pack is one attachment, not the technical documentation: the risk assessment, the design description, the test reports and the EU declaration of conformity remain yours to write. DevKit Dossier supports your evidence; it gives no legal advice, does not certify anything and submits nothing to ENISA's single reporting platform. It is hosted in the EU and self-serve, at a flat price per organisation of 49, 99 or 249 EUR per month with a 14-day trial.
Sources
This guide is general information, not legal advice.
DevKit Dossier