The Cyber Resilience Act, Regulation (EU) 2024/2847, puts the burden of proof on the manufacturer. Article 31 requires technical documentation to be drawn up before a product with digital elements is placed on the market, kept up to date over the support period, and kept available to authorities. Annex VII lists what it has to contain. For the manufacturer who self-assesses, it is the whole of the evidence; for the one who goes to a notified body, it is what the body examines first (Annex VIII, module B, point 3.3).

Annex VII is a page long and every item on it maps to something concrete. Here is the list, with what each point is asking you to produce.

The eight points of Annex VII

The technical documentation must contain at least the following, as applicable to the product.

1. A general description of the product. Its intended purpose; the versions of software that affect compliance with the essential requirements; for a hardware product, photographs or illustrations showing external features, marking and internal layout; and the user information and instructions that Annex II requires. In practice: a product sheet with a version table, and the user-facing security information (contact for vulnerabilities, support period, how to install updates, secure default configuration) that Annex II lists.

2. A description of design, development, production and vulnerability handling. Three parts. (a) Design and development information, including, where applicable, drawings, schemes and a description of the system architecture explaining how software components build on or feed into each other. (b) The vulnerability handling processes, explicitly including the software bill of materials, the coordinated vulnerability disclosure policy, evidence of a contact address for reporting vulnerabilities, and a description of how updates are distributed securely. (c) The production and monitoring processes and how they are validated. Point 2(b) is where the four Part II documents go, and it names them.

3. The cybersecurity risk assessment. The assessment under Article 13 against which the product is designed, developed, produced, delivered and maintained, including how the essential requirements in Part I of Annex I are applicable. This is the document that justifies every "where applicable" exclusion; a Part I, point 2 requirement left out without a line here is a gap.

4. The support period determination. The information taken into account to determine the support period under Article 13(8): at least five years unless the product is expected to be in use for less, and stated to users. Write down the expected time in use and the reasoning; a number without reasoning is what a market surveillance authority asks about first.

5. Standards applied, or what you did instead. A list of harmonised standards applied in full or in part, common specifications under Article 27, or European cybersecurity certification schemes; and, where none has been applied, a description of the solutions adopted to meet Annex I, including any other technical specifications used. Partly applied standards must say which parts. As of September 2026 no harmonised standard under the CRA has been published, so for most files this point is the description of the solutions adopted, per requirement.

6. Test reports. Reports of the tests carried out to verify conformity of the product and of the vulnerability handling processes with Annex I, Parts I and II. Penetration test reports, static analysis results, dependency scan output, update-mechanism tests: whatever you did, with dates.

7. A copy of the EU declaration of conformity. The Annex V declaration, signed, identifying the product.

8. The software bill of materials, on reasoned request. Where applicable, the SBOM itself, to be provided to a market surveillance authority on a reasoned request where it is necessary to check compliance with Annex I. Note the shape: the SBOM has to exist (point 2(b) and Annex I, Part II, point 1), but it does not have to be published, only produced when a reasoned request comes.

Three things people get wrong

"Before it is placed on the market" is the deadline, not December 2027. Article 31(1) requires the documentation to be drawn up before placing on the market. For a product first placed after 11 December 2027, that is before launch. For a product already on the market, Article 69 means the requirements bite only on substantial modification, so the file is due before the first substantial modification after that date.

Ten years or the support period, whichever is longer. Annex VIII requires the manufacturer to keep the declaration of conformity together with the technical documentation at the disposal of the national authorities for 10 years after the product was placed on the market or for the support period, whichever is longer. A product supported for twelve years is a file kept for twelve.

The file is per product, and it has to be kept current. Article 31 requires it to be kept up to date during the support period. A file that describes version 1 while version 4 ships is not a technical file; it is a historical document.

What each point turns into

The eight points are written as information, not as documents, and a notified body or an authority reads documents. The mapping we use, and that the technical file pack drafts for one product, is eleven controlled documents: a scope and classification determination (Article 3 and Annex III), the general description with user information (point 1 and Annex II), the risk assessment (point 3), the vulnerability handling process (point 2), the support period determination (point 4), the standards and test evidence record (points 5 and 6), the EU declaration of conformity (point 7), and the four operating documents Part II presumes: the coordinated vulnerability disclosure policy, the security update and support statement, the SBOM procedure, and the Article 14 reporting procedure, which is not in Annex VII but is the one an authority asks about the day something is exploited.

Whichever way you cut it, start with points 3 and 4. The risk assessment decides what the rest of the file has to say, and the support period decides for how long you are saying it.

Sources

  • Regulation (EU) 2024/2847, Article 31 and Annex VII (the eight points, paraphrased closely; read the text for the wording), Annex II for user information, Annex V for the declaration, Annex VIII Part I point 4.2 and Part II point 10 for the ten-year rule, Article 13(8) for the support period, Article 27 for standards and common specifications, Article 69 and 71(2) for the dates. Read from the Official Journal text on EUR-Lex on 11 September 2026.

This is not legal advice. Annex VII is one page; the point numbers above let you read it against your own file in a few minutes.