Marketplace

Cyber Resilience Act · Annex VII

The CRA technical file, drafted: eleven documents

CRANow in force . Reporting duties apply since 11 Sept 2026.

The technical documentation Article 31 and Annex VII require of a manufacturer, as eleven documents for one product, delivered as PDF and DOCX, generic placeholders where your product goes.

€5,000

Documents by email within minutes; add them to a free workspace whenever you like.

excl. VAT · one payment · invoice from Paddle · no account

The 11 documents

Every document by name, one line on what it settles, and the point of the Regulation it satisfies.

  1. 1 · Article 3 and Annex III

    Scope and classification determination

    Whether the product is in scope, and its class under Annex III, with the reasoning.

  2. 2 · Annex VII point 1, Annex II

    General description and user information

    What the product is, what it does and what the user is told, per Annex II.

  3. 3 · Annex VII point 3, Annex I Part I

    Cybersecurity risk assessment

    The Article 13 risk assessment against every Annex I Part I requirement.

  4. 4 · Annex VII point 2, Annex I Part II

    Vulnerability handling process

    How vulnerabilities are found, fixed and communicated, per Annex I Part II.

  5. 5 · Annex VII point 4, Article 13(8)

    Support period determination

    How long security updates are provided and why, per Article 13(8).

  6. 6 · Annex VII points 5 and 6

    Standards applied and test evidence

    Which standards and specifications apply and the evidence that tests were run.

  7. 7 · Annex VII point 7, Annex V

    EU declaration of conformity (draft)

    The declaration of conformity, ready for the signature, per Annex V.

  8. 8 · Annex I Part II points 5 and 6

    Coordinated vulnerability disclosure policy

    The coordinated vulnerability disclosure policy the Regulation requires to be published.

  9. 9 · Annex I Part II points 2, 7 and 8, Article 13(8)

    Security updates and support statement

    What updates are provided, how, for how long, and where the user reads it.

  10. 10 · Annex I Part II point 1

    Software bill of materials procedure

    How the software bill of materials is produced, in which format, and kept current.

  11. 11 · Article 14, Article 71(2)

    Article 14 reporting procedure

    Who reports what to ENISA and the CSIRT, and the 24-hour, 72-hour and 14-day steps.

A sample page

The first page of the Cybersecurity risk assessment, as it arrives: PDF and DOCX, the generic placeholders in square brackets are what your workspace fills in.

First page of the Cybersecurity risk assessment, a sample

Who it is for

  • A manufacturer of software or a connected product placed on the EU market, with a technical file to show from 11 December 2027.
  • A team that would rather start from a complete, structured set than from the Regulation's text.
  • A consultancy drafting the file for a client, one set per product.

Who it is not for

  • A product outside the Regulation's scope; the scope check on the CRA hub is free.
  • An importer or distributor: the importer and distributor pack is the one with your duties.
  • A team that needs the file kept current across releases: that is the workspace's job, not a file's.

How delivery works

  1. 1. Pay

    Paddle takes the payment in the overlay on this page and issues the invoice, VAT handled for your country.

  2. 2. Receive

    Within minutes an email carries a link, good for seven days, to the set as PDF and DOCX.

  3. 3. Use, or claim

    Edit the DOCX yourself, or create a free workspace with the same email: the purchase attaches to it and the documents are drafted again from your own product record.

In a workspace

A workspace created, or an owner signing in, with the buyer's address claims the purchase once. The same 11 documents are then drafted from the product you register, kept current as the record changes, and exported with the audit trail. The trial is 14 days, no card.

Regulation references

Every document names the article or annex point it satisfies; the Official Journal text is the source, read in English.

  • Article 3 and Annex III
  • Annex VII point 1, Annex II
  • Annex VII point 3, Annex I Part I
  • Annex VII point 2, Annex I Part II
  • Annex VII point 4, Article 13(8)
  • Annex VII points 5 and 6
  • Annex VII point 7, Annex V
  • Annex I Part II points 5 and 6
  • Annex I Part II points 2, 7 and 8, Article 13(8)
  • Annex I Part II point 1
  • Article 14, Article 71(2)

The terms

  • One payment; the invoice comes from Paddle, our merchant of record, with VAT for your country.
  • The documents are yours to edit and keep; a link that has expired is re-sent on request.
  • Cancellation and refund terms are on the cancellation page. Cancellation and refund

Questions

Is this the full technical documentation Annex VII asks for?
It is the structure and the drafted text of every Annex VII point; the product-specific facts, test results and the SBOM are yours to fill in, and the placeholders show where.
Do I need an account to buy it?
No. Paddle takes the payment on this page and the documents arrive by email. A free workspace can claim the purchase later if you want them drafted from your own product record.
Which product classes does it cover?
Default products under self-assessment (Module A). An important or critical product needs the same file plus a conformity route the documents name; the scope determination in the pack decides which.
In which language are the documents?
English, the language every notified body and market surveillance authority accepts for the file; the page and the support are in yours.
What does the workspace add?
The same eleven documents drafted from the product you register, the Article 14 clocks, the notifications drafted when a vulnerability is exploited, and an export with the audit trail.

The other path

€249 a month runs the same file live: register the product, the workspace drafts every document from its record, keeps the clocks and stays current.

Start free, 14 days, no card

This page in:DeutschFrançaisNederlandsEspañolDansk