CRA: creating the technical documentation and preparing the conformity assessment
Annex VII · Annex II · Art. 32

Documentation and conformity

CRA: creating the technical documentation and preparing the conformity assessment

From 11 December 2027, every product newly placed on the market needs the technical documentation under Annex VII, the information and instructions to the user under Annex II, a conformity assessment, the EU declaration of conformity and the CE marking. We build the documentation with your teams and prepare the assessment.

What belongs in the technical documentation

Annex VII sets the minimum content, including: a general product description with intended purpose, security-relevant software versions and user information; a description of design, development and production including system architecture and vulnerability handling processes with the SBOM and CVD policy; the risk assessment under Article 13; the basis for the support period; the standards or specifications applied; test and examination reports; the EU declaration of conformity.

The documentation is drawn up before placing on the market, kept up to date at least during the support period and retained for at least ten years or for the support period, whichever is longer (Art. 13(13), Art. 31). The applicable assessment route depends on the product class (Art. 32).

Service modules

Per product, building on what already exists.

Structure under Annex VII

Documentation structure per product, mapping of existing documents, list of gaps.

Risk assessment

Documented cybersecurity risk assessment per product, derived from architecture and code and re-runnable after changes.

Article on risk assessment

User information under Annex II

Contact point for vulnerabilities, intended purpose, secure commissioning and updates, type and end date of the support period.

Evidence for Annex I

For each requirement, how it is implemented and what evidences it, including your existing test and examination reports.

Preparing the assessment route

Technical assessment of product class and procedure (module A, B and C, H or certification), preparation of documents for a notified body where needed.

Conformity assessment explained

Supply chain and handover

If you supply software to other manufacturers, we define which parts you hand over per release and in what form.

What you end up with

Documentation you can take into the conformity assessment.

  1. 01

    Documentation package per product

    Structured under Annex VII, with references to the evidence.

  2. 02

    User information

    Content under Annex II, ready for manual, website or packaging.

  3. 03

    Input for the declaration of conformity

    Information under Article 28 and Annex V, for you to issue and sign.

  4. 04

    Maintenance rule

    Who updates the documentation on which occasion.

How we work

From existing material to assessment-ready documentation.

  1. 1

    Free initial call

    Products, existing documents, deadlines. You then receive a proposal with a clearly defined scope.

  2. 2

    Review

    Record existing documents and evidence and map them to Annex VII.

  3. 3

    Close gaps

    Create the risk assessment, Annex I evidence and user information.

  4. 4

    Prepare the assessment

    Compile documents for the chosen route.

  5. 5

    Handover

    Package, input for the declaration of conformity and maintenance rule.

What we do not do

So that expectations are right:

  • We are not a notified body, do not issue certificates and do not sign the declaration of conformity; you do that as the manufacturer.
  • No legal services: we give a technical assessment of product class and assessment route; the legal decision rests with your legal department or counsel.
  • We do not carry out penetration tests.

The CRA obligations remain with your company. We help you meet them and document the evidence.

Frequently asked questions

When do we need the technical documentation?+

For products placed on the market from 11 December 2027, before placing them on the market. Building it requires the risk assessment and Annex I evidence, which in turn need lead time.

Do we need a notified body?+

That depends on the product class. For products not listed in Annex III or IV, internal control is sufficient. For class I only if harmonised standards, common specifications or a certification scheme at assurance level at least ‘substantial’ are applied in full. For class II and critical products, third-party assessment is required.

Can we use existing documents?+

Yes. Documents from existing certifications, development processes and product files are mapped to Annex VII, and only what is missing is added.

What does creating the technical documentation cost?+

It depends on the number of products, the product class and the state of your documents. After a free initial call you receive a proposal with a clearly defined scope.

Further reading

This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).

Last updated: 2026-10-08

Kontakt aufnehmen

Prepare documentation and conformity

Tell us about your products and the state of your documentation. The initial call is free and without obligation; we usually reply within one to two working days.