
Documentation and conformity
CRA: creating the technical documentation and preparing the conformity assessment
From 11 December 2027, every product newly placed on the market needs the technical documentation under Annex VII, the information and instructions to the user under Annex II, a conformity assessment, the EU declaration of conformity and the CE marking. We build the documentation with your teams and prepare the assessment.
What belongs in the technical documentation
Annex VII sets the minimum content, including: a general product description with intended purpose, security-relevant software versions and user information; a description of design, development and production including system architecture and vulnerability handling processes with the SBOM and CVD policy; the risk assessment under Article 13; the basis for the support period; the standards or specifications applied; test and examination reports; the EU declaration of conformity.
The documentation is drawn up before placing on the market, kept up to date at least during the support period and retained for at least ten years or for the support period, whichever is longer (Art. 13(13), Art. 31). The applicable assessment route depends on the product class (Art. 32).
Service modules
Per product, building on what already exists.
Structure under Annex VII
Documentation structure per product, mapping of existing documents, list of gaps.
Risk assessment
Documented cybersecurity risk assessment per product, derived from architecture and code and re-runnable after changes.
Article on risk assessmentUser information under Annex II
Contact point for vulnerabilities, intended purpose, secure commissioning and updates, type and end date of the support period.
Evidence for Annex I
For each requirement, how it is implemented and what evidences it, including your existing test and examination reports.
Preparing the assessment route
Technical assessment of product class and procedure (module A, B and C, H or certification), preparation of documents for a notified body where needed.
Conformity assessment explainedSupply chain and handover
If you supply software to other manufacturers, we define which parts you hand over per release and in what form.
What you end up with
Documentation you can take into the conformity assessment.
01
Documentation package per product
Structured under Annex VII, with references to the evidence.
02
User information
Content under Annex II, ready for manual, website or packaging.
03
Input for the declaration of conformity
Information under Article 28 and Annex V, for you to issue and sign.
04
Maintenance rule
Who updates the documentation on which occasion.
How we work
From existing material to assessment-ready documentation.
1
Free initial call
Products, existing documents, deadlines. You then receive a proposal with a clearly defined scope.
2
Review
Record existing documents and evidence and map them to Annex VII.
3
Close gaps
Create the risk assessment, Annex I evidence and user information.
4
Prepare the assessment
Compile documents for the chosen route.
5
Handover
Package, input for the declaration of conformity and maintenance rule.
What we do not do
So that expectations are right:
- We are not a notified body, do not issue certificates and do not sign the declaration of conformity; you do that as the manufacturer.
- No legal services: we give a technical assessment of product class and assessment route; the legal decision rests with your legal department or counsel.
- We do not carry out penetration tests.
The CRA obligations remain with your company. We help you meet them and document the evidence.
Frequently asked questions
When do we need the technical documentation?+
For products placed on the market from 11 December 2027, before placing them on the market. Building it requires the risk assessment and Annex I evidence, which in turn need lead time.
Do we need a notified body?+
That depends on the product class. For products not listed in Annex III or IV, internal control is sufficient. For class I only if harmonised standards, common specifications or a certification scheme at assurance level at least ‘substantial’ are applied in full. For class II and critical products, third-party assessment is required.
Can we use existing documents?+
Yes. Documents from existing certifications, development processes and product files are mapped to Annex VII, and only what is missing is added.
What does creating the technical documentation cost?+
It depends on the number of products, the product class and the state of your documents. After a free initial call you receive a proposal with a clearly defined scope.
Further reading
- Technical documentation under Annex VII
- Conformity assessment and CE marking
- Product classes
- Support period and update duty
- CRA checklist, step 9
This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).
Last updated: 2026-10-08
Kontakt aufnehmen
Prepare documentation and conformity
Tell us about your products and the state of your documentation. The initial call is free and without obligation; we usually reply within one to two working days.