The technical file proves how the product meets the CRA. Annex VII has eight items. Items 2, 3 and 6 (design and vulnerability handling, risk assessment, test reports) usually take the longest to prepare.
Checklist
| # | Annex VII item |
|---|---|
| 1 | General description: intended purpose, software versions affecting compliance, hardware images and layout, Annex II user information |
| 2 | Design, development and production, and vulnerability handling: architecture, SBOM, coordinated vulnerability disclosure policy, evidence of the contact address, secure update distribution |
| 3 | Cybersecurity risk assessment and applicability of Annex I Part I |
| 4 | Information used to determine the support period |
| 5 | Harmonised standards, common specifications or certification schemes applied, or descriptions of alternative solutions |
| 6 | Test reports for the product and the vulnerability handling processes |
| 7 | Copy of the EU declaration of conformity |
| 8 | SBOM, on a reasoned request from a market surveillance authority |
What this means for manufacturers
The file is built from artefacts that already exist in engineering. The work is to select the right ones, make them consistent, version them and record who keeps them current. Where an Annex I requirement is not applicable, the file must say why (Article 13(4)).
If you cannot demonstrate it, you cannot rely on it as evidence.
Writing the file for the first release and treating it as finished. Substantial modifications and new vulnerabilities change what it must say.
We help manufacturers turn this requirement into a process and evidence.
Related guidance
- Cyber Resilience Act (CRA): what it is and what it requires
- CRA SBOM requirements: what is actually required?
This guidance explains the regulation and gives practical recommendations. It is not legal advice. Regulatory facts and recommendations are labelled separately. See our editorial policy (Slovenian): editorial policy.