CRA technical documentation index
Four sheets that map the Annex VII file: one row per element per product, the declaration's Annex V items, and a retention schedule with derived end dates.
Compliance5 Sept 20263 min read
On this page
cra-technical-documentation-index.xlsx · 9 kBLicensed CC BY 4.0
What this is
A pointer layer over the technical documentation a manufacturer draws up before placing a product with digital elements on the market. One row per Annex VII element per product: the record that answers it, where that record sits, the role that owns it, and whether it is finished. Section 3.2 of CRA technical documentation and the declaration of conformity produces it. The evidence stays where it is produced; this file is what makes it findable.
How to use it
- Open one row per element, per product version. The elements are the eight Annex VII points, with 2(a), 2(b) and 2(c) split out 1. See the playbook, section 3.2.
- Name the record and its location in one cell. A location that only the producing team can open is not a location.
- Give every row an owning role, never a person. Ownership follows the function that produces the record.
- Set status from the closed list: 1. Complete, 2. Draft, 3. Missing or 4. Not applicable.
- Where an element is out of scope, file the justification with it. Where an essential requirement does not apply, the documentation carries a clear justification 2.
- Fill the Declaration sheet from the signed declaration. It carries the Annex V items, with the value or the record that answers each 3.
- Derive every retention end date. The floor is ten years after placing, or the support period if that is longer 4.
- Review on the release gate, not on a calendar. The documentation is kept up to date, at least through the support period 5.
What good looks like
Five of the nine Index columns, from the workbook's example rows.
| Element ID | Product | Owner (role) | Status | Next review |
|---|---|---|---|---|
| AVII-1 | Gateway firmware 4.4.3 | Product manager | 1. Complete | 2027-05-10 |
| AVII-2B | Gateway firmware 4.4.3 | Product security lead | 2. Draft | 2027-02-06 |
| AVII-3 | Gateway firmware 4.4.3 | Risk lead | 1. Complete | 2027-05-10 |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Element ID | yes | The Annex VII point the row answers | Inventing an element the annex does not name |
| Annex VII element | yes | The element as the annex puts it | Replacing it with an internal document title |
| Product | yes | The product and version the row covers | One row for a product family that shares nothing |
| Owner (role) | yes | The role accountable for the record | A person, or the file's custodian for every row |
| Record | yes | The record's name and where it sits | "In the wiki", with no path |
| Status | yes | 1. Complete, 2. Draft, 3. Missing, 4. Not applicable | Not applicable with no justification filed |
| Last updated | yes | When the record changed, not the row | The date the spreadsheet was touched |
| Retention end | yes | Derived from placing date and support period | A general document-retention period |
Download
- File:
cra-technical-documentation-index.xlsx(xlsx, 9 KB) — sheets Read first, Index, Declaration, Retention. - Markdown variant: the same tables as
_cra-technical-documentation-index.md, beside the workbook. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data, no organisation names; the example rows are invented.
Related
- Playbook: CRA technical documentation and the declaration of conformity.
- Playbook: Choosing the CRA conformity route, which decides what the module adds.
- Template: Vulnerability handling record, the records behind element 2(b).
References
- European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). OJ L, 2024/2847, 20.11.2024. Articles 13 and 31 and Annexes V and VII read at https://publications.europa.eu/resource/celex/32024R2847 6
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by any standards body.
Sources
- 1EU Publications Office CELEX 32024R2847 Annex VII points 1 to 8 · verified 2026-09-05
- 2EU Publications Office CELEX 32024R2847 Art. 13(4) · verified 2026-09-05
- 3EU Publications Office CELEX 32024R2847 Annex V points 1 to 8 · verified 2026-09-05
- 4EU Publications Office CELEX 32024R2847 Art. 13(13) · verified 2026-09-05
- 5EU Publications Office CELEX 32024R2847 Art. 31(2) · verified 2026-09-05
- 6EU Publications Office CELEX 32024R2847 Arts. 13 and 31 and Annexes V and VII · verified 2026-09-05