Annex VII, evidenced chapter by chapter
Product description, architecture, risk assessment, SBOM, and test reports — structured in one place, per product
Annex VII of the EU Cyber Resilience Act specifies what the technical documentation must contain — from the product description through design and development to the risk assessment. In Kunnus, this documentation takes shape where you already work: architecture and interfaces from the product inventory, the risk assessment from the risk analysis, the SBOM from the repository, test reports as uploads. Kunnus covers the CRA layer of the CE documentation.
Technical Documentation — SmartSensor XR
Key Benefits
Architecture Documentation per Product
Architecture description, diagram upload, network interfaces, physical interfaces, and component relationships — maintained directly on the product.
Risk Assessment Included
The documented cybersecurity risk assessment under Art. 13(2) is a mandatory part of the technical documentation — and flows in directly from the risk analysis.
SBOM as a Component
Every product's current SBOM lives in the central repository and is assigned to the documentation — versioned and machine-readable.
Documents & Test Reports
Test reports, certificates, and further records are stored per product in the detail tabs — findable, versioned, and assigned to the right product.
Capabilities
Structure per Annex VII
Annex VIIThe documentation follows the chapters of Annex VII: product description, design and development, vulnerability handling, risk assessment, standards, test reports.
Architecture & Interfaces
Architecture description with diagram upload, network and physical interfaces, and component relationships — per product and version.
Risk Assessment as a Mandatory Chapter
Art. 13Risk analysis results are assigned to the documentation and carried forward on change — kept up to date, as Art. 13(3) requires.
Vulnerability Process Documented
Annex I Part IICVD policy, handling process, and advisories from the vulnerability workflow evidence the Annex I Part II requirements — no duplicate upkeep.
Currency across the Lifecycle
New versions and changes are linked to the documentation. The activity history shows what changed and when.
Use Cases
Market Surveillance Request
The authority requests a product's technical documentation. Instead of assembling files from shared drives, the documentation is available structured per product — including risk assessment and SBOM.
Conformity Assessment with a Notified Body
For a class II product, the notified body receives complete, structured records per Annex VII — architecture, risk assessment, and test reports in one place.
Product Update without a Documentation Gap
A firmware update changes interfaces and components. The documentation is carried forward on the new version — the history stays complete.
Related Features
Build your technical documentation in a structured way
See how the Annex VII documentation takes shape in Kunnus — from the work you're already doing. We'll walk you through the structure in a personalized demo.