Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What CRA evidence should manufacturers retain, and for how long?
Updated
Regulation (EU) 2024/2847 Article 13(13): manufacturers keep technical documentation and the EU declaration of conformity for at least 10 years after placing on the market or the support period, whichever is longer. This page is not legal advice and does not start a clock.
CRA evidence-retention checklist, last verified 9 September 2026 against Regulation (EU) 2024/2847 Articles 13, 14, 18, 19, 28, 31, 32 and 71, Annex VII (content of the technical documentation) and Annex VIII (conformity assessment procedures), the European Commission's CRA pages (Commission materials, not the regulation), and ENISA product-security materials (agency guidance, not the regulation). It is not legal advice, not a filing, not a determination that the CRA applies, not YOUR 10-year file, and not a substitute for counsel. This product does not retain YOUR CRA technical documentation pack automatically.
This is evidence retention, not YOUR file
Audience: a compliance owner, CISO, or product lead at an organisation that might be a manufacturer of products with digital elements under Regulation (EU) 2024/2847. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been placed on the Union market, that a support period has been set, or that a 10-year keep has started.
Article 13(13) is the keep rule this page quotes. It is a manufacturer duty in Chapter II. It is not Article 14. Article 14 reporting applies from 11 September 2026 (Article 71(2)). Article 13 essential-requirements and documentation duties, including this keep, follow 11 December 2027 unless the article you quote says otherwise. This page does not move those dates. Last verified 9 September 2026. Not legal advice.
- Statute versus guidance: Articles 13, 14, 18, 19, 28, 31, 32 and 71, Annex VII, and Annex VIII are legal requirements only if they apply. Commission CRA pages are Commission materials, not the regulation. ENISA product-security materials are agency guidance, not the regulation. Recommended practice is labelled as recommended practice. This page quotes which kind of text it is relying on.
- The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The CRA-cluster Article 14 overview on this site is how Article 14 sits in the cluster. The statute-clock Article 14 guide on this site is the ladder under breach reporting.
- The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. The vulnerability-disclosure guide on this site is the coordinated-disclosure page. The readiness-checklist guide on this site is the end-to-end CRA readiness page. A dedicated vulnerability-management, security-updates, and final-report guide is not on this site yet. Naming them is not a link.
- This product does not retain YOUR CRA technical documentation pack automatically, does not draw up YOUR EU declaration of conformity, and does not file with a CSIRT or ENISA. Readiness in this product is not CE marking. A named human still submits.
The statutory keep — 10 years or the support period, whichever is longer
Last verified 9 September 2026 against Article 13(13) on EUR-Lex. Article 13(13): manufacturers shall keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. That is the legal requirement. This page does not start that keep for YOU.
The 10-year limb is counted from placing on the market (Article 3(21): the first making available of a product with digital elements on the Union market). The other limb is the support period determined under Article 13(8). Article 13(8): without prejudice to the second subparagraph, the support period shall be at least five years; where the product is expected to be in use for less than five years, the support period shall correspond to the expected use time. If the support period is five years, ten years after placing on the market is longer. If the support period is longer than ten years, the support period is longer. This page does not compute YOUR period.
Article 31(2): the technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be continuously updated, where appropriate, at least during the support period. Updating during the support period is a living-file duty. The Article 13(13) keep is how long that file then stays at the disposal of market surveillance authorities. They are not the same sentence.
| Limb | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| 10 years after placing on the market | Article 13(13): keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market. | Legal requirement — Article 13(13). Only if the CRA applies. This page does not find that YOU have placed a product on the Union market. | 9 September 2026 |
| Or the support period, whichever is longer | The same sentence of Article 13(13) adds: or for the support period, whichever is longer. Article 13(8) is how the support period is determined. The keep is the longer of the two limbs, not a choice of the shorter. | Legal requirement — Articles 13(8) and 13(13). | 9 September 2026 |
| When that keep applies | Article 71(2): this Regulation shall apply from 11 December 2027. Article 14 shall apply from 11 September 2026. Article 13(13) is not Article 14. This keep follows full application unless counsel says another article moves it. | Legal requirement — Article 71(2). This page does not start an Article 14 clock and does not start a 10-year keep. | 9 September 2026 |
Evidence checklist — item, cited text, kind of text, what the product keeps
Work this table with counsel. It is a checklist of what the cited text says to retain. It is not YOUR file, not a determination that a keep has started, and not a substitute for Annex VII. Last verified 9 September 2026. Not legal advice.
| Item | What the cited text says | Kind of text | What the product does / does not keep |
|---|---|---|---|
| Technical documentation | Article 13(12): before placing on the market, manufacturers shall draw up the technical documentation referred to in Article 31. Article 31(1): it shall contain all relevant data or details of the means used to ensure compliance with Annex I, and shall at least contain the elements set out in Annex VII. Article 31(2): drawn up before placing on the market and continuously updated, where appropriate, at least during the support period. Article 13(13): keep it at the disposal of market surveillance authorities for at least 10 years after placing on the market or for the support period, whichever is longer. | Legal requirement — Articles 13(12), 13(13) and 31, and Annex VII. Only if the CRA applies. | Does not retain YOUR CRA technical documentation pack automatically. Compliance evidence collection records control-mapped artifacts for a starter subset. Those rows are not Annex VII. |
| EU declaration of conformity | Article 13(12): where conformity has been demonstrated, manufacturers shall draw up the EU declaration of conformity in accordance with Article 28. Article 13(13) keeps that declaration with the technical documentation for the same 10-year / support-period keep. Annex VII point 7: a copy of the EU declaration of conformity is an element of the technical documentation. | Legal requirement — Articles 13(12), 13(13) and 28, and Annex VII point 7. | Does not draw up YOUR EU declaration of conformity and does not keep it for 10 years. |
| Conformity assessment records | Article 13(12): manufacturers shall carry out the chosen conformity assessment procedures as referred to in Article 32 or have them carried out. Annex VIII (EU-type examination) point 10: the manufacturer shall keep a copy of the EU-type examination certificate, its annexes and additions together with the technical documentation at the disposal of the national authorities for 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. Annex VIII (full quality assurance) repeats that 10-year / support-period keep for technical documentation, quality-system documentation, approved changes, and notified-body decisions and reports. | Legal requirement — Articles 13(12) and 32, and Annex VIII. | Does not run Article 32 procedures, does not act as a notified body, and does not keep YOUR certificate file. |
| Vulnerability-handling process description | Annex VII point 2(b): the technical documentation includes necessary information and specifications of the vulnerability handling processes put in place by the manufacturer, including the software bill of materials, the coordinated vulnerability disclosure policy, evidence of the provision of a contact address for the reporting of the vulnerabilities, and a description of the technical solutions chosen for the secure distribution of updates. | Legal requirement — Annex VII point 2(b), as content of the Article 31 technical documentation. | Does not keep YOUR Annex VII process description. Connector-ingested vulnerability records are security findings, not that description. |
| Vulnerability-handling logs (systematic documentation) | Article 13(7): manufacturers shall systematically document, in a manner that is proportionate to the nature and the cybersecurity risks, relevant cybersecurity aspects concerning the products with digital elements, including vulnerabilities of which they become aware and any relevant information provided by third parties, and shall, where applicable, update the cybersecurity risk assessment of the products. Article 13(7) does not state a 10-year period. The 10-year / support-period keep attaches to the technical documentation under Article 13(13). | Legal requirement — Article 13(7) (a documentation duty, not a second 10-year clock). Putting those records into the living technical documentation is how they can fall under Article 13(13). That step is for counsel, not this page. | Keeps connector-ingested vulnerability records and a cyber risk register under Security. Those rows are not Article 13(7) logs retained for 10 years. |
| Software bill of materials (SBOM) | Annex VII point 2(b) includes the software bill of materials in the vulnerability-handling process description. Annex VII point 8: where applicable, the software bill of materials, further to a reasoned request from a market surveillance authority provided that it is necessary in order for that authority to be able to check compliance with the essential cybersecurity requirements set out in Annex I. Recital 77 (a recital, not an operative article) states that manufacturers should not be obliged to make the SBOM public. | Legal requirement — Annex VII points 2(b) and 8. Recital 77 is a recital, not an operative article. | Generates and queries SBOMs (CycloneDX) for blast radius. That inventory is not YOUR CRA SBOM kept at the disposal of market surveillance for 10 years. |
| Update records versus update availability | Article 13(9): manufacturers shall ensure that each security update, as referred to in Part II, point (8), of Annex I, which has been made available to users during the support period, remains available after it has been issued for a minimum of 10 years or for the remainder of the support period, whichever is longer. That is availability of the update itself, not a quoted duty to keep a log of updates for 10 years. Annex VII point 2(b) asks for a description of the technical solutions chosen for the secure distribution of updates — inside the technical documentation. | Legal requirement — Article 13(9) (update availability) and Annex VII point 2(b) (description in the technical documentation). Distinct sentences. Recommended practice of keeping distribution logs with the living technical documentation is recommended practice, not Article 13(9). | Does not keep YOUR security updates available for 10 years and does not keep YOUR update-distribution archive. |
| User information and instructions (Annex II) | Article 13(18): manufacturers shall keep the information and instructions to the user set out in Annex II at the disposal of users and market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. Where such information and instructions are provided online, manufacturers shall ensure that they are accessible, user-friendly and available online for at least 10 years after placing on the market or for the support period, whichever is longer. | Legal requirement — Article 13(18). Same 10-year / support-period structure as Article 13(13), applied to Annex II information. | Does not host YOUR Annex II instructions for 10 years. |
| Reporting records (Article 14) | Article 14 sets the 24-hour early warning, 72-hour notification, and final-report duties, submitted via the single reporting platform. Article 14 does not state a 10-year keep of copies of those notifications. Keeping copies of what was submitted, when, and to which CSIRT designated as coordinator is recommended practice, not a quoted Article 14 retention period. | Legal requirement — Article 14 (to notify, if it applies). Retention of copies is recommended practice, not a quoted statutory period. This page does not invent a 10-year Article 14 archive. | Signed-in Compliance → CRA reporting tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker does not file and is not a 10-year Article 14 archive. |
| Authorised-representative keep | Article 18(3)(a): the mandate shall allow the authorised representative to keep the EU declaration of conformity referred to in Article 28 and the technical documentation referred to in Article 31 at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. | Legal requirement — Article 18(3). Only if a mandate exists. This page does not find that YOU are an authorised representative. | Does not act as YOUR authorised representative and does not keep that mandate file. |
| Importer copy of the EU declaration of conformity | Article 19(6): importers shall, for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer, keep a copy of the EU declaration of conformity at the disposal of the market surveillance authorities and ensure that the technical documentation can be made available to those authorities, upon request. | Legal requirement — Article 19(6). Only if the importer role applies. The importer keep is a copy of the declaration plus the ability to make the technical documentation available, not a second manufacturer pack. | Does not keep YOUR importer copy of the EU declaration of conformity. |
What Annex VII puts in the technical documentation
Article 31(1) points at Annex VII. Annex VII is the content list for the technical documentation, as applicable to the relevant product with digital elements. This page does not fill Annex VII for YOU. Last verified 9 September 2026 against Annex VII on EUR-Lex. Not legal advice.
| Annex VII point | What the cited text says | Kind of text |
|---|---|---|
| 1 — general description | Intended purpose; versions of software affecting compliance with essential cybersecurity requirements; for hardware, photographs or illustrations showing external features, marking and internal layout; user information and instructions as set out in Annex II. | Legal requirement — Annex VII point 1. |
| 2 — design, development, production, and vulnerability handling | Design and development information, including where applicable drawings, schemes, and system architecture; vulnerability-handling process specifications (SBOM, coordinated vulnerability disclosure policy, evidence of a contact address, description of technical solutions for secure distribution of updates); production and monitoring processes and their validation. | Legal requirement — Annex VII point 2. |
| 3 — cybersecurity risk assessment | An assessment of the cybersecurity risks against which the product is designed, developed, produced, delivered and maintained pursuant to Article 13, including how the essential cybersecurity requirements set out in Part I of Annex I are applicable. | Legal requirement — Annex VII point 3 and Article 13(4). |
| 4 — support-period determination | Relevant information that was taken into account to determine the support period pursuant to Article 13(8). | Legal requirement — Annex VII point 4 and Article 13(8). |
| 5 — standards, common specifications, or other solutions | A list of applied harmonised standards, common specifications, or European cybersecurity certification schemes; where those have not been applied, descriptions of the solutions adopted to meet Annex I, including other technical specifications applied. | Legal requirement — Annex VII point 5. |
| 6 — test reports | Reports of the tests carried out to verify the conformity of the product with digital elements and of the vulnerability handling processes with the applicable essential cybersecurity requirements in Parts I and II of Annex I. | Legal requirement — Annex VII point 6. |
| 7 — EU declaration of conformity | A copy of the EU declaration of conformity. | Legal requirement — Annex VII point 7. |
| 8 — SBOM on reasoned request | Where applicable, the software bill of materials, further to a reasoned request from a market surveillance authority provided that it is necessary in order for that authority to be able to check compliance with Annex I. | Legal requirement — Annex VII point 8. Distinct from making an SBOM public. |
Statutory retention versus recommended practice
Do not treat a recommended copy as Article 13(13), and do not treat Article 13(13) as optional because a checklist exists. Last verified 9 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Article 13(13) keep of technical documentation and the EU declaration of conformity | Legal requirement — at least 10 years after placing on the market or the support period, whichever is longer. | Does not compute YOUR period, and does not start that keep. |
| Article 13(18) keep of Annex II information and instructions | Legal requirement — the same 10-year / support-period structure, including online availability where instructions are provided online. | Does not host YOUR Annex II file. |
| Article 13(9) security-update availability | Legal requirement — each security update issued during the support period remains available for a minimum of 10 years after it has been issued or for the remainder of the support period, whichever is longer. Availability of the update, not a quoted log-retention period. | Does not treat update availability as a record-retention duty, and does not keep YOUR updates. |
| Article 13(7) systematic documentation of cybersecurity aspects | Legal requirement — document relevant cybersecurity aspects, including vulnerabilities of which the manufacturer becomes aware. No separate 10-year period in that paragraph. | Does not invent a 10-year clock on Article 13(7). |
| Article 14 notifications | Legal requirement — to notify, if Article 14 applies. No quoted 10-year keep of copies. Keeping copies of submissions is recommended practice. | Does not invent an Article 14 archive period. |
| Articles 18(3) and 19(6) | Legal requirement — authorised-representative keep of the declaration and technical documentation; importer keep of a copy of the declaration and ability to make the technical documentation available. Same 10-year / support-period structure. | Does not classify YOUR role. |
| European Commission CRA pages and 27 July 2026 guidance | Commission materials. Guidance, not the regulation. | Does not treat a Commission page as a substitute for Article 13(13). |
| ENISA product-security materials | Agency guidance, not the regulation. | Does not treat an ENISA page as starting YOUR keep. |
What to do now
As of last verification on 9 September 2026, Article 14 applies from 11 September 2026 — two days from that verification date. Article 13 documentation duties, including the Article 13(13) keep, follow 11 December 2027 unless counsel says otherwise. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that a keep has started, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test. Marking CRA in an obligation map is not that determination.
- If counsel says Article 13 may apply, plan the 10-year / support-period keep of the technical documentation and the EU declaration of conformity. Quote Article 13(13). Do not substitute a five-year support period for that keep, and do not substitute this product for that file.
- If counsel says Article 14 may apply, open the statute-clock Article 14 guide on this site for the 24-hour / 72-hour / 14-day ladder. Keeping copies of submissions is recommended practice, not a quoted Article 14 retention period. This page does not start that clock.
- Do not treat Article 13(9) update availability as a record-retention period. Do not treat Commission or ENISA guidance as the regulation. Do not treat this product's evidence rows as YOUR Annex VII pack. Readiness in this product is not CE marking.
- The readiness-checklist guide on this site is the end-to-end CRA readiness page. A dedicated vulnerability-management, security-updates, and final-report guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a filing, and not YOUR keep. Walk it with counsel. The CRA overview on this site is the pillar page. The statute-clock Article 14 guide on this site is the ladder.
- Does the CRA apply? Product with digital elements made available on the Union market — Articles 2 and 3. This page does not run that test.
- Article 13(13): technical documentation and EU declaration of conformity at the disposal of market surveillance authorities for at least 10 years after placing on the market or the support period, whichever is longer.
- Article 31 and Annex VII: what goes in that technical documentation. This page does not fill Annex VII for YOU.
- Article 13(9) is update availability. Article 13(7) is systematic documentation without a second 10-year clock. Article 14 does not quote a 10-year keep of reports.
- Full application of Article 13 documentation duties: 11 December 2027 (Article 71(2)). Article 14 reporting: 11 September 2026. Those dates are not one number.
- Readiness in this product is not CE marking. This product does not retain YOUR CRA technical documentation pack automatically. Document the assessment, including a not-in-scope decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The signed-in app does not decide that the CRA applies, does not decide that you are a manufacturer, does not retain YOUR CRA technical documentation pack automatically, does not draw up YOUR EU declaration of conformity, does not start an Article 14 clock, and does not file with a CSIRT or ENISA. Readiness is not CE marking. None of the surfaces below is a 10-year market-surveillance file.
If you already have a session: signed-in app → Compliance holds evidence collection (control-mapped artifacts) and a human evidence review overlay (accept can render a manual row as met; reject as gap). That met-verdict overlay is a compliance artifact for SOC 2 / ISO 27001-style programs — a timestamped evidence record for controls. It is not Annex VII technical documentation, not an EU declaration of conformity, and not a 10-year keep under Article 13(13). SBOM and vulnerability records exist: CycloneDX generation, blast-radius queries, and connector-ingested vulnerability findings. Those records are retained evidence in this product. They are not YOUR CRA SBOM kept at the disposal of market surveillance authorities for 10 years, and they are not a substitute for Annex VII point 2(b). signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organisation has classified as CRA-in-scope. That tracker does not start an Article 14 clock, does not file, and is not a 10-year reporting archive. A named human still submits.
The bundled framework key cra is customer-visible. Its version label is Regulation (EU) 2024/2847 (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not full conformity-assessment detail. The obligation map lists frameworks the organisation has marked in-scope, including cra if that mark is set. That mark is not a determination that the CRA applies and not a determination that you are a manufacturer. The cyber risk register lives under Security. None of those surfaces is CE marking.
This page does not document a public demo URL. There is no public CRA demo path.
Primary sources (last verified 9 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 13, 14, 18, 19, 28, 31, 32 and 71, Annex VII and Annex VIII, is a legal requirement only if it applies. Article 13(13) is the keep of technical documentation and the EU declaration of conformity for at least 10 years after placing on the market or the support period, whichever is longer. Article 14 reporting applies from 11 September 2026; the rest, including Article 13 documentation duties, from 11 December 2027 (Article 71(2)). The European Commission's CRA policy page and CRA summary page are Commission materials, not the regulation. ENISA's product-security pages are agency guidance, not the regulation. These are not a complete world list. Not legal advice.
The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The CRA-cluster Article 14 overview on this site is how Article 14 sits in the cluster. The statute-clock Article 14 guide on this site is the live ladder under breach reporting. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. The vulnerability-disclosure guide on this site is the coordinated-disclosure page. The readiness-checklist guide on this site is the end-to-end CRA readiness page. A dedicated vulnerability-management, security-updates, and final-report guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is an evidence-retention checklist distilled from Regulation (EU) 2024/2847 Articles 13, 14, 18, 19, 28, 31 and 32, Annex VII and Annex VIII, with Commission and ENISA materials labelled as guidance, not the regulation. Whether the CRA applies, what YOUR support period is, and how long YOUR file is kept are legal questions for counsel on your facts. This page does not start a clock.
Does ShipReady keep the CRA technical documentation for 10 years?
No. This product does not retain YOUR CRA technical documentation pack automatically, does not draw up YOUR EU declaration of conformity, and does not keep those files at the disposal of market surveillance authorities. Compliance evidence collection and the met-verdict overlay record control-mapped artifacts for a starter subset. SBOM and vulnerability records exist as product evidence; they are not an Annex VII pack and not a 10-year Article 13(13) keep. A named human still holds the manufacturer file.
Is readiness CE marking?
No. Readiness in this product is not CE marking, not an EU declaration of conformity, and not a market-surveillance determination. Article 13(12) is where manufacturers draw up the EU declaration of conformity in accordance with Article 28 and affix the CE marking in accordance with Article 30 — after the chosen Article 32 procedure has demonstrated conformity. Marking cra in-scope on the obligation map is not that step.
Does Article 14 require keeping reports for 10 years?
No quoted 10-year keep. Article 14 sets the 24-hour, 72-hour, and final-report duties. It does not state a 10-year retention of copies. The 10-year / support-period keep in Article 13(13) is for the technical documentation and the EU declaration of conformity. Keeping copies of Article 14 submissions is recommended practice, not a quoted Article 14 period. This page does not invent one.
Is the keep always 10 years after placing on the market?
No. Article 13(13) is at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. A five-year support period under Article 13(8) does not shorten that keep to five years. A support period longer than ten years lengthens it. This page does not compute YOUR period. Last verified 9 September 2026. Not legal advice.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.