On this page
- Annex VII structures the file: description, risk analysis, design, testing, lifecycle.
- Every claim should resolve to a controlled artifact: revision, build, report, or approval.
- Keep a current technical file with traceable evidence for released versions and preserve historical records.
- Drafts stay drafts until the responsible person approves them.
What Annex VII asks for
Article 31 and Annex VII set the technical-documentation requirements. The file is prepared before placing the product on the market and updated where appropriate during support. The list below is a practical grouping, not a substitute for the complete annex:
Evidence beats prose
A file that asserts is weaker than a file that points. Each statement gains weight when it resolves to something controlled: a commit, a lockfile, a signed build, a test run, a recorded approval. That is what traceability means in practice - not decoration, but the ability to open the claim and find the artifact.
Immutability matters too. Snapshots taken at release time protect the file from drift: when someone asks what version 2.8.0 proved, the answer should not depend on what changed afterwards.
Keep an index with a requirement locator, product version, artifact identifier, date, owner and review state. The release-evidence checklist gives a worked handoff. Under Article 13(13), retain the technical documentation and declaration for at least ten years after placing on the market or for the support period, whichever is longer.
Inspect the recorded relationships
ConformOps provides a release lineage view for Full Assessment, with older run navigation under retained Continuous history access. Select a release, run or artifact and follow recorded links between source snapshots, evidence, components, vulnerability observations, requirements, gaps and original approval decisions. Invalidated runs, superseded decisions and missing links remain visible. The lineage download excludes source contents, paths and decision rationale; it is an index of recorded relationships, not a declaration of compliance.
Keep it alive across releases
The file describes a moving product. Ship a release and the dependency tree shifts, the tests move, the approvals age. Maintaining the annex incrementally - updating only what the change touched - is cheaper and more truthful than an annual rewrite, and it keeps the file usable for the reporting clocks that assume current information.
Frequently asked questions
Is Annex VII the same as the declaration of conformity?
No. The EU declaration is the separate Annex V instrument. Annex VII is the technical file underneath it - and authorities can request the file even when nothing is sold yet.
Can one file cover several products or versions?
Shared controls can serve several products, but the release-specific facts - versions, SBOM, test results, approvals - must remain traceable to each product. A common core with per-release deltas is the usual shape.