What is a technical file?
A technical file is the evidence that your product meets EU law — kept by you, not filed with anyone. You draw it up before placing the product on the market, you keep it for ten years, and you produce it if a market surveillance authority asks. It is the difference between claiming conformity and being able to demonstrate it.
The pattern, across every regulation
EU product legislation has used the same architecture since the New Approach of the 1980s, and once you see it, every regulation becomes readable:
- Essential requirements — outcomes the product must achieve, written in an annex, deliberately technology-neutral.
- Harmonised standards — voluntary technical specifications that, when applied, give a presumption of conformity with those requirements.
- Conformity assessment — the procedure by which you establish the product complies. Self-assessment for most products; a notified body for higher-risk categories.
- Technical documentation — the evidence trail, kept by you.
- Declaration of conformity — your signed statement.
- CE marking — the visible claim.
The names change between regulations. The structure does not.
What goes in one
The specific contents come from the annex of the regulation that applies to you. But the shape is consistent:
| Section | Purpose |
|---|---|
| Product description | What the product is, its intended use, its versions or models, and its foreseeable misuse. |
| Design and construction | Drawings, architecture, schematics, and the explanations needed to understand them. |
| Risk assessment | The hazards or threats identified, the risks evaluated, and the measures adopted. |
| Requirement-to-evidence index | Each applicable essential requirement mapped to the evidence that satisfies it. The single most useful page in any file. |
| Standards applied | Dated references, and which requirements each standard covers. |
| Test reports | What you tested, how, what you found, what you did about it. |
| Production controls | How you ensure the units you actually ship match the one you assessed. |
| Instructions | A copy, as supplied to the user. |
| Declaration of conformity | A copy of the signed declaration. |
By regulation
Cyber Resilience Act
Annex VII. Eight sections covering design, vulnerability handling, the SBOM and the risk assessment. Applies in full from 11 December 2027.
Read →Machinery Regulation
Annex IV, Parts A and B. Drawings, calculations, risk assessment and instructions. Applies from 20 January 2027.
Read →CE marking
What the mark means, where it goes, how big it has to be, and who may affix it.
Read →Authorised representative
What manufacturers outside the EU need, what the mandate must cover, and what the representative is actually liable for.
Read →How long you keep it
Ten years after the product is placed on the market, as a general rule. Under the Cyber Resilience Act, ten years or the support period, whichever is longer — which for a product with a long support commitment means longer than ten. For series production, the clock runs from the last unit placed on the market.
Practical advice that applies to every regulation
- Build the index first. Start with the list of applicable essential requirements and fill in evidence against it. A file assembled the other way round — documents first, mapping later — always has gaps, and the gaps are invisible until someone reads it adversarially.
- Record the "not applicable" decisions. Requirements you judged inapplicable need a one-line reason. This is the cheapest insurance in compliance.
- Write it during development. The evidence is generated as a by-product of doing the engineering properly. Captured then, it is nearly free; reconstructed later, it is expensive and worse.
- Assume an adversarial reader. Not because authorities are hostile, but because that is the standard that produces a file which holds up.
- Keep it retrievable by someone other than its author. Ten years is longer than most people stay in a job.
Get told when the requirements change
None of the 35 CRA harmonised standards is published yet. When they land — and when deadlines move — we email you. No more than twice a month.