技术文件

CRA technical documentation 是产品和 manufacturer 网络安全流程的证据文件。它必须说明产品如何满足 Annex I,以及 manufacturer 如何处理漏洞。

文件义务

The technical documentation shall contain all relevant data or details of the means used by the manufacturer to ensure that the product with digital elements and the processes put in place by the manufacturer comply with the essential cybersecurity requirements set out in Annex I. It shall at least contain the elements set out in Annex VII.

Regulation (EU) 2024/2847, Article 31(1)

Article 31 范围很宽。文件必须说明 manufacturer 用什么方式使产品及其流程符合 Annex I。它不只是设计文件、测试报告或用户手册。

证据点

Annex I Part I 的产品网络安全属性,以及 Annex I Part II 的 vulnerability-handling 流程。

时间和更新

The technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be continuously updated, where appropriate, at least during the support period.

Regulation (EU) 2024/2847, Article 31(2)

Technical documentation 必须在产品 placing on the market 之前形成。之后在 support period 内,相关变化重要时也必须保持更新。

  • 产品设计、架构、软件版本或更新方法变化可能要求更新。
  • Cybersecurity risk assessment 变化可能要求更新。
  • 新的漏洞信息可能要求更新。
  • 经过重新设计或重新评估的产品,应有能识别变更版本的文件。

Annex VII 内容

Annex VII 是最低内容清单。它更适合作为证据类别来读,而不是表格模板。具体细节取决于相关产品。

风险评估

Article 13(4) 将 cybersecurity risk assessment 放入 technical documentation。风险评估说明 Annex I 如何适用于产品,包括在 manufacturer 得出不相关结论时,为什么某项产品属性要求不相关。

Commission FAQ 说明,无论产品在欧盟内外制造,产品 placed on the market 时文件都必须可用。FAQ 还说明,后续重新设计和重新评估应反映在 technical documentation 中。

符合性和主管机关使用

Technical documentation 主要用于 conformity assessment 和 market surveillance。Commission FAQ 说明,它通常不需要向客户或公众提供。

FAQ 描述的主要公开例外,是某些使用 Article 32(5) self-assessment 路径的重要 free and open-source software products。

保持足以评估的清晰度

Market surveillance authority 可以要求提供证明符合性所需的信息。缺失或不清楚的文件本身可能成为正式合规问题。

Sources