Technical File retention requirements per EU directive
Selected documentation-retention and availability duties under CRA, MDR, RED and machinery legislation, with product-specific evidence and source references.
By CenitiaUpdated
Do not use one ten-year timer for every dossier. Define the legal trigger, covered models/devices, support period and implantability before setting the schedule. Product-law retention does not justify permanent retention of every unrelated personal-data record.
Manufacturer duties, lifetime and retention
Document cybersecurity risk assessment and technical evidence; do not infer conformity from an AI draft. Article 13(8): determine support with expected use and reasonable user expectations; normally at least five years, or shorter where expected use is shorter. Consider longer expected use. Article 13(13): retain technical documentation and DoC for ten years after placing on the market or the support period, whichever is longer. Annex VII specifies technical-documentation content.
Manufacturer and retention
Article 10(8): retain technical documentation, DoC and relevant certificates for at least ten years after the last device covered by the declaration is placed on the market; at least fifteen years for implantables. Benefit–risk and risk controls must satisfy Annex I; a low numerical RPN does not establish acceptable serious harm.
CE and notified-body number
Article 20(3) requires the NB identification number following CE when the Annex IV full-quality-assurance procedure is used. NB participation in type examination does not alone trigger that CE-adjacent number. Manufacturer documentation retention is Article 10(4); authorised-representative retention is Article 11(2)(a).
Documentation and instructions
Manufacturer obligations include technical documentation under Annex IV and applicable retention. Digital instructions must meet Article 10(7) access/download/retention conditions; free paper instructions are available on request at purchase within one month. Essential safety information for non-professional users must be supplied on paper. Do not replace these conditions with a simple online-only policy.
Evidence to keep with the product
Record the intended purpose, responsible economic operator, target market, first placing date and exact hardware/firmware configuration. For each applicable requirement, link the actual test or assessment record, dated standard/specification, scope and reviewer decision. Proposed controls and supplier marketing statements are not evidence that the final configuration has passed an assessment.
Separate an open question from a completed assessment. A report outside the laboratory's relevant scope, a different firmware build or an unverified exemption needs a reasoned decision before it supports a declaration. Keep original evidence and the issued declaration alongside any AI-assisted working draft.
Using Cenitia for this work
Cenitia assists with a limited regulatory catalogue and draft documents. The manufacturer must confirm applicability, actual applied specifications and completed assessment procedures. AI scores are quality signals, not a probability of conformity. Source monitoring raises a review prompt when validated source text changes; it does not automatically verify amendments, update the corpus or monitor every national rule and OJ standard edition. Public QR verification records issuance, not product certification.
Review status
This guide was substantively corrected by Cenitia on 2 October 2026 using the primary references below. It is an editorial summary, not an authoritative legal quotation or an independently signed expert opinion. Product-specific and licensed-standard questions remain subject to a real technical review.
Primary references
FAQ
Frequently asked questions
Does an AI draft or QR verification prove conformity?
No. The manufacturer must establish scope and satisfy applicable requirements using actual evidence. QR verification records issuance, not product certification.
What information must be checked for this product?
Confirm intended use, role, market/date, final configuration, dated specifications, assessment route and evidence scope. Record unresolved questions and a real reviewer decision.
Continue reading
Related guides
guide
Risk assessment for CE compliance — methodology overview and standards reference
How to document product-specific safety and cybersecurity risks, choose methods within their verified scope, and connect risk controls to conformity evidence.
6 min read
tutorial
Technical File for IoT devices — concrete template aligned with CRA and RED
An illustrative eight-part evidence folder for connected IoT products, with separate checks against applicable RED documentation and future CRA Annex VII duties.
10 min read
guide
Technical File 101 — documentation scope and evidence overview
A concise overview of technical documentation, selected CRA, RED and machinery duties, retention and the product evidence needed to support conformity.
3 min read
tutorial
Coordinated Vulnerability Disclosure Policy for Hardware Manufacturers
Build a usable hardware vulnerability disclosure policy with intake owners, safe testing boundaries and a security.txt example.
4 min read
Put this into practice
Free tools & references
- EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
- CRA Readiness CheckerScore your product against the Cyber Resilience Act essential requirements.Open tool →
New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.