Technical documentation and signing
This screen prepares two documents — the technical documentation file and the EU declaration of conformity — and keeps the proof of who signed them and when. It does not establish whether the product complies with the Regulation: no screen in CRAnotify does, because that assessment belongs to the economic operator. Signing is the most demanding gesture the product offers, and it asks for more than a click: your identity is proved again at the moment you sign.
Where it lives
From Products, the Technical documentation button in the toolbar: it opens the index, one row per managed product and three states per row — file, conformity path, declaration. From there you open a product's page. The screen has no navigation entry of its own: it lives under Products.
The index shows no total, no percentage and no summary score. Every number you see — how many fields are missing, how much evidence there is — can be recounted by hand by opening the row. A single number summarising "how it is going" would be read as a conformity judgement, whatever label you put next to it.
The file is assembled, not concluded
The file is pre-filled from the data the system already holds, and every field carries where it comes from and when it is from. The "source" column is not decorative: whoever reviews the document must be able to trace the source without asking the person who filled it in.
| Field | Source |
|---|---|
| Product name, internal identifier, category, version | Product register |
| Manufacturer: legal name, registered office, country, regulatory contact | The primary legal entity |
| Economic operator role | Confirmed roles on that product |
| Support period (end), release date | The product's lifecycle |
| Evidence: bill of materials, process, coordinated disclosure, document | The most recent item of each type (see CRA controls and evidence) |
| Approved VEX statements | Only approved ones: a draft is an opinion in progress (see VEX assessments) |
Missing data is never invented. The field stays empty and says "information required". A file with a declared hole gets completed; one with a hole filled by a plausible value gets found in an inspection, and at that point the data is no longer the problem.
The conformity path says where you have got to
The second panel records the steps of your assessment work. These are the steps, and they are states of the collection, not outcomes:
To record a step, choose the state and write what it rests on. For "decision recorded" the field is mandatory, and the check is on the server: a decision recorded without the evidence it rests on cannot be defended before anyone.
What none of these steps means. None of them says the product complies with the Regulation, and there is no step that would: "compliant", "certified" and "approved for the market" are not states here, and they will not become states. Whoever places the product on the market carries that.
Signing asks for your identity again
Signing means a person states that this document is the document. That is why the gesture does not start from a session left open on a laptop in a meeting room: at signing time the form asks for
- your password, always;
- your second-factor code if your account has two-step verification enabled. If you have not enabled it, the field does not appear — which is the best reason to enable it: see Account security.
Re-authentication is not a courtesy of the interface: it is a condition of the model. The functions that apply the signature refuse to run without the proof of identity, so no path — an API, an import, a future button — can skip it.
The right role is required too: signing goes through the same check as filing, and is reserved to the Administrator and Approver roles. An Assessor sees the file and records the steps of the path, but does not sign: see Users, roles and escalation.
The document that gets signed is reassembled by the system at that moment: nothing the browser sends back enters it. You sign what the system knows now, not what was on screen ten minutes earlier.
What each of the two signatures requires
| Condition | Technical file | EU declaration |
|---|---|---|
| No missing field | Yes | Yes |
| Re-authentication (password, plus the code when enabled) | Yes | Yes |
| A decision recorded in the conformity path | — | Yes |
| Explicit confirmation tick | — | Yes |
When a condition is not met the button is disabled and the page says why: it lists the missing fields by name, or reports that a recorded decision is what is missing. A button that disappears without explaining itself leaves the reader guessing, and whoever guesses concludes the software is broken.
The declaration's tick says: "I am signing this declaration on behalf of the economic operator, and I take responsibility for it." It is explicit because a signature given by mistake cannot be withdrawn.
If the signature does not go through
| Message | What happened |
|---|---|
| "The password does not match" | Nothing was signed and nothing changed. The attempt does leave a row in the registry, with whoever made it. |
| "The second-factor code is not valid" | As above. Read the code from the authenticator app at the moment you submit. |
| "Too many signing attempts" | The brake on rapid attempts has kicked in. Try again later. |
| "The document still has fields to fill in" | Complete the listed fields and try again: a signature on a file with a hole is a signature on a blank. |
| "The conformity path has not recorded a decision yet" | Record the "decision recorded" step, with what it rests on, before signing the declaration. |
| "The explicit confirmation is required" | The declaration's tick was not ticked. |
| "The session carries no identity" | Sign in again and retry: a gesture without an identity is not performed. |
What remains after signing
Signing rewrites nothing: it adds a version, with its author and its moment. The previous version stays in the document's history, and the state becomes "Signed". The gesture leaves a row in the activity registry and becomes dossier material: before an authority the question is not only "do you have the documentation", but "who approved it, when, and on what".
The printable version
The Printable version link opens the document laid out for print; the PDF is produced by the browser's print dialog, as for the defence dossier. A draft can be printed, and it declares that it is a draft: a printed document that does not say its own state is the one that ends up in the wrong file.