CRAnotify Documentation

Technical documentation and signing

This screen prepares two documents — the technical documentation file and the EU declaration of conformity — and keeps the proof of who signed them and when. It does not establish whether the product complies with the Regulation: no screen in CRAnotify does, because that assessment belongs to the economic operator. Signing is the most demanding gesture the product offers, and it asks for more than a click: your identity is proved again at the moment you sign.

Where it lives

From Products, the Technical documentation button in the toolbar: it opens the index, one row per managed product and three states per row — file, conformity path, declaration. From there you open a product's page. The screen has no navigation entry of its own: it lives under Products.

The index shows no total, no percentage and no summary score. Every number you see — how many fields are missing, how much evidence there is — can be recounted by hand by opening the row. A single number summarising "how it is going" would be read as a conformity judgement, whatever label you put next to it.

The file is assembled, not concluded

The file is pre-filled from the data the system already holds, and every field carries where it comes from and when it is from. The "source" column is not decorative: whoever reviews the document must be able to trace the source without asking the person who filled it in.

FieldSource
Product name, internal identifier, category, versionProduct register
Manufacturer: legal name, registered office, country, regulatory contactThe primary legal entity
Economic operator roleConfirmed roles on that product
Support period (end), release dateThe product's lifecycle
Evidence: bill of materials, process, coordinated disclosure, documentThe most recent item of each type (see CRA controls and evidence)
Approved VEX statementsOnly approved ones: a draft is an opinion in progress (see VEX assessments)

Missing data is never invented. The field stays empty and says "information required". A file with a declared hole gets completed; one with a hole filled by a plausible value gets found in an inspection, and at that point the data is no longer the problem.

The conformity path says where you have got to

The second panel records the steps of your assessment work. These are the steps, and they are states of the collection, not outcomes:

Not startedThe starting point. Not a destination, and it cannot be recorded.
Evidence collectionYou are gathering the material.
Assessment in progressThe assessment is open.
Waiting for human reviewSomeone has to look before you go further.
Documentation readyThe file is complete as you understand it.
Decision recordedA person decided. The system records that, not that the decision was right.

To record a step, choose the state and write what it rests on. For "decision recorded" the field is mandatory, and the check is on the server: a decision recorded without the evidence it rests on cannot be defended before anyone.

What none of these steps means. None of them says the product complies with the Regulation, and there is no step that would: "compliant", "certified" and "approved for the market" are not states here, and they will not become states. Whoever places the product on the market carries that.

Signing asks for your identity again

Signing means a person states that this document is the document. That is why the gesture does not start from a session left open on a laptop in a meeting room: at signing time the form asks for

  1. your password, always;
  2. your second-factor code if your account has two-step verification enabled. If you have not enabled it, the field does not appear — which is the best reason to enable it: see Account security.

Re-authentication is not a courtesy of the interface: it is a condition of the model. The functions that apply the signature refuse to run without the proof of identity, so no path — an API, an import, a future button — can skip it.

The right role is required too: signing goes through the same check as filing, and is reserved to the Administrator and Approver roles. An Assessor sees the file and records the steps of the path, but does not sign: see Users, roles and escalation.

The document that gets signed is reassembled by the system at that moment: nothing the browser sends back enters it. You sign what the system knows now, not what was on screen ten minutes earlier.

What each of the two signatures requires

ConditionTechnical fileEU declaration
No missing fieldYesYes
Re-authentication (password, plus the code when enabled)YesYes
A decision recorded in the conformity path—Yes
Explicit confirmation tick—Yes

When a condition is not met the button is disabled and the page says why: it lists the missing fields by name, or reports that a recorded decision is what is missing. A button that disappears without explaining itself leaves the reader guessing, and whoever guesses concludes the software is broken.

The declaration's tick says: "I am signing this declaration on behalf of the economic operator, and I take responsibility for it." It is explicit because a signature given by mistake cannot be withdrawn.

If the signature does not go through

MessageWhat happened
"The password does not match"Nothing was signed and nothing changed. The attempt does leave a row in the registry, with whoever made it.
"The second-factor code is not valid"As above. Read the code from the authenticator app at the moment you submit.
"Too many signing attempts"The brake on rapid attempts has kicked in. Try again later.
"The document still has fields to fill in"Complete the listed fields and try again: a signature on a file with a hole is a signature on a blank.
"The conformity path has not recorded a decision yet"Record the "decision recorded" step, with what it rests on, before signing the declaration.
"The explicit confirmation is required"The declaration's tick was not ticked.
"The session carries no identity"Sign in again and retry: a gesture without an identity is not performed.

What remains after signing

Signing rewrites nothing: it adds a version, with its author and its moment. The previous version stays in the document's history, and the state becomes "Signed". The gesture leaves a row in the activity registry and becomes dossier material: before an authority the question is not only "do you have the documentation", but "who approved it, when, and on what".

The printable version

The Printable version link opens the document laid out for print; the PDF is produced by the browser's print dialog, as for the defence dossier. A draft can be printed, and it declares that it is a draft: a printed document that does not say its own state is the one that ends up in the wrong file.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu