<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">
CRA Technical File Custody

Meet the CRA’s decade-long custody demand.

Every product with digital elements you place on the EU market needs an Annex VII technical file, kept available to market surveillance authorities for at least ten years. Codekeeper’s Technical File Custody holds versioned files in an independent, encrypted vault.

Held independently — retained for the full ten years.
Your CE marking hinges on your technical file and EU declaration of conformity staying complete and accurate for as long as you support the product. Codekeeper holds both in an immutable vault and syncs updates to keep it current for the full retention period.
badge-cra CRA
solutions-eu-ai-act-2 EU AI Act
badge-iso-27001-v2 ISO 27001
solutions_badge_hipaa HIPAA
solutions-ffiec FFIEC
One custody deposit for the documentation retention requirements your industry’s frameworks place on you.
The old way

CRA retention demands outlast your storage tools.

Most manufacturers assemble the technical file like any engineering document — in a wiki, object store, or a compliance platform. That works at launch, but the obligation runs a decade longer. Across that decade, platforms retire, migrations drop version history, ransomware compromises drives, and files get deleted.

A technical file you cannot produce breaches your manufacturer obligations under Article 13. Fines run up to €15 million or 2.5% of worldwide annual turnover. No manufacturer can afford a migration or a breach erasing evidence they stay liable to produce.

The technical file in your own tooling
Annex VII technical file PDF
Last edited · 14 Mar 2024
Not tested
Migrated, retired, or deleted — and the version history goes with it.
cra-sbom-escrow-team-meeting-800
Why we built it

The document custody system built to last decades.

For 10+ years, Codekeeper has secured the technical documentation and design records of 3 500+ companies. Systems change, and documents scatter, corrupt, or get deleted. Our deposits, integrity checks, and version control are built to protect against those failures.
10+
years managing escrow
3 500+
companies protected
ISO 27001
certified
24 hrs
to go live

Technical File Custody features that meet your retention needs

Each capability below covers a different part of the retention duty, from keeping the file current to producing the right version years later.

Immutable document custody

Your technical file is held in an AES256/512 encrypted, immutable vault outside your own infrastructure, so ransomware, a corrupted migration, or an accidental deletion on your side leaves the deposit untouched.

Automated deposit syncing

When you update the technical file, Codekeeper pulls the new version from your connected storage and development tools, so the deposit matches the file you keep current under Article 31(2).

Version-locked deposit history

Every deposit is stored as its own dated version with a timestamped audit trail, and you set how many versions to retain. A request about a product you shipped six years ago draws the file exactly as it stood then.

Ten-year retention, managed per product

Custody runs ten years from the date each product is placed on the market, or your declared support period where that is longer — so no file leaves custody while you are still liable to produce it.

Declaration of conformity custody

Your signed EU declaration of conformity is deposited alongside the technical file version it certifies, so the two never drift apart and the pairing an authority asks for still holds years later.

Annex VII completeness verification

Verification checks each deposit against the elements Annex VII requires, so gaps are identified and corrected early instead of surfacing during an audit.

How it works

How Technical File Custody works

In review
AC
SentryGate Router Product
BL
Annex VII file In custody
AgreementTechnical file
Last deposit2 days ago
Active
NV
MeshLink Gateway Product
FB
DoC + Annex VII In custody
AgreementTechnical file
Last depositToday

1. Deposit your technical file

You hand over the technical file as it stands today, including the product description, the cybersecurity risk assessment, test reports, and your signed EU declaration of conformity.

Deposits
3 active · last verified today
Software Resilience Certificate
Software Resilience
Certificate
Passed

2. Each update logged as a dated version

Codekeeper syncs changes from your systems, stores each as a dated version, and checks it against Annex VII.

Certified tier seal
Codekeeper Software Resilience Certificate
ProductSentryGate Router
TierCertified
Annex VII checkComplete · v4.2
Retained until2037
Authorized · Codekeeper
Verified

3. Produce the technical file on demand

When a market surveillance authority or notified body asks, you retrieve the exact version they need, with its Software Resilience Certificate.

Setup is live in 24 hours, and custody starts with the technical file you have today. How your team authors and stores that file stays exactly as is.

Book a demo

These companies’ systems are protected, compliant, and resilient.

They made the decision. They built their resilience. They have peace of mind. You can too.
icon-google
icon-g2
“We’ve had a great experience with CodeKeeper. The setup process was smooth, and the team made everything very straightforward. Knowing our critical software assets are securely protected gives us real peace of mind. Their support has been responsive and professional, and the overall service has been reliable and easy to work with. Highly recommended.”
testimonial-circle-j

Jordan Adler

“We worked with Codekeeper as our escrow provider for major enterprise deployments and found them to be extremely professional, responsive, and flexible throughout.
I'd highly recommend Codekeeper. They clearly understand the realities of working with growing tech businesses and enterprise customers alike.”
testimonial-circle-r

Ross Kilshaw

I found Codekeeper's solution excellent for what I need. I scheduled a demo to better understand the possibilities. Very easy! It was a clear and straightforward meeting, focused exactly on what I needed. Excellent service!
testimonial-circle-t

Thiago Mendes

Airbus partner logo in muted style
Bayer partner logo in muted style
EU Parliament partner logo in muted style
General Motors partner logo in muted style
Intuit partner logo in muted style
Nestle partner logo in muted style
Pepsico partner logo in muted style
Pfizer partner logo in muted style
Framework mapping

One custody vault for all mandated retention files

Several frameworks make you keep documentation and produce it years later, each with its own retention period. Those periods rarely align, leaving the same records tracked against different deadlines. Custody consolidates them onto one verified version history.
badge-cra
CRA — Art. 31 & Art. 13(13) Technical documentation and declaration of conformity, retained ten years.
solutions-eu-ai-act-2
EU AI Act — Art. 11 & Art. 18 Technical documentation kept available to national competent authorities for ten years.
badge-iso-27001-v2
ISO 27001 — Annex A 5.33 Records protected from loss, destruction, and falsification, in line with retention requirements.
solutions_badge_hipaa
HIPAA — 45 CFR §164.316(b)(2)(i) Documentation retained six years, binding on business associates.
solutions-ffiec
FFIEC — BCM booklet Vital records kept current and version-controlled for retrieval.
What's at stake

Your EU market success comes down to one file

Without it

  • Product pulled from the market. Unavailable or incomplete documentation is formal non-compliance under Article 58 — the product can be restricted, recalled, or withdrawn.
  • Fines up to €10M or 2% of worldwide annual turnover for a deficient technical file or declaration of conformity.
  • A further €5M or 1% for supplying an incomplete file to a market surveillance authority.
  • Total version history loss if a platform is retired or acquired, leaving you with the compliance ramifications with no way out.
€15M or 2.5% of worldwide annual turnover — the ceiling for breaching your Article 13 manufacturer obligations

With Third-Party Component Escrow

  • The file is held outside your infrastructure — an outage, ransomware, or a migration leaves it untouched.
  • Every dated version stays retrievable — a request about a six-year-old product draws the version that shipped with it.
  • Retention runs to each product’s deadline — covering the full ten years from placement or the support period, whichever is longer.
  • Verified against Annex VII requirements — ensuring it holds what’s required and issues a Software Resilience Certificate as proof.
  • File version history stays intact — meeting the compliance obligations even if you stop trading or are acquired.
Sample

See a technical file custody report

A standalone Software Resilience Report showing each deposited version of a technical file with its timestamp, the changes recorded against it, and the Annex VII completeness check behind them.
Version timeline
Change log
Certified tier seal
Codekeeper Software Resilience Report
ProductSentryGate Router
TierCertified
Annex VII checkComplete · v4.2
Retained until2037
Versions held18 · since 2027
Integrity checksAll passed
Authorized · Codekeeper
Verified
Get the sample custody report

We’ll email the sample custody report to you.

Give your CRA technical file a permanent keeper.

Ten years is several corporate lifetimes — the engineers and compliance leads who wrote the risk assessment and shipped each version can move on at any time. Codekeeper holds the technical file independently and tracks its full version history, so you can always point to the version market surveillance authorities want to see.

Frequently asked questions

What counts as the CRA technical file?
The CRA technical file is the technical documentation set out in Annex VII. It covers the product description and intended purpose, the information and instructions for users, the design, development and vulnerability-handling processes including the software bill of materials, the cybersecurity risk assessment, the information used to set your support period, the harmonized standards applied, test reports, and a copy of your EU declaration of conformity.
How long must CRA technical documentation be kept?
CRA technical documentation must be kept for at least ten years after the product is placed on the market, or for the support period where that runs longer, under Article 13(13). The same duty covers your EU declaration of conformity. Article 31 separately requires the technical file drawn up before the product is placed on the market and kept updated across the support period.
What happens if you cannot produce your CRA technical file?
If you cannot produce your CRA technical file, Article 58 treats technical documentation that is unavailable or incomplete as formal non-compliance, and the market surveillance authority requires you to bring that non-compliance to an end. Where it continues, the Member State restricts or prohibits the product, or has the product recalled or withdrawn from the market.
Who does the CRA technical documentation duty apply to?
The CRA technical documentation duty applies to manufacturers first, and it reaches further down the supply chain. Article 18(3) requires an EU authorized representative to keep the technical documentation and EU declaration of conformity at the disposal of market surveillance authorities for ten years after the product is placed on the market, or the support period where that is longer, and Article 19 places a corresponding obligation on importers.
How is Technical File Custody different from keeping the technical file in our own compliance platform or cloud storage?
Technical File Custody is different from your own platform or cloud storage because the technical file is held by an independent third party, outside the systems that could lose it. Your own tooling can be migrated, retired, or reached by ransomware, and version history usually breaks in the move. Custody keeps each dated version intact and retrievable for the full retention period.
What happens to the technical file if we cease operations or are acquired?
A technical file held in custody stays reachable through both. Custody continues independently of your company’s status, so an acquirer or successor inherits the file with its full version history rather than a partial copy. Article 13(23) separately requires a manufacturer that stops trading to inform market surveillance authorities before the cessation takes effect, and to inform users by any means available.
Which regulations does Technical File Custody support?
Technical File Custody supports the CRA most directly, covering the Annex VII technical documentation under Article 31 and the ten-year retention duty under Article 13(13). The same deposit serves the EU AI Act’s ten-year documentation keeping under Article 18, the records protection control in ISO 27001 Annex A 5.33, the six-year documentation retention HIPAA places on business associates, and the vital records expectations in the FFIEC IT Handbook.