We do the compliance work for you
The software is for teams who want to do this themselves. This page is for everyone else — the manufacturers who need an Annex VII file in hand, not a subscription and a learning curve.
Same system, operated by us. That is why a technical file costs €2,900 here and five figures from a consultancy: the evidence gathering is automated, so you are paying for judgement rather than for someone re-typing your dependency list.
Readiness report
Where you actually stand, and what it will take to close the gap.
We run your repository through the scanner and read your product against Annex I. You get a short written report: what is blocking conformity, what it will cost to fix, and the order to do it in. If it turns out you are out of scope, the report says so and that is the end of the bill.
- Scope and Annex III classification, with the reasoning written out
- CycloneDX SBOM and a vulnerability position on your current dependencies
- Annex I gap analysis — what exists, what is missing, what is arguable
- A prioritised plan with realistic effort against each item
Technical file build
Most asked forThe full Annex VII documentation set, built and handed over.
The documentation a market surveillance authority or a notified body will ask for, produced from your real product rather than a template. You review and sign; we do the assembly. The declaration of conformity is drafted but stays unissued until you are satisfied the underlying claims are true.
- Annex VII technical documentation, complete
- Cybersecurity risk assessment (Article 13(2))
- CycloneDX and SPDX SBOM
- Coordinated vulnerability disclosure policy and hosted security.txt
- Article 14 reporting procedure with your roles and CSIRT named
- Draft EU declaration of conformity
Maintenance retainer
Because a technical file goes stale the week after you ship.
Conformity is not a document you produce once. Every dependency bump changes your vulnerability position, and Article 13(8) obliges you to keep the file current across the whole support period. We re-scan, update the file, and tell you when something needs a decision.
- Continuous dependency scanning with advisories when something lands
- Technical file and SBOM kept current as you ship
- Article 14 clocks watched, with the reporting pack ready if you need it
- A named person who already knows your product
Who this is for
Annex III Class II manufacturers
Firewalls, intrusion detection and prevention, hypervisors, container runtimes, tamper-resistant microcontrollers. You cannot self-assess — a notified body must be involved, and the documentation is the first thing they ask for.
Annex IV critical products
Hardware security modules, smartcards and secure elements, smart meter gateways. The smallest group, the highest urgency, and the least tolerance for an incomplete file.
Hardware brands shipping in 2027
IoT, electronics, machinery. An 18-month development cycle means a product launching before 11 December 2027 is having its conformity decisions made this quarter.
What we will not do
- Tell you that you are in scope when you are not. The free scope check is free precisely so this conversation starts honestly.
- Sign your declaration of conformity. That is the manufacturer’s legal act and it stays yours — we draft it, you take responsibility for it.
- Act as your notified body. Where your class requires one, we prepare what they will ask for; we are not the assessor and cannot be.
- Claim your product is secure. The file documents what you have done. It does not substitute for having done it.
Tell us about your product
Nothing is quoted from a form. Tell us what you are shipping and what deadline you are working to, and you will get a reply from a person — usually with questions before a price.
There are 451 days to 11 December 2027, but the Article 14 reporting duties have applied since 11 September 2026 and they bind products already on the market.
Prefer to do it yourself? The software is from €99 a month, or start with the free scope check.