Technical Files

Annex IV under the AI Act, Annex VII under the CRA, Article 30 records under GDPR, the DORA register of information, the NIS2 evidence set. Compiled from one evidence base, in the shape each authority expects. BETA - expected release Q4 2026.

One evidence base, every file they ask for

Multiple regimes ask overlapping questions about the same product in many different formats. Grecta answers them once and renders the answer in each format they demand.

One set of facts, many file shapes.

Your architecture, data flows, risk controls and incident procedures are described once and compiled into whichever regime-specific structure is being demanded.

Compiled, not guessed or written.

The file is assembled from evidence already bound to obligations, so nothing in it is drafted fresh or guessed by AI at the moment you need it most.

Ready before it is asked for.

Market surveillance authorities, enterprise buyers and insurers give you days, not quarters. The file exists before the request arrives.

Answer once, render many times. The alternative is maintaining six versions of the same facts and discovering the inconsistencies when a reviewer does.

Compiled from evidence you already hold.

Grecta resolves which regimes apply to your product and which documentation obligations follow from each. It binds every obligation to the artefact that satisfies it, drawing on what you have uploaded and populating what you do not. When you need a file, it compiles the bound evidence into the structure the relevant authority expects.

Map obligations and bind evidence

Each applicable regime is resolved against your product profile, and every documentation obligation it creates is listed with the provision it comes from. Each obligation is tied to a specific artefact, with its date of production, its review status and who signed it off. Unfilled obligations stay visible as gaps.

The bound evidence renders into the required structure. Annex IV, Annex VII, an Article 30 record or a DORA register, each from the same underlying facts.

268

obligations mapped (Sept 2026)

1

consolidated evidence base

0

untraced evidence

What a compiled file carries

The structure the authority expects.

Annex IV and Annex VII have prescribed contents, and a file that covers the right material in the wrong shape still comes back. Each file renders into its own regime's required structure rather than a generic export.

Evidence that reuses across regimes.

A risk assessment written for the AI Act answers part of the CRA. A processing record answers part of DORA. Grecta binds each artefact to every obligation it satisfies, so you produce evidence once and it counts everywhere it applies.

Retention and version history.

The AI Act requires technical documentation to be kept for ten years after a system is placed on the market, and CRA and PLD retention run on their own long clocks. Every compiled version is retained and remains addressable, including after the product has left your roadmap.

Disclosure readiness.

Under Article 10(2)(a) of the revised Product Liability Directive, defectiveness is presumed where a defendant fails to disclose relevant evidence. The consequence of not being able to produce your file is no longer delay. It is losing the point.

Where the Compliance Technical Files get demanded

Connected products and industrial software

The Cyber Resilience Act requires Annex VII technical documentation and an EU declaration of conformity before CE marking, and reporting obligations under Article 14 went live on 11 September 2026. The revised Product Liability Directive applies to everything placed on the market from 9 December 2026.

Financial services

Clinical and patient-facing software carries MDR technical documentation alongside AI Act Annex IV, GDPR Article 35 assessments and CRA obligations where the product has digital elements. Hospital procurement reviews all of it before a pilot starts.

Health technology

Recruitment and candidate-ranking systems are high-risk under Annex III by default, and buyers now face their own deployer obligations under Article 26. They will ask what you hand them to satisfy those.

Essential and important entities under NIS2

Competent authorities can require evidence of the risk management measures in Article 21 and the incident handling in Article 23. Demonstrating a measure exists is a documentation problem before it is a security one.

Have the Compliance Technical Files before they ask

Compile your first technical file from evidence you already hold, in the structure the authority expects.

Join the pilot

FAQ

AI Act Annex IV technical documentation, CRA Annex VII technical documentation and the EU declaration of conformity, GDPR Article 30 records and Article 35 assessments, the DORA register of information, and the evidence set supporting NIS2 Article 21 measures. Which of these your product needs is resolved from your profile rather than chosen from a menu.

It needs review, and the file tells you which parts. Every artefact carries one of three states: uploaded by you, populated by Grecta and not yet reviewed, or populated and reviewed. Nothing is presented as signed off that a human has not signed off. Technical files nobody checked are evidence of a careless process, which is worse in front of an authority than an honest gap.

No, it gets bound. Upload what exists and Grecta maps each document to the obligations it satisfies, across every regime it satisfies them in. What is left unbound is your actual gap list, which is usually shorter and different from what people expect.

A generator writes a document from a prompt. Grecta compiles a file from evidence that is already bound to obligations, and every line traces back to the provision requiring it. The same inputs always produce the same file. That matters when a reviewer tests one statement and decides whether to trusat the rest.

The obligation map is updated centrally, and every product affected by the change is flagged with what moved and which parts of the file it touches. The previously compiled version is retained and stays addressable, because the question in a dispute is what you documented at the time, not what the rules say now.

Anyone you choose. Files export for submission to an authority, for an enterprise buyer's security review, or for an insurer. Where a buyer only needs assurance rather than the full file, the Living Compliance Passport gives them a link to the position without handing over the underlying documentation.

Stay on top of regulatory changes effortlessly

When CRA, DORA, NIS2, GDPR or AI Act documentation obligations move, we work out what changed and what it means for products like yours. One email, only when something actually happens.

Subscribe to waitlist

No digest, no roundup, no news you already saw on LinkedIn.