CE marking and technical documentation: the internal process
The content of the file is described in Technical documentation; the affixing rules in CE marking. This page covers the internal process: who does what, in which tool, with which approval.
The principle: a gate, not a formality
The technical documentation is not a document Legal writes at the end from whatever engineering chooses to send. It is an assembly of items produced continuously, whose absence blocks placing on the market.
Hence a single control point, the market gate, passed on presentation of evidence, not on a statement of intent.
Split of roles
| File item | Producer | Reviewer | Approver |
|---|---|---|---|
| General description, versions | Product management | Legal | Legal |
| Architecture diagrams | Engineering | CISO | CISO |
| SBOM | CI chain | CISO | CISO |
| CVD policy and evidence of publication | PSIRT | Legal | Legal |
| Evidence the contact point works | PSIRT | Legal | Legal |
| Update distribution process | Engineering | CISO | CISO |
| Risk assessment | CISO | Legal | CISO |
| Support period and justification | Product management | Legal | Executive management |
| Standards applied and deviations | CISO | Legal | CISO |
| Test reports | Quality and CISO | CISO | CISO |
| EU declaration of conformity | Legal | Executive management | Authorised signatory |
| Notified body attestations | Legal | — | Legal |
The support period escalates to executive management because it commits the company financially for five to ten years: it is not a technical decision.
The workflow
- Open the file when the decision to develop is taken, not on the eve of launch. The file is a living space, fed throughout the project.
- Completeness milestones at key project stages: design, end of development, pre-launch. At each milestone, a statement of missing items.
- Conformity review before placing on the market, in session, with those responsible for each item.
- Signed record, which authorises affixing the marking.
- Freeze and archive the version of the file corresponding to the version placed on the market.
- Reopen on substantial modification.
The conformity review record
One page, structured as:
- identification of the product and the exact version placed on the market;
- criticality class and assessment route chosen, with a pointer to the classification sheet;
- status of the fifteen points of the checklist, ticked item by item;
- any reservations, with deadline and owner;
- decision: authorisation to affix the marking, or reasoned refusal;
- date, participants, signatures.
This document is the trace of the company’s diligence. In an inspection it demonstrates that conformity was verified before placing on the market, not reconstructed afterwards.
The tool
The technical documentation must live in a system that guarantees:
- traceability of versions and approvals;
- immutability of frozen states;
- retrieval of a past state, ten years later;
- linking to technical artefacts — SBOM, test reports — rather than copying them.
A shared folder without versioning satisfies none of those four criteria.