Annex VII technical documentation — gap report
SAMPLE — not generated from recorded state
Atlas Gateway 4.2 — sample
Economic operator
Manufacturer
Product class
Important class I
Conformity route
Notified body
This is a sample document. It describes a product that does not exist.
It is published so you can see the shape of an Annex VII gap report before signing up. Nothing in it was recorded by anyone, it is not evidence of anything, and it must not be filed or forwarded as though it were.
A gap here means “not recorded in this service”. It does not mean the requirement is unmet.
Slots marked not recorded may well be satisfied by material held elsewhere. Read this document as an inventory of what this service holds, not as an assessment of the product.
3 mandatory section(s) still open.
Annex VII(1) General description of the product
intended purpose; versions of software affecting compliance with the essential requirements; for hardware, photographs or illustrations showing external features, marking and internal layout; user information and instructions (Annex II)
RECORDED
3 record(s)
Annex VII(2) Design, development, production and vulnerability handling processes
design and development information, including system architecture and how components integrate; vulnerability handling process specifications, including the SBOM, the coordinated vulnerability disclosure policy, the reporting contact address, and how security updates are securely distributed; production and monitoring processes, and their validation
RECORDED
5 record(s)
Annex VII(3) Cybersecurity risk assessment
the Article 13 risk assessment; how each Annex I Part I requirement applies to this product; how each applicable requirement is implemented
RECORDED
2 record(s)
Annex VII(4) Support period determination
information taken into account in determining the support period (Article 13(8))
Nothing attached. Use attach_evidence(subject_ref='technical_file:tf.4', ...).
NOT RECORDED
Mandatory
Annex VII(5) Standards and specifications applied
harmonised standards applied in full or in part; other technical specifications or common specifications applied; where standards were not applied, a description of the solutions adopted to meet the essential requirements
Nothing attached. Use attach_evidence(subject_ref='technical_file:tf.5', ...).
NOT RECORDED
Mandatory
Annex VII(6) Test reports
reports of the tests carried out to verify conformity of the product; reports of the tests carried out on the vulnerability handling processes
Nothing attached. Use attach_evidence(subject_ref='technical_file:tf.6', ...).
NOT RECORDED
Mandatory
Annex VII(7) EU Declaration of Conformity
a copy of the EU declaration of conformity
Filled last, by design: freeze the file, draw up the declaration against it, then re-freeze so this section contains a copy.
FILLED LAST
By design
Annex VII(8) Software bill of materials
the SBOM, where requested by a market surveillance authority
Nothing attached. Use attach_evidence(subject_ref='technical_file:tf.8', ...).
NOT RECORDED
Optional