Exporting a compliance dossier
Sooner or later someone asks for the evidence: a notified body, an enterprise customer's security questionnaire, or your own auditor. What they want is not the tool — it is a set of documents that stand on their own.
What a dossier usually has to contain
The CRA's Annex VII sets the expectation for technical documentation. In practice a reviewer is looking for five things:
| What it answers | |
|---|---|
| Product description & intended use | What is this, who uses it, in what environment |
| Risk assessment | What could go wrong, how it was scored, what was decided — including accepted risks |
| Requirement coverage | Which essential requirements apply, where each is met, and why any is not applicable |
| Verification evidence | That the measures were tested, not just designed |
| Vulnerability handling & support period | How you will keep it secure after release, and for how long |
The gap most often found is the third one: requirements marked as covered, with nothing behind them naming an activity, an owner and a record.
Getting it out of TRA Studio
Reports are produced per project. From a project you can export:
- The report — a formatted document covering the system model, threats and mitigations, the risk picture and the sign-off state. Rendered in the browser, so you print it to PDF with your own header and logo.
- JSON — the complete structured project, for archiving or for feeding another system.
- CSV — tabular data where someone downstream wants to filter and pivot.
Your organisation's report identity — name, logo, colours — is set once under organisation settings and applies to everything you produce.
Making the export worth sending
Freeze a version before you export. A dossier is a statement about a specific product version at a specific date. Export from a signed-off version, not from a project someone is still editing.
Close the gaps first, or explain them. Unassigned requirements are visible in the tool by design. Exporting with them open is fine if each carries a justification; exporting with them silently blank is the thing that comes back as a finding.
Export the surrounding documents too. The report covers the analysis. The process documents around it — vulnerability handling, support period, secure development — live in your own quality system. If you want to see what those look like when done properly, the example document set is a complete worked family.
Guidance based on the CRA text. A starting point for your own work, not legal advice, and not a substitute for a conformity assessment.
