TRA Studio
All resources

Exporting a compliance dossier

Sooner or later someone asks for the evidence: a notified body, an enterprise customer's security questionnaire, or your own auditor. What they want is not the tool — it is a set of documents that stand on their own.


What a dossier usually has to contain

The CRA's Annex VII sets the expectation for technical documentation. In practice a reviewer is looking for five things:

What it answers
Product description & intended useWhat is this, who uses it, in what environment
Risk assessmentWhat could go wrong, how it was scored, what was decided — including accepted risks
Requirement coverageWhich essential requirements apply, where each is met, and why any is not applicable
Verification evidenceThat the measures were tested, not just designed
Vulnerability handling & support periodHow you will keep it secure after release, and for how long

The gap most often found is the third one: requirements marked as covered, with nothing behind them naming an activity, an owner and a record.


Getting it out of TRA Studio

Reports are produced per project. From a project you can export:

  • The report — a formatted document covering the system model, threats and mitigations, the risk picture and the sign-off state. Rendered in the browser, so you print it to PDF with your own header and logo.
  • JSON — the complete structured project, for archiving or for feeding another system.
  • CSV — tabular data where someone downstream wants to filter and pivot.

Your organisation's report identity — name, logo, colours — is set once under organisation settings and applies to everything you produce.


Making the export worth sending

Freeze a version before you export. A dossier is a statement about a specific product version at a specific date. Export from a signed-off version, not from a project someone is still editing.

Close the gaps first, or explain them. Unassigned requirements are visible in the tool by design. Exporting with them open is fine if each carries a justification; exporting with them silently blank is the thing that comes back as a finding.

Export the surrounding documents too. The report covers the analysis. The process documents around it — vulnerability handling, support period, secure development — live in your own quality system. If you want to see what those look like when done properly, the example document set is a complete worked family.


Guidance based on the CRA text. A starting point for your own work, not legal advice, and not a substitute for a conformity assessment.