TCF – Technical Construction File (now more commonly called Technical File, or TF) – is the core of the entire CE certification system. It's not a single report – it's a complete technical evidence chain. If this file is wrong, your DoC is built on sand – signed but worthless.
From 1 August 2025, the EN 18031 cybersecurity provisions under the RED Directive are fully mandatory. TCF writing requirements are significantly stricter than two years ago. This article covers the TCF directory structure, what each section should contain, and how to sign the DoC – against current regulations.
The TCF is the manufacturer's statutory evidence base to demonstrate product compliance to EU market‑surveillance authorities. Legally, it does not accompany the product to the consumer – it's an internal manufacturer document. When EU market‑surveillance authorities or customs request it, you must produce it within the specified timeframe. If you can't – or if the file has major defects – the product is deemed non‑compliant – delisting, recall, and fines follow.
Retention period:
·General LVD/EMC/RED/RoHS directives: at least 10 years after the last product is placed on the market.
·Some special directives (e.g., certain medical devices): 5 years – check the specific directive.
Important: non‑EU manufacturers do not need to store the full file physically in Europe – you only need to ensure that the EU‑based authorised representative can make it available when requested.
Common myth: from 2026, paper DoCs will be invalid – you must use an EU‑wide e‑DoC platform. This is draft‑discussion material – not enacted legislation. The current RED/LVD/EMC directives still accept PDF or paper DoCs issued by the manufacturer – no EU platform upload is required.
二、TCF – Six Core Sections
A review‑ready TCF must cover the following six sections. Missing any one – you'll be asked for supplementary information.
Section 1: Product description and overview
This section gives reviewers a quick understanding of what your product is.
·Basic product information: name, model, specification list, unique identifiers (serial/batch numbers).
·Product photos: high‑quality images, nameplate artwork – clearly showing CE mark, manufacturer name/address, and model.
·Intended use statement: what the product does, operating environment, target users.
Intended use descriptions must be specific. "For indoor use" vs. "For domestic and office indoor environments – temperature 0–40°C, relative humidity ≤85%, altitude ≤2000m" – the latter has review value. Specific constraints make risk assessment much more credible.
Section 2: Applicable EU directives and harmonised standards
This is the navigation section – and the highest‑failure chapter.
List all applicable EU directives. Example: a smart LED lamp may involve:
·LVD 2014/35/EU
·EMC 2014/30/EU
·RED 2014/53/EU
·RoHS 2011/65/EU
·Energy‑labelling regulation (EU) 2019/2015
One cannot be missed.
Then list the EN harmonised standards and version numbers. Emphasise version numbers – EN standards are updated – if your DoC references an old version after it's been replaced, the product is legally non‑compliant.
Example: EN 62368-1 – audio/video and IT equipment safety – but different products reference different versions. If you've only partially applied a standard – or not applied it – state the reasons and explain what alternative technical solutions were used to meet the essential safety requirements.
Section 3: Design and manufacturing information
This section shows the reviewer the product's internal logic.
·Hardware drawings: general assembly, exploded view, critical structural‑component dimension drawings.
·Circuit drawings: full schematics, PCB layout and silkscreen, BOM.
Common over‑complication: the BOM does not need each component's safety‑certificate number listed in the table. Critical safety components (fuses, optocouplers, X/Y capacitors, relays, transformers) – their compliance evidence can be attached as annexes – the BOM itself only needs the part number. You don't need to fill every certificate number into the table cells.
·Production process: manufacturing steps, assembly steps, quality‑control measures during production. Purpose: demonstrate that mass‑production products are the same as the tested samples.
With EN 18031 in effect, this section has an additional requirement: connected wireless devices must describe security objectives and protection measures. However: if the hardware does not support secure boot or firmware encryption signing – a risk‑assessment + compensatory‑measures path is acceptable – you don't need all these capabilities in hardware.
Section 4: Risk assessment report
This is the most strictly reviewed section in the TCF.
·Risk identification: cover normal use and foreseeable fault conditions. Mechanical, electrical, thermal, chemical, radiation, and cybersecurity hazards – each must be assessed. Foreseeable misuse must also be considered – e.g., wet‑hand operation, operation outside rated temperature.
·Risk mitigation: for each identified risk, explain the measures taken to eliminate or reduce it – design improvements, safety guards, warning labels – with verification of effectiveness.
Cybersecurity risks – new requirement. Assess the likelihood of unauthorised remote access, firmware tampering, data leakage, and DDoS attacks. Provide measures taken – e.g., mandatory default‑password change, TLS 1.3 encryption, secure firmware update mechanism.
Risk assessment uses a qualitative framework – likelihood × severity + risk‑reduction measures. Numerical percentage reductions are not required – qualitative analysis with closed‑loop measures satisfies regulatory requirements.
Section 5: Test reports and verification data
This section provides objective evidence.
·Test reports: safety, EMC, RF, energy efficiency – all must be formal versions from accredited labs.
·EN 18031 cybersecurity test report – only for connected radio equipment. Pure receivers and non‑connected wireless devices are not mandatory.
·Specialised verification: depends on product characteristics. Ordinary consumer CE‑RED/LVD products do not need biocompatibility testing or clinical evaluation reports – those are for MDR medical devices.
Section 6: User manual and safety labelling
The user manual is the last line of defence for product safety.
·Operation and maintenance manual: installation, commissioning, operating steps, routine maintenance, troubleshooting.
·Safety warnings: must be in the official languages of the EU member states where the product is sold – at least English – plus local languages as needed. Warnings must correspond to the risks identified in the risk assessment.
Label and nameplate artwork: CE mark, manufacturer information, product model, rated parameters. Wireless devices – RF transmit power and applicable band information – can be in the manual or packaging – RED does not mandate this on the nameplate itself. WEEE mark – a product‑label element under waste‑electronics recycling regulations – does not go into the DoC.
三、How to Write the DoC
Once the TCF is complete, sign the Declaration of Conformity (DoC).
The DoC has fixed legal format requirements – under EU Decision 768/2008/EC. A compliant DoC must include:
·Product unique identifier – model number + batch number.
·Manufacturer or EU authorised representative – name and address.
·"This declaration of conformity is issued under the sole responsibility of the manufacturer." – the legal meaning must be retained – but it may be translated into member‑state official languages – it does not have to be in English verbatim.
·Complete list of applicable EU directives – with year of publication.
·Complete list of referenced EN harmonised standards – full titles and version years.
·If a Notified Body was involved (medical devices, PPE, etc.) – NB name and four‑digit ID.
·Place and date of issue, authorised signatory's name and title, handwritten signature.
Signatory authority: does not have to be the legal representative personally – a compliance officer or manager with written authorisation can sign. Overseas manufacturers can also have their EU authorised representative sign – provided the authorisation document is retained in the TCF.
四、Common TCF Rejection Reasons
1.Referencing obsolete EN standards – this is very common. Before each TCF update, check the CENELEC website for the latest versions of all referenced standards.
2.Risk assessment is superficial – writing "risk is low" with no analysis or measures. Risk analysis must have four closed‑loop steps: identification, assessment, measures, verification.
3.Missing EN 18031 cybersecurity test report – for new projects after August 2025 with connected wireless functionality – this is no longer skippable.
4.DoC signatory lacks written authorisation – authorisation documents must be retained in the TCF – otherwise, the review deems it invalid.
5.Document version chaos – product design changed – TCF not updated. If you changed the thermal design or added EMC ferrite beads – these changes must be recorded in the TCF – with re‑assessment of impact.
For CE technical documentation, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.
Related News