Must the manufacturer document how its OTA or other update-distribution mechanism is secured?
Yes.
The CRA technical-documentation rules do not treat secure update distribution as just an operational detail. Annex VII requires the technical documentation to include the necessary information and specifications of the manufacturer's vulnerability-handling processes, including a description of the technical solutions chosen for the secure distribution of updates.
So the manufacturer needs more than a working update channel. It also needs documentation showing what secure update-distribution approach it chose for the product.
Supports documenting the technical solutions chosen for secure update distribution.