Formal security documentation is usually a neglected task. However, it’s a basic requirement to have comprehensive and recent documents in place, not only if you are facing some sort of audit. We will compare the aims and structure of "classical" security documentation and will show common shortcomings of these documents. Especially when moving from waterfall to a more agile approach there are new challenges:- changes occur more frequently and must be reflected in the security documents,- increasing numbers of (micro-) services require significantly more documentation efforts,- resource-oriented services do not match well with usually established process-focused approaches,- security documentation is the first victim in high frequency deployment environments.The proven way to solve these issues is automation! We will outline an approach to take advantage of already existing meta information to derive a solid foundation of a security documentation. The process can be integrated into the usual build process and liberates the dev team from annoying documentation tasks.The talk will be completed with a summary of documentation parts that can be produced by automation and parts that need human expertise. We will also give an outlook on aspects that maybe addressed in later stages of automation.