Cyber Resilience Act

Substantial modification

Legal definition Art. 3(30) CRA

“a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed”
Regulation (EU) 2024/2847, Art. 3(30) CRA

The Cyber Resilience Act (CRA) does not assess products continuously but at a moment in time: at the placing on the market. Substantial modification is the mechanism that stops later changes from quietly voiding that assessment.

The definition names two triggers, and one is enough: the change affects compliance with the essential cybersecurity requirements set out in Part I of Annex I, or it modifies the intended purpose for which the product was assessed.

The second trigger is easily missed

The code can stay entirely unchanged. If a product is marketed with a different intended purpose than the one assessed, the threshold is crossed anyway. Software assessed as an internal tool and later offered for operation over the open internet is the classic example.

Anyone watching only technical changes misses this case systematically.

What counts as substantial and what does not

Usually not substantial: bug fixes, security updates that close a vulnerability, interface changes with no effect on protective mechanisms.

Usually substantial: new external interfaces, changes to authentication, encryption or permission handling, swapping a security-relevant core component, new features that process additional data or open new connections.

The classification is a judgement, not a calculation. Which is precisely why it belongs in writing: decisions recorded in a way someone can follow are what counts in a later examination.

The consequences

Where a modification is substantial, the compliance of the changed product has to be verified. Recital 202 states the consequence: where applicable, the product undergoes a new Conformity assessment. Where the manufacturer undertakes that assessment involving a third party, a change that might lead to a substantial modification is to be notified to the third party. The technical documentation is carried forward in any case: under Article 31(2) it is continuously updated, where appropriate, at least during the support period.

A substantial modification does not extend the Support period. Article 13(10) even points the other way: where a manufacturer has placed subsequent substantially modified versions of a software product on the market, it may ensure compliance with the essential cybersecurity requirement in Part II, point (2), of Annex I only for the version last placed on the market, provided that users of the earlier versions have access to that version free of charge and incur no additional costs to adjust the hardware and software environment.

Who becomes a manufacturer through it

The consequence with the widest practical reach concerns other economic operators. An Importer or Distributor carrying out a substantial modification of a product already placed on the market is deemed a manufacturer under Article 21 and becomes subject to Articles 13 and 14. Any other person who substantially modifies a product and makes it available on the market is likewise deemed a manufacturer under Article 22, but bears those obligations only for the part of the product affected by the modification, and for the entire product only where the modification has an impact on its cybersecurity as a whole.

Deep customer-specific adaptations are therefore not a peripheral service but potentially the entry into the manufacturer role, with everything that entails.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.