Cyber Resilience Act
Substantial modification
Legal definition Art. 3(30) CRA
“a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed”
The Cyber Resilience Act (CRA) does not assess products continuously but at a moment in time: at the placing on the market. Substantial modification is the mechanism that stops later changes from quietly voiding that assessment.
The definition names two triggers, and one is enough: the change affects compliance with the essential cybersecurity requirements set out in Part I of Annex I, or it modifies the intended purpose for which the product was assessed.
The second trigger is easily missed
The code can stay entirely unchanged. If a product is marketed with a different intended purpose than the one assessed, the threshold is crossed anyway. Software assessed as an internal tool and later offered for operation over the open internet is the classic example.
Anyone watching only technical changes misses this case systematically.
What counts as substantial and what does not
Usually not substantial: bug fixes, security updates that close a vulnerability, interface changes with no effect on protective mechanisms.
Usually substantial: new external interfaces, changes to authentication, encryption or permission handling, swapping a security-relevant core component, new features that process additional data or open new connections.
The classification is a judgement, not a calculation. Which is precisely why it belongs in writing: decisions recorded in a way someone can follow are what counts in a later examination.
The consequences
Where a modification is substantial, the compliance of the changed product has to be verified. Recital 202 states the consequence: where applicable, the product undergoes a new Conformity assessment. Where the manufacturer undertakes that assessment involving a third party, a change that might lead to a substantial modification is to be notified to the third party. The technical documentation is carried forward in any case: under Article 31(2) it is continuously updated, where appropriate, at least during the support period.
A substantial modification does not extend the Support period. Article 13(10) even points the other way: where a manufacturer has placed subsequent substantially modified versions of a software product on the market, it may ensure compliance with the essential cybersecurity requirement in Part II, point (2), of Annex I only for the version last placed on the market, provided that users of the earlier versions have access to that version free of charge and incur no additional costs to adjust the hardware and software environment.
Who becomes a manufacturer through it
The consequence with the widest practical reach concerns other economic operators. An Importer or Distributor carrying out a substantial modification of a product already placed on the market is deemed a manufacturer under Article 21 and becomes subject to Articles 13 and 14. Any other person who substantially modifies a product and makes it available on the market is likewise deemed a manufacturer under Article 22, but bears those obligations only for the part of the product affected by the modification, and for the entire product only where the modification has an impact on its cybersecurity as a whole.
Deep customer-specific adaptations are therefore not a peripheral service but potentially the entry into the manufacturer role, with everything that entails.
Practical questions
-
As a rule, no. An update that closes a vulnerability restores compliance rather than affecting it. That is what the CRA requires anyway. It becomes substantial once the security architecture is reworked, or new functionality with new attack surface is added. The line is not drawn by the amount of code but by the effect on the requirements that were assessed.
-
The compliance of the product in its modified form has to be verified first: the affected essential requirements are re-examined, the technical documentation and the risk assessment are updated, and conformity assessment is repeated where applicable, to the extent the change reaches. The result is a modified version that has to be compliant in its own right.
-
Yes, considerably. Anyone making a substantial modification to a product already placed on the market and then making it available is deemed a Manufacturer for the purposes of the regulation. For importers and distributors the obligations of Articles 13 and 14 then apply in full. For anyone else, Article 22(2) limits them to the part of the product affected by the modification, and extends them to the entire product only where the modification has an impact on its cybersecurity as a whole. In practice this catches system integrators and providers of deep customer-specific adaptations.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.