← Commission worked examplesRepairs and spare parts

Are spare parts and repairs subject to the Cyber Resilience Act?

6 worked examples from Commission guidance C(2026) 5252 final, reproduced word for word.

Also asked

  • Does the CRA apply to replacement parts for older products?
  • When does a repair become a substantial modification under the CRA?
  • What does identical mean for a CRA spare part?
  • Can I supply a newer chip as a spare part under the CRA?
  • Are spare parts for pre-CRA products exempt?

Article 2(6) takes spare parts outside the CRA where they replace identical components in a product with digital elements. The Commission's examples turn on what identical means. A replacement module built to the same specifications is exempt, whether the host product predates the CRA or not. A newer chip with a different cryptographic implementation and secure boot mechanism is not identical and is a product in its own right. A different chipset can still be identical where the protocols and security mechanisms are unchanged.

The exemption covers the spare part. Whether the repair substantially modifies the host product is a separate question answered by the same risk-impact test.

At a glance

Legal basis
Article 2(6)
Test
Identical component, manufactured to the same specifications
Cryptography and secure boot changed
Not identical. Exemption lost (Example 37)
Different chipset, same security mechanisms
Still identical. Exemption holds (Example 38)
Component or whole subassembly
Both exempt (Example 39)

Last reviewed 27 July 2026

Verified against The Annex to Commission Communication C(2026) 5252 final of 27 July 2026, compared against the earlier undated consultation draft, and Regulation (EU) 2024/2847 as published in OJ L, 20.11.2024, read at EUR-Lex on 27 July 2026

Identical is judged on cybersecurity properties, not part numbers

Examples 36 to 38 are the useful trio, because they show the test cutting both ways.

A replacement communication module that is identical and built to the same specifications is exempt under Article 2(6), and the guidance confirms this holds whether the controller it repairs was placed on the market in 2026 or in 2028.[2]

A newer chip supplied because the original is discontinued is not identical where it has a different cryptographic implementation and an updated secure boot mechanism, because those differences affect its cybersecurity properties. It becomes a product with digital elements subject to the CRA, assessed in light of its intended purpose including interoperability with the older host.

A module built on a different chipset with updated firmware can still be identical, provided it performs the same function using the same communication protocols and security mechanisms and the firmware does not alter characteristics relevant to cybersecurity. The silicon is not the test.

CRA referenceArticle 2(6)

A repair that stays inside the assessed intended use is not a modification

Example 35 handles the ordinary case. Swapping a defective RAM module for a better performing one does not substantially modify a server, because compliance with the essential requirements is unaffected and the improved performance stays within the intended use already considered in the risk assessment.

Example 39 confirms the exemption does not depend on how deep in the assembly the replacement sits. Where a programmable logic controller's CPU fails, supplying either an identical CPU or an identical complete PLC as a spare part falls within Article 2(6), provided it goes through the after-sales channel and the system it is intended for is clearly identified.[1]

CRA referenceArticle 2(6), Article 3, point (30)

The counter-example that did not survive to adoption

The March 2026 consultation draft carried a second physical repair example immediately after the RAM case. It described a similar operation that significantly changed the server's behaviour by altering how core functions are executed, a change the original risk assessment had not considered, and concluded the server was substantially modified.

That example is not in the adopted text. The rule it illustrated survives at point 95, so the deletion narrows the illustration rather than the rule. It is reproduced below because readers working from the draft will remember it, and because it is the clearest statement of what a repair has to do before it crosses the line.

CRA referenceArticle 3, point (30)

The Commission’s examples, word for word

6 examples, reproduced exactly as published. Each carries the section, guidance point and page it comes from. The bold line above each quotation is our summary of the outcome and is not part of the source.

Example 35

Section 4.1 Physical repairs, point 95, page 32

Not a substantial modification. Better-performing RAM, still inside the assessed intended use

The manufacturer of a computer server performs a repair operation, switching out a defective RAM with a new, better performing one. The server's compliance with the essential requirements is not affected. The server performs better, but its new performance remains within the server's intended use as considered in the cybersecurity risk assessment. The computer server is not considered to be substantially modified.

Draft Example 29.

Example 36

Section 4.2 Spare parts, point 101, page 33

Exempt under Article 2(6). An identical replacement module, whether the host product predates the CRA or not

A manufacturer has placed connected controllers on the EU market. In one case, the controller was placed on the market in 2026, before the date of application of the CRA. In another case, the controller was placed on the market in 2028, in compliance with the CRA. In 2028, a digital communication module in both types of controllers fails. The manufacturer supplies as a spare part a replacement module that is identical and manufactured according to the same specifications as the original.

In both cases, the replacement module falls within the scope of the exemption in Article 2(6). The spare part is not itself subject to the CRA, even though it is a product with digital elements, because it replaces an identical component in a product with digital elements. The repair does not constitute a substantial modification of the product with digital elements.

Merged from draft Examples 31 and 33.

Example 37

Section 4.2 Spare parts, point 101, page 34

Not exempt. Different cryptographic implementation and secure boot means the part is not identical

A manufacturer placed a connected industrial controller on the EU market in 2026, before the date of application of the CRA. In 2028, a communication chip in that controller fails. As the manufacturer no longer manufactures that chip, it supplies as a spare part a newer chip with equivalent functionality, but with a different cryptographic implementation and updated secure boot mechanism, in order to maintain compatibility and continued operation.

In this case, the replacement chip cannot be considered identical, as the differences in the cryptographic implementation and secure boot mechanism affect the chip's cybersecurity properties. It therefore does not benefit from the exemption in Article 2(6) and constitutes a product with digital elements subject to the CRA. Compliance of the replacement part must be assessed in light of its intended purpose, including its role in ensuring interoperability with the product with digital elements placed on the market before the CRA entered into application.

Example 38

Section 4.2 Spare parts, point 101, page 34

Exempt. A different chipset can still be identical where the security mechanisms are unchanged

A manufacturer places on the market a smart building controller in 2028 in compliance with the CRA. In 2029, the wireless module in that controller fails. As the manufacturer no longer manufactures that module, it supplies as a spare part a new module that performs the same function using the same communication protocols and security mechanisms, but is based on a different chipset and has updated firmware that does not alter characteristics that may be relevant to cybersecurity.

In this case, the replacement module can be considered identical. The module therefore benefits from the exemption in Article 2(6) and is not subject to the CRA.

Example 39

Section 4.2 Spare parts, point 102, page 34

Exempt either way. The exemption applies whether the spare part is a component or the whole subassembly

In 2027, a manufacturer places on the market an industrial automation system that incorporates a programmable logic controller (PLC) as one of its components. In 2031, the PLC's central processing unit (CPU) fails. The manufacturer offers two repair options: (i) the supply of a replacement CPU unit, which can be considered identical to the CPU originally installed; or (ii) the supply of a complete replacement PLC, which can be considered identical to the PLC originally installed. In each case, the replacement is supplied through the manufacturer's after-sales service channel as a spare part, and the industrial automation system for which the replacement is intended is clearly identified. In both cases, the replacement falls within the scope of the exemption in Article 2(6), whether the replacement concerns a component within the PLC, or the PLC as a whole.

New in the adopted text. It has no counterpart in the earlier consultation draft.

Deleted draft example

Section 4.1 Physical repairs (earlier draft only), point 90, page 28

Deleted before adoption. The draft's counter-example, a repair that does amount to a substantial modification

The manufacturer of the computer server performs a similar operation as in example 1, but the operation leads to a significant change in the server's behaviour by altering the way core functions are executed. The manufacturer had not considered the server's new behaviour in its original risk assessment, thereby potentially affecting the product's compliance with the essential requirement. The computer server is considered to be substantially modified.

From the earlier consultation draft. It was removed before adoption and is not part of the guidance in force.

Draft Example 30. It followed the RAM replacement example that became Example 35 in the final text, and its cross-reference to 'example 1' points at draft Example 29, the same RAM case. The final guidance still states the rule at point 95 but no longer illustrates the positive case.

Sources

Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.

  1. [1]

    European Commission · Sections 4.1 and 4.2, points 95 to 102 · C(2026) 5252 final · Final, adopted 27 July 2026

    Article 26 guidance sets out the Commission's interpretation of the CRA. It does not bind economic operators, and only the Court of Justice of the European Union can give an authoritative interpretation of the Regulation.

    Accessed 2026-07-27

  2. [3]

    European Union · Article 3, point (30) · CELEX:32024R2847

    Accessed 2026-07-27

  3. [4]

    European Commission, DG CONNECT · Section 4.1, point 90, draft Example 30 · Consultation draft, superseded by C(2026) 5252 final

    A superseded consultation draft. It reflects neither the adopted guidance nor the law, and is reproduced here only to show what the Commission removed.

    Accessed 2026-07-27

Turn the guidance into an audit-ready file

Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.