← Commission worked examplesSubstantial modification

Which software updates has the Commission called substantial modifications?

12 worked examples from Commission guidance C(2026) 5252 final, reproduced word for word.

Also asked

  • Does a security update count as a substantial modification under the CRA?
  • Do I need a new conformity assessment after a feature update?
  • Does adding a remember me feature trigger a new CRA assessment?
  • Does changing a cryptographic algorithm substantially modify a product?
  • Who is the manufacturer when a third party modifies a product?

The Commission tests a software update by its effect on the cybersecurity risk profile rather than by its size. A persistent login feature storing authentication tokens locally is a substantial modification. So is a diagnostics export that leaves sensitive operational data unencrypted. Enabling control features that shipped disabled but assessed is not, and neither is group messaging the original assessment anticipated. Security updates generally fall outside, until they change the intended purpose or add new external dependencies.

A substantially modified product is treated as a new product and constitutes a new placing on the market. The reassessment focuses on the modified parts, and existing documentation may be reused for the rest.

At a glance

Legal basis
Article 3, point (30), recital 39
Test
Potential adverse impact on the risk profile, not scale or complexity (point 107)
Four questions
New threat vectors, new attack scenarios, changed likelihood, changed impact (point 110)
Negative branch
Cumulative. All four must be negative (point 111)
Security updates
Generally outside, per recital 39, unless point 109 applies

Last reviewed 27 July 2026

Verified against The Annex to Commission Communication C(2026) 5252 final of 27 July 2026, and Regulation (EU) 2024/2847 as published in OJ L, 20.11.2024, read at EUR-Lex on 27 July 2026

Size is not the test

Article 3, point (30) defines a substantial modification as a change after placing on the market that affects compliance with the essential requirements in Part I of Annex I, or that modifies the intended purpose for which the product was assessed.[2]

Point 107 of the guidance is explicit that the assessment should not be based on the scale or complexity of the change but on its potential adverse impact on the cybersecurity risk profile. Examples 44 and 45 make that concrete. A remember me feature storing authentication tokens locally is limited in scope and is still a substantial modification, because it introduces token theft, unauthorised access and session hijacking risks nobody assessed. A logging and diagnostics export is minor on its face and is still a substantial modification, because it ends up storing sensitive operational data unencrypted.

CRA referenceArticle 3, point (30)

What the original risk assessment already covers stays outside

Examples 42 and 43 are the reward for a thorough original assessment. Group messaging with administrator controls and moderation tools is not a substantial modification where the assessment already covered its later introduction, including the increased complexity of message routing. Enabling automated control loops that shipped present but disabled is not a substantial modification where the assessment explicitly covered their future activation, the closed-loop risks and the safeguards.

Examples 40 and 41 show the other end. A monitoring dashboard that gains the ability to adjust operating parameters and restart machines has moved from situational awareness to operational control. A personal data organiser that starts generating behavioural profiles and making automated decisions without user intervention has become an automated decision-making system. In both the intended purpose evolved beyond what the assessment envisaged.[1]

CRA referenceArticle 3, point (30), Article 13(2)

The security update carve-out and where it stops

Recital 39 and point 108 keep security updates outside, even where they are technically significant.[3] Fixing an input validation error or an authentication bypass sits inside the carve-out. So does hardening configuration, including tightening firewall rules, disabling unused ports, changing default administrator password policies and making multi-factor authentication mandatory where the functionality already existed. So does disabling a deprecated cryptographic algorithm in favour of a stronger one the original assessment already covered.

Point 109 closes the carve-out where the update modifies the intended purpose beyond what was foreseen or introduces new or increased risk. Replacing local file encryption with a remote service operated by the manufacturer qualifies as a substantial modification, and so does swapping an internally managed key lifecycle for a third-party key management service. Both are security-driven. Both materially alter data flows or add externally reachable interfaces nobody assessed.

CRA referenceRecital 39, Article 3, point (30)

Integration is not modification

Example 51 answers a question integrators ask constantly. A company that buys off-the-shelf microcontroller modules and connectivity components, writes its own firmware and a sensor package, and assembles a connected agricultural monitor placed on the market under its own name is not substantially modifying anything. It is placing a new product on the market, and it owns compliance for that product as a whole.

Where someone other than the original manufacturer genuinely does modify a product already on the market, Articles 21 and 22 make them the manufacturer, with obligations limited to the modified part where the change does not negatively affect the cybersecurity of the product as a whole.[4]

CRA referenceArticles 21 and 22

The Commission’s examples, word for word

12 examples, reproduced exactly as published. Each carries the section, guidance point and page it comes from. The bold line above each quotation is our summary of the outcome and is not part of the source.

Example 40

Section 4.3 Software updates as substantial modifications, point 105, page 35

Substantial modification. Monitoring dashboard gains operational control over the machines

A manufacturer places on the market a dashboard that collects data from machines and displays trends and alerts, without having the ability to control such machines. The manufacturer subsequently develops a new version of that dashboard, introducing functionalities that enable it to control the machines, including by adjusting operating parameters and restarting machines following fault conditions. As a result of these changes, the dashboard's intended purpose has evolved beyond what was envisaged in the risk assessment, shifting from a situational awareness tool to a product with digital elements intended to exercise operational control over other devices. The dashboard has therefore been substantially modified.

Example 41

Section 4.3 Software updates as substantial modifications, point 105, page 35

Substantial modification. A user-controlled tool becomes an automated decision-making system

A manufacturer places on the market a consumer software application intended to organise and display personal data, such as emails, messages, or documents, and to support basic search and filtering functions. The manufacturer subsequently introduces an update that enables the application to automatically analyse user content in order to generate behavioural profiles and make automated decisions affecting the prioritisation, suppression, or recommendation of content without user intervention. As a result of this change, the software's intended purpose shifts from a user-controlled information management tool to an automated decision-making system, which was not envisaged in the risk assessment. The application has therefore been substantially modified.

Example 42

Section 4.3 Software updates as substantial modifications, point 106, page 36

Not a substantial modification. Group messaging was already inside the original risk assessment

A messaging application is initially released with functionality limited to one-to-one messaging. The manufacturer's risk assessment covers the later introduction of group messaging, including for example the increased complexity of message routing. In a subsequent update, the manufacturer adds a group chat functionality together with administrator controls and moderation tools that were already foreseen and assessed in the original design. The update implements functionalities that fall within the scope of the original intended purpose and risk assessment. The messaging application has therefore not been substantially modified.

Example 43

Section 4.3 Software updates as substantial modifications, point 106, page 36

Not a substantial modification. Enabling control features that shipped disabled but assessed

A production monitoring system is placed on the market with read-only dashboards enabled, while automated control features are present in the system architecture but remain disabled. The manufacturer's risk assessment explicitly covers the future activation of automated control loops, including the cybersecurity risks associated with closed-loop control, as well as safeguards such as operator override mechanisms and fail-safe states. In a later update, the manufacturer enables the automated control features and activates the safeguards as originally assessed. The production monitoring system has therefore not been substantially modified.

Example 44

Section 4.3 Software updates as substantial modifications, point 107, page 36

Substantial modification. A small convenience feature introducing token theft and session hijacking risk

A manufacturer introduces an update to a software application adding a 'remember me' or persistent login feature that stores authentication tokens locally to improve user convenience. Although the functionality is limited in scope, it introduces new risks related to token theft, unauthorised access, and session hijacking that were not considered in the risk assessment. The update therefore affects compliance with the essential requirements. The software application has been substantially modified.

Example 45

Section 4.3 Software updates as substantial modifications, point 107, page 36

Substantial modification. Diagnostics logging that stores sensitive operational data unencrypted

A manufacturer adds a new logging and diagnostics feature to an existing software product with digital elements, enabling detailed system logs to be exported for troubleshooting purposes. While the functionality appears minor, it results in the collection and storage of sensitive operational data in an unencrypted format, introducing risks of data exposure that were not previously assessed or mitigated. The change may therefore have a significant impact on the cybersecurity risk profile of the product with digital elements. The software product with digital elements has been substantially modified.

Example 46

Section 4.3 Software updates as substantial modifications, point 108, page 37

Not a substantial modification. A security update fixing a buffer overflow or an authentication bypass

A manufacturer deploys a security update to address a vulnerability in the codebase of a product with digital elements by correcting an input validation error that could lead to a buffer overflow, or by fixing a logic flaw allowing authentication bypass through improper session token validation. The update modifies the internal implementation of the software without affecting that product's intended purpose or introducing new exposure. Such an update is intended exclusively to reduce the cybersecurity risk. The security update should not be considered a substantial modification.

Example 47

Section 4.3 Software updates as substantial modifications, point 108, page 37

Not a substantial modification. Hardening configuration, even where users must change how they access the product

A manufacturer introduces a security update that strengthens existing security configurations, such as tightening firewall rules, disabling unused network ports, changing default administrator password policies, or making multi-factor authentication mandatory where such functionality was already available or foreseen. Although the update may affect how users configure or access the product with digital elements, it does not alter its intended purpose and serves solely to enhance its security posture. The security update should not be considered a substantial modification.

Example 48

Section 4.3 Software updates as substantial modifications, point 108, page 37

Not a substantial modification. Deprecating an algorithm the original risk assessment already anticipated

A manufacturer places on the market a software product with digital elements that secures communications using a configurable encryption framework supporting multiple cryptographic algorithms and key sizes, as described in the product's technical documentation and risk assessment. The risk assessment covers all the cryptographic options provided in the product with digital elements and anticipates the future deprecation of certain algorithms. The risk assessment also includes mitigation measures, such as cryptographic agility, internal key management, and compatibility testing. In response to emerging cryptographic guidance, the manufacturer deploys a security update that disables a deprecated algorithm and activates a stronger, already supported alternative, without introducing new external dependencies or altering data flows. As the update implements a security measure that was foreseen and assessed as part of the original design, and it does not introduce new cybersecurity risks, the security update should not be considered a substantial modification.

Example 49

Section 4.3 Software updates as substantial modifications, point 109, page 38

Substantial modification despite the security motive. Local encryption replaced by a remote service

A manufacturer places on the market a software product with digital elements intended to provide local file encryption for data stored on a user's device, enabling users to encrypt and decrypt files on demand. Following the discovery of a vulnerability in the encryption workflow, the manufacturer deploys a security update that removes local encryption functionality and instead requires all files to be uploaded to, stored in, and processed by a remote encryption service operated by the manufacturer. As a result of this change, the product with digital elements no longer performs local encryption as originally intended, instead functioning as a remote encryption and data processing service. Although the update is introduced for security reasons, it fundamentally alters that product's intended purpose in a manner not foreseen in the risk assessment and therefore qualifies as a substantial modification.

Example 50

Section 4.3 Software updates as substantial modifications, point 109, page 38

Substantial modification despite the security motive. A new dependency on a third-party key management service

A manufacturer places on the market a software product with digital elements that relies on an established encryption protocol and an internally managed key lifecycle to secure communications between components of the product with digital elements. In response to newly identified cryptographic weaknesses, the manufacturer introduces a security update that replaces the existing encryption mechanism with a different protocol requiring the use of an external key management service operated by a third party. As a result of this change, the dependencies and data flows of the product with digital elements are materially altered, introducing new external interfaces and reliance on third-party services not considered in the risk assessment. Although the update is security-driven, it introduces new cybersecurity risks, and therefore qualifies as a substantial modification.

Example 51

Section 4.4.1 Substantial modifications carried out by a person other than the original manufacturer, point 120, page 41

Not a modification at all. Integrating third-party components into a new product makes you its manufacturer

A company purchases off-the-shelf microcontroller modules and connectivity components from third-party suppliers, develops proprietary firmware and a sensor package, and assembles them into a connected agricultural monitoring product with digital elements that it places on the market under its own name. Although the company has modified the underlying microcontroller modules and combined them with other components, it is not substantially modifying a product with digital elements already placed on the market; rather, it is placing a new product with digital elements on the market. The company is the manufacturer of the agricultural monitor for the purposes of the CRA and is required to comply with the Regulation in respect of the agricultural monitor as a whole.

New in the adopted text. It has no counterpart in the earlier consultation draft.

Sources

Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.

  1. [1]

    European Commission · Sections 4.3 and 4.4.1, points 105 to 120 · C(2026) 5252 final · Final, adopted 27 July 2026

    Article 26 guidance sets out the Commission's interpretation of the CRA. It does not bind economic operators, and only the Court of Justice of the European Union can give an authoritative interpretation of the Regulation.

    Accessed 2026-07-27

  2. [2]

    European Union · Article 3, point (30) · CELEX:32024R2847

    'substantial modification' means a change to the product with digital elements following its placing on the market

    Accessed 2026-07-27

  3. [3]

    European Union · Recital 39 · CELEX:32024R2847

    Accessed 2026-07-27

  4. [4]

    European Union · Articles 21 and 22 · CELEX:32024R2847

    Accessed 2026-07-27

Further reading on this site

Turn the guidance into an audit-ready file

Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.