← CRA FAQConformity and CE marking

Is my software update a substantial modification under the CRA?

Also asked

  • Does a security patch count as a substantial modification?
  • Does a substantial modification reset my support period?
  • Do I have to redo the whole conformity assessment after a substantial modification?
  • Am I the manufacturer if I modify someone else's product?

Ask four questions from Commission guidance point 110. Does the update introduce new threat vectors, enable new attack scenarios, change the likelihood of previously identified attack scenarios, or change their impact? Where all four are negative and the assumptions in your risk assessment still hold, the update is unlikely to be substantial. Any single yes makes it substantial, as does a change to the intended purpose the product was assessed against. The size of the change is irrelevant.

A substantially modified product is newly placed on the market, which triggers a fresh conformity assessment and its own declared support period. Conformity work may focus on the modified parts where the change does not harm the product's cybersecurity as a whole.

At a glance

Definition
CRA Article 3(30)
Test
Four factors, guidance C(2026) 5252 point 110
Scale
Not a factor. A small change can be substantial
Security updates
Generally not substantial, unless they alter intended purpose or dependencies
Consequence
Newly placed on the market, needs its own support period

Last reviewed 27 July 2026

Verified against Regulation (EU) 2024/2847 Articles 3(30), 21 and 22 and recitals 39 and 41 as published in OJ L, 20.11.2024, and Commission guidance C(2026) 5252 final of 27 July 2026, points 90 to 124.

The four-factor test

Article 3(30) defines a substantial modification as a change after placing on the market which affects compliance with the Annex I Part I essential requirements, or results in a modification to the intended purpose the product was assessed for.[1] Commission guidance C(2026) 5252 point 110 turns that into four questions a manufacturer can actually apply.[4]

Does the update introduce new threat vectors, such as additional interfaces, communication channels, execution environments or external dependencies? Does it enable new attack scenarios? Does it change the likelihood of previously identified attack scenarios, for example by lowering the effort required to exploit them or weakening existing safeguards? Does it change their potential impact, including the scope of affected data or functions, or the ability to detect, contain or recover from an incident?

The negative branch is cumulative. All four must be negative and the assumptions and mitigation measures relied on in the risk assessment must remain valid and effective.

CRA referenceArticle 3(30)

Why the size of the change does not matter

Point 107 is explicit that the assessment turns on the potential adverse impact on the product's cybersecurity risk profile rather than on the scale or complexity of the change.[4] The guidance illustrates this in both directions.

Adding a persistent login feature that stores authentication tokens locally is a substantial modification, because it introduces risks of token theft, unauthorised access and session hijacking that the risk assessment never considered. A diagnostics feature that exports detailed logs is substantial where it results in sensitive operational data being stored unencrypted.

In the other direction, enabling automated control features that were present in the architecture but shipped disabled, and whose activation the risk assessment already covered together with its safeguards, is not a substantial modification. Neither is adding group messaging to a messaging application where the original risk assessment anticipated it.

CRA referenceArticle 3(30)

The security-update carve-out and its limits

Recital 39 and guidance point 108 treat security updates as generally not substantial modifications, because their purpose is to reduce risk.[3][4] Tightening firewall rules, disabling unused ports, changing default password policies, making multi-factor authentication mandatory where it already existed, and disabling a deprecated cryptographic algorithm in favour of one already supported and assessed all fall inside the carve-out, even where the technical change is significant.

The carve-out is conditional. It falls away where the update alters the intended purpose or the dependency structure. Replacing local file encryption with a remote encryption service operated by the manufacturer is a substantial modification despite its security motive, because the product no longer does what it was assessed to do. So is swapping an internally managed key lifecycle for a third-party key management service, because it introduces new external interfaces and reliance not considered in the risk assessment.

CRA referenceRecital 39

What follows from a substantial verdict

A substantially modified product made available on the market is treated as a new product, and making it available is a new placing on the market.[4] The original manufacturer stays the manufacturer, but a fresh conformity assessment is owed.

That assessment is proportionate. Existing documentation and test results may be reused for parts the modification did not touch, and a third-party assessment should focus on the modified parts.[5] Where someone other than the original manufacturer carries out the modification, Article 22 makes them the manufacturer, and their Article 13 and 14 obligations extend only to the modified part where the change does not harm the product's cybersecurity as a whole.[2]

The support period needs re-deriving rather than resetting. Each substantially modified version needs its own declared period under Article 13(8), but a substantial modification does not automatically reset or extend it. The question is whether the modification changed the factors that set the expected use time.

CRA referenceArticles 13, 21 and 22

Sources

Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.

  1. [1]

    Publications Office of the European Union · Article 3(30) · CELEX:32024R2847 · OJ L, 20.11.2024

    a change to the product with digital elements following its placing on the market, which affects the compliance

    Accessed 2026-07-27

  2. [2]

    Publications Office of the European Union · Article 22 · CELEX:32024R2847 · OJ L, 20.11.2024

    Accessed 2026-07-27

  3. [3]

    Publications Office of the European Union · Recitals 39 and 41 · CELEX:32024R2847 · OJ L, 20.11.2024

    Accessed 2026-07-27

  4. [4]

    European Commission · C(2026) 5252

    Non-binding. Only the Court of Justice of the European Union can give an authoritative interpretation of the CRA.

    Accessed 2026-07-27

  5. [5]

    European Commission · 2022/C 247/01

    A Commission notice. It explains how New Legislative Framework product rules are applied across sectors without itself creating obligations.

    Accessed 2026-07-27

Follow-up questions

Does a change made by our cloud provider count?+

No. Guidance point 208 states that a major change in a third-party remote service is not a substantial modification of your product, because those elements are not under your responsibility. It should still prompt you to revise the risk assessment and check that your product-level controls remain adequate.

We assemble components into a new product. Is that a modification?+

No, that is integration. You are placing a new product on the market rather than modifying one already on it, so you are its manufacturer and the CRA applies to the product as a whole. You may rely on the compliance activities of the component manufacturers to support your own.

Work out where your product actually lands

Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.