Repairs and spare parts
Repairs that keep a product within its assessed intended use do not constitute substantial modifications. Replacing identical components or upgrading memory creates no new conformity obligations.
Article 2(6) exempts spare parts that replace identical components. Equivalence is judged on security properties and protocols rather than part numbers.
If a replacement component introduces new cryptographic mechanisms or altered secure boot processes, it requires independent assessment as a product with digital elements.
Updates, substantial modification, and the support period
An update becomes a substantial modification when it extends intended purpose or introduces new risks to essential requirements. Adding machinery control functions to a passive monitoring dashboard crosses this threshold.
Standard security patches, bug fixes, and configuration hardening do not constitute substantial modifications.
Under Article 13(10), manufacturers can remediate only the latest version if user upgrades are free of charge. Substantial modifications require reassessing the support period if hardware operational life increases.
Two questions decide a substantial modification. Does the update take the product beyond the assessed intended purpose, and does it introduce a risk that touches the essential requirements. Everything else, including most security updates, stays outside.
Core functionality, conformity, and treating risk
Classification follows core functionality as defined in Implementing Regulation (EU) 2025/2392. Products are classified by their primary operational capabilities.
Software modules sold as independent subscriptions are classified separately. Adding auxiliary features does not alter the core conformity route of the main product.
Manufacturers can mitigate risk by defining operational limits in user information. Existing compliant designs require no redesign if current risk assessments prove conformity.