Not every repair or update changes the CRA role. The key question is whether the modification meets the CRA definition of substantial modification by affecting Annex I Part I compliance or changing the intended purpose for which the product was assessed. That decision should be made before the modified product is placed or made available on the market.
Start With the CRA Definition of Substantial Modification
Article 3 defines substantial modification as a change after market placement that affects compliance with the essential cybersecurity requirements in Annex I Part I or results in a modification to the intended purpose for which the product was assessed.
Importers and Distributors Fall Under Article 21
Where an importer or distributor carries out a substantial modification of a product already placed on the market, Article 21 treats that operator as the manufacturer and makes Articles 13 and 14 applicable.
Other Persons Can Become Manufacturers Under Article 22
A person other than the manufacturer, importer or distributor that substantially modifies the product and makes it available on the market is considered the manufacturer for CRA purposes.
Obligations Can Apply to the Affected Part or the Whole Product
Article 22 states that Articles 13 and 14 apply to the part affected by the substantial modification or to the entire product where the change impacts the cybersecurity of the product as a whole.
Not Every Security Update Is a Substantial Modification
The CRA recitals distinguish security updates intended to reduce cybersecurity risk without changing intended purpose from substantial modifications. Product teams should therefore avoid treating every patch as a new manufacturer event.
Feature and Intended-Purpose Changes Need Closer Review
Changes that alter intended use, major product functions, exposure or the assumptions behind the original conformity assessment are stronger candidates for substantial-modification review.
Conformity May Need to Be Reassessed
Where the modification affects compliance or intended purpose, conformity should be reviewed and, where applicable, a new conformity assessment performed before the modified product reaches the market.
Document the Modification Decision
Record the original intended purpose, the modification, affected parts, cybersecurity impact, role conclusion, conformity impact and approval. This prevents market-access teams from relying on undocumented assumptions about whether the change was substantial.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.