Not every repair, patch or software update creates a new manufacturer role. The CRA focuses on substantial modification. Security updates designed to decrease cybersecurity risk without changing intended purpose are generally not considered substantial modifications, while changes to intended purpose or changes that affect Annex I compliance can trigger a new manufacturer analysis and potentially a new conformity assessment.
Substantial Modification Has a Defined CRA Meaning
Article 3(30) defines substantial modification as a change to the product with digital elements following its placing on the market which affects compliance with the essential cybersecurity requirements in Part I of Annex I or results in a modification to the intended purpose for which the product was assessed. The analysis therefore focuses on compliance effect and intended purpose rather than on the size of the code diff alone.
Importers and Distributors Are Covered by Article 21
Article 21 provides that an importer or distributor is considered the manufacturer where it carries out a substantial modification of a product with digital elements already placed on the market. The operator then becomes subject to Articles 13 and 14. A reseller that materially changes a product should therefore reassess its CRA role before supplying the changed version.
Article 22 Covers Other Modifying Persons
Article 22 covers a natural or legal person other than the manufacturer, importer or distributor that carries out a substantial modification and makes the modified product available on the market. That person shall be considered to be a manufacturer for CRA purposes. This can be relevant to integrators, customisers and other businesses that commercially supply materially changed products.
The Obligations Can Apply to the Affected Part or the Product as a Whole
Article 22 states that Articles 13 and 14 apply to the part of the product affected by the substantial modification or, where the modification has an impact on the cybersecurity of the product as a whole, to the entire product. Teams therefore need to analyse the cybersecurity effect of the modification rather than assuming that obligations are always confined to the changed module.
A Security Update Is Not Automatically a Substantial Modification
The CRA recitals explain that a security update designed to decrease the level of cybersecurity risk and that does not modify the intended purpose is not considered to be a substantial modification. A patch addressing a known vulnerability can therefore remain ordinary security maintenance even where functions or performance change solely for the purpose of reducing cybersecurity risk.
Minor Functionality Changes Are Generally Different
Recital 39 explains that minor functionality updates, such as visual enhancements or adding pictograms or languages to the user interface, should not generally be considered substantial modifications. This does not create a universal safe harbour for every small code change, but it demonstrates that CRA analysis depends on the effect of the change rather than simply whether a new version number exists.
Feature Updates Can Become Substantial
A feature update can become a substantial modification where it modifies the original intended functions, type or performance and meets the CRA modification criteria. New functionality can broaden the attack surface and change the level or nature of cybersecurity risk. A software release process should therefore flag material feature changes for CRA assessment before the updated version is made available on the market.
Maintenance and Repair Do Not Necessarily Trigger the Rule
The CRA recitals state that refurbishment, maintenance and repair do not necessarily create a substantial modification where intended purpose and functionality remain unchanged and the level of risk remains unaffected. Product teams should document why a repair or maintenance operation does not affect Annex I compliance rather than assuming every post-market intervention has the same legal effect.
A Substantial Modification Can Require a New Conformity Assessment
Recital 41 explains that where a substantial modification may affect compliance or changes intended purpose, conformity should be verified and, where applicable, the product should undergo a new conformity assessment. Where third-party conformity assessment is involved, a change that might lead to substantial modification may also need to be notified to the relevant third party.
Build a Modification Decision Into Release Governance
For significant software or hardware changes, record the original intended purpose, the modification, affected product components, change in cybersecurity risk, effect on Annex I compliance, whether the modified version will be made available on the market and whether the change creates a new manufacturer role. The decision should be completed before commercial release rather than after the modified product reaches users.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.