Under the Cyber Resilience Act, does it matter for substantial-modification analysis whether the feature change was shipped separately or bundled with a security update?
No.
Recital 39 says that when assessing whether a feature update is a substantial modification, it is not relevant whether the feature update is provided separately or in combination with a security update. What matters is the effect on intended purpose and cybersecurity risk, not the packaging of the release.
Recital 39 says the packaging of a feature update with a security update is not the substantial-modification test.