FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Substantial Modification

Do importers, distributors, and other third parties become manufacturers under the same CRA rule?

No. The CRA separates the provisions.

Article 21 covers importers and distributors that carry out a substantial modification of a product already placed on the market. Article 22 covers other natural or legal persons where they carry out a substantial modification and make the modified product available on the market.

Citations
Cyber Resilience Act

Articles 21 and 22 distinguish importer/distributor manufacturer status from other persons making substantially modified products available.

CRA Substantial Modification

If only one part is affected, do CRA obligations apply only to that part?

Article 22 narrows the obligation to the part affected by the substantial modification, unless the modification affects the cybersecurity of the product as a whole.

In practice, the evidence should explain the affected boundary. If the changed part alters shared authentication, update mechanisms, communications, data flows, remote processing, or other whole-product security assumptions, teams should expect the whole-product assessment to be relevant.

Citations
Cyber Resilience Act

Article 22(2) limits obligations to the affected part or extends them to the whole product when whole-product cybersecurity is affected.

CRA Substantial Modification

Does a CRA substantial modification trigger a new conformity assessment?

Where a substantial modification may affect CRA compliance or changes intended purpose, compliance should be verified again and, where applicable, the product should undergo a new conformity assessment.

If a third-party conformity assessment was used, a change that might lead to a substantial modification should be notified to the third party where applicable.

Citations
Cyber Resilience Act

Recital 41 addresses re-verification, new conformity assessment where applicable, and notifying third parties about possible substantial modifications.

CRA Substantial Modification

Must every CRA test and technical-documentation item be redone after a substantial modification?

No. Existing tests and documentation can be reused for parts of the product that are not affected by the substantial modification.

The person placing the modified product on the market must still update the technical documentation for impacted requirements, demonstrate why unchanged parts do not need new evidence, take responsibility for the modified product's conformity, and draw the required declaration of conformity.

Citations
Blue Guide 2022

Section 2.1 explains that technical documentation updates should track modification impact and that unchanged aspects need not be retested.

CRA Substantial Modification

What evidence should a CRA substantial-modification file contain?

Keep enough evidence to show the change was assessed against the CRA test rather than only approved as an engineering release.

A useful file links the release scope to the original intended purpose, risk assessment, threat model, affected architecture, Annex I Part I controls, vulnerability-handling impact, user instructions, test results, conformity route, declaration status, and any third-party assessment notification.

Citations
Cyber Resilience Act

Articles 13(7), 31(2), and Annex VII require the risk assessment and technical documentation to remain accurate and updated.

CRA Substantial Modification

What should user-facing guidance say after a CRA post-market change?

Users should receive practical information tied to the actual change: what changed, whether action is needed, any configuration or security-update steps, changed support information, and any known constraints introduced by replacement parts or interoperability measures.

For security updates, the CRA separately requires security updates to be disseminated without delay and accompanied by advisory messages with relevant information, including potential user action. Where technically feasible, new security updates must be provided separately from functionality updates.

Citations
Cyber Resilience Act

Annex I Part II points 2, 7, and 8 address vulnerability remediation, secure update distribution, and user advisory messages.

European Commission CRA FAQs

The Commission FAQ explains security-update transparency, automatic-update expectations, and separate security updates where technically feasible.

CRA Substantial Modification

How does CRA substantial modification affect products placed on the market before 11 December 2027?

Products with digital elements placed on the market before 11 December 2027 are subject to CRA requirements only if, from that date, they are subject to a substantial modification.

The Commission FAQ gives a practical contrast: a non-substantial bug-fix update for a smart TV placed on the market in 2027 does not require bringing that TV into full CRA conformity, but a later update that adds smart-home-control functionality and qualifies as substantial does.

Citations
Cyber Resilience Act

Article 69(2) sets the transition rule for products placed on the market before 11 December 2027.

CRA Substantial Modification

For a legacy product, should the manufacturer be able to prove an update is not substantial?

Yes. For products placed on the market before 11 December 2027 where the CRA was not applied at initial placement, the draft guidance says manufacturers must be able to demonstrate to a market surveillance authority that later updates do not constitute substantial modifications.

A cybersecurity risk assessment covering Article 13(2) elements, plus documented compliance reasoning, should make that position easier to support.

Citations
Cyber Resilience Act

Article 69(2) is the legal basis for substantial-modification treatment of pre-application products.

CRA Substantial Modification

If a legacy product is substantially modified after 11 December 2027, what must happen before market placement?

The manufacturer must comply with the CRA in its entirety before placing the substantially modified product on the market, and then for the duration of that product's support period.

Teams should treat this as a release gate: confirm product scope, update the risk assessment and technical documentation, choose or confirm the conformity assessment route, prepare conformity evidence, update user information, and confirm vulnerability-handling processes before the modified product is made available.

Citations
CRA Substantial Modification

Does a third party become the CRA manufacturer if it modifies a product only for its own use?

Article 22 does not automatically make every third-party modifier the manufacturer. For a natural or legal person other than an importer or distributor, the Article 22 trigger requires both a substantial modification and making the modified product available on the market.

A modification kept solely for the modifier's own use therefore does not meet that specific Article 22 market-availability trigger. Importers and distributors are governed separately by Article 21, and other EU or national rules may still apply. The facts should record who performed or commissioned the change, whether the product was supplied onward, and under whose name or trademark it was made available.

Citations
Cyber Resilience Act

Article 21 covers importers and distributors; Article 22(1) covers another person only where that person substantially modifies a product and makes it available on the market.

CRA Support Period

What does the CRA mean by Support Period?

The CRA defines the Support Period as the period during which the manufacturer must ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the CRA vulnerability-handling requirements.

Article 13(8) applies that obligation from placing on the market and throughout the Support Period. The obligation covers the product in its entirety, including integrated components.

Citations
Cyber Resilience Act

Article 3(20) defines the Support Period; Article 13(8) applies vulnerability-handling duties during that period.

CRA Support Period

Is the CRA Support Period always five years?

No. The CRA sets a minimum of at least five years, but that is not a universal cap or safe default.

If the product with digital elements is expected to be in use for less than five years, the Support Period must correspond to that expected use time. If the product is reasonably expected to be used for longer than five years, the Commission FAQ says five years is not sufficient by itself and the manufacturer should consider the Article 13(8) criteria, which may require a longer period.

Citations
CRA Support Period

What criteria should manufacturers use to determine the Support Period?

Article 13(8) requires the Support Period to reflect the length of time during which the product is expected to be in use.

The mandatory factors are reasonable user expectations, the nature of the product including intended purpose, and relevant Union law determining the lifetime of products with digital elements. Manufacturers may also consider support periods for similar products, availability of the operating environment, support periods of third-party integrated components that provide core functions, and relevant ADCO or Commission guidance.

The Commission FAQ adds an important guardrail: manufacturers are not expected to set support periods by simply copying expected use time, except where the expected use time is less than five years. The criteria must be considered proportionately.

Citations
Cyber Resilience Act

Article 13(8) lists the required and optional criteria for determining the Support Period.

CRA Support Period

How does expected product lifetime affect the cybersecurity risk assessment?

Expected use is not only a support-period input. Article 13(3) requires the cybersecurity risk assessment to take into account the length of time the product is expected to be in use.

The Commission FAQ explains that manufacturers should consider product lifetime during design and development and prepare the product so that vulnerabilities, including component vulnerabilities, can be handled effectively throughout the Support Period.

Citations
CRA Support Period

When can the Support Period be shorter than five years?

A shorter Support Period is justified only where the product is expected to be in use for less than five years. In that case, the CRA says the Support Period must correspond to the expected use time.

The Commission FAQ gives examples such as a contact-tracing application intended for a pandemic and some software applications that become unavailable and are no longer in use once a subscription expires. Do not generalize that example to every subscription product; document why the product is genuinely unavailable or no longer in use after the relevant period.

Citations
Page 45 of 58