What is a substantial modification under the Cyber Resilience Act?
A CRA is a change made after a product with digital elements has been that affects the product's compliance with Annex I Part I or changes the for which the product was assessed.
The test is about the change's cybersecurity and intended-purpose effect. A release note label such as patch, upgrade, repair, maintenance, hotfix, or feature update does not decide the answer by itself.
Defines substantial modification in Article 3(30) by reference to Annex I Part I compliance and assessed intended purpose.
Explains in points 85-87 why substantial modification matters across manufacturer status, legacy products, and conformity reassessment.