Cyber Resilience Act decision examples
CRA product modifications
Review changes to intended purpose, cybersecurity and manufacturer responsibilities. Compare worked examples and the evidence behind each CRA assessment.
Does this change require a new assessment?
Open a situation to compare the relevant facts, worked results and evidence to retain.
Is adding remote access a substantial modification under the CRA?
Assess the change’s effect on essential-requirement compliance and the intended purpose. The feature name alone cannot establish whether it is a substantial modification.
View facts and examplesDoes changing a monitoring product into a controller require CRA reassessment?
A change to the intended purpose used in the conformity assessment can meet the substantial-modification test. An unchanged enclosure or product name does not settle the question.
View facts and examplesIs every security patch a substantial CRA modification?
A patch is not automatically substantial. Record whether it affects essential-requirement compliance or changes the assessed intended purpose, and resolve conflicting risk evidence.
View facts and examplesCan a distributor become responsible as manufacturer after changing firmware?
A person who substantially modifies a product and makes it available can acquire manufacturer obligations. Record both the change and the subsequent supply activity.
View facts and examplesHow to use these examples
The situations are hypothetical and use explicitly recorded assumptions. They explain a decision path, not a conclusion about your own product. Reporting obligations for manufacturers apply from 11 September 2026; broader product requirements apply from 11 December 2027.
Product-readiness examples support preparation for those broader requirements. A readiness result does not declare conformity. Primary sources and the assessment version are provided on each situation page.