The situation
A distributor adds a new operational function to a manufacturer’s firmware and sells the modified equipment. Compare that with a non-manufacturer modifying a unit without making the modified product available. The resulting role assessment depends on both parts of the facts.
Facts that change the answer
- Who is responsible for the change?
- Does it meet the substantial-modification test?
- Is the modified product made available on the Union market?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Distributor supplies firmware with a new purpose
Hypothetical example 1
A person other than the original manufacturer who substantially modifies and makes the product available is treated as a manufacturer for the affected part, or the whole product where the cybersecurity impact is product-wide.(CRA Articles 21–22)
Key facts in this example
- Physical or software change being assessed
- Distributor adds a new product function and supplies the modified device
- Person responsible for the change
- distributor
- The modified product is made available on the Union market
- yes
All recorded assumptions (10)
- Product with digital elements
- Hypothetical example product
- Physical or software change being assessed
- Distributor adds a new product function and supplies the modified device
- The product was already placed on the Union market before this change
- Yes
- Person responsible for the change
- distributor
- The modified product is made available on the Union market
- yes
- The change affects compliance with an applicable essential cybersecurity requirement
- no
- The change modifies the intended purpose for which the product’s conformity was assessed
- yes
- The change and its cybersecurity effects were foreseen in the initial risk assessment
- yes
- Effect on the nature or level of cybersecurity risk
- decreases risk only
- The affected part of the product and any product-wide cybersecurity impact are documented
- Yes
Non-manufacturer does not supply the modified unit
Hypothetical example 2
Key facts in this example
- Physical or software change being assessed
- Hypothetical security update to a supplied product
- Person responsible for the change
- user or other person
- The modified product is made available on the Union market
- no
All recorded assumptions (10)
- Product with digital elements
- Hypothetical example product
- Physical or software change being assessed
- Hypothetical security update to a supplied product
- The product was already placed on the Union market before this change
- Yes
- Person responsible for the change
- user or other person
- The modified product is made available on the Union market
- no
- The change affects compliance with an applicable essential cybersecurity requirement
- no
- The change modifies the intended purpose for which the product’s conformity was assessed
- yes
- The change and its cybersecurity effects were foreseen in the initial risk assessment
- yes
- Effect on the nature or level of cybersecurity risk
- decreases risk only
- The affected part of the product and any product-wide cybersecurity impact are documented
- Yes
Evaluated on 2026-09-13 using EU Cyber Resilience Act substantial-modification determination, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Modification and intended-purpose record
- Identity of the modifying person
- Distribution facts and responsibility for conformity review
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Confirm the responsible economic operator before shipping the modified product. Do not assume that the original manufacturer’s evidence covers the new version.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Articles 3(30), 13, 14, 21 and 22; recitals 39–41
- European Commission CRA implementation guidance (2026)Section 4 — substantial modifications and their consequences
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.