The situation
A manufacturer adds remote administration to a controller previously managed locally. New authentication, network exposure and maintenance paths may affect the earlier assessment. A documented finding of changed compliance and an unresolved finding should lead to different next actions.
Facts that change the answer
- Does remote access affect compliance with an essential cybersecurity requirement?
- Does it change the assessed intended purpose?
- Is the product-wide security effect documented?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Manufacturer records a relevant compliance effect
Hypothetical example 1
Key facts in this example
- The change affects compliance with an applicable essential cybersecurity requirement
- yes
- Effect on the nature or level of cybersecurity risk
- changes hazard or increases risk
All recorded assumptions (10)
- Product with digital elements
- Hypothetical example product
- Physical or software change being assessed
- Add remote administration to a previously local controller
- The product was already placed on the Union market before this change
- Yes
- Person responsible for the change
- original manufacturer
- The modified product is made available on the Union market
- yes
- The change affects compliance with an applicable essential cybersecurity requirement
- yes
- The change modifies the intended purpose for which the product’s conformity was assessed
- no
- The change and its cybersecurity effects were foreseen in the initial risk assessment
- yes
- Effect on the nature or level of cybersecurity risk
- changes hazard or increases risk
- The affected part of the product and any product-wide cybersecurity impact are documented
- Yes
Remote-access security effect remains uncertain
Hypothetical example 2
Key facts in this example
- The change affects compliance with an applicable essential cybersecurity requirement
- uncertain
- Effect on the nature or level of cybersecurity risk
- uncertain
All recorded assumptions (10)
- Product with digital elements
- Hypothetical example product
- Physical or software change being assessed
- Add remote administration to a previously local controller
- The product was already placed on the Union market before this change
- Yes
- Person responsible for the change
- original manufacturer
- The modified product is made available on the Union market
- yes
- The change affects compliance with an applicable essential cybersecurity requirement
- uncertain
- The change modifies the intended purpose for which the product’s conformity was assessed
- no
- The change and its cybersecurity effects were foreseen in the initial risk assessment
- yes
- Effect on the nature or level of cybersecurity risk
- uncertain
- The affected part of the product and any product-wide cybersecurity impact are documented
- Yes
Evaluated on 2026-09-13 using EU Cyber Resilience Act substantial-modification determination, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Before-and-after interface and permission map
- Updated risk assessment and test results
- Change owner, affected releases and scope rationale
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Resolve uncertainty before treating the release as an ordinary update. When the substantial-modification test is met, plan the resulting conformity reassessment.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Articles 3(30), 13, 14, 21 and 22; recitals 39–41
- European Commission CRA implementation guidance (2026)Section 4 — substantial modifications and their consequences
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.