Product modifications

Does changing a monitoring product into a controller require CRA reassessment?

A change to the intended purpose used in the conformity assessment can meet the substantial-modification test. An unchanged enclosure or product name does not settle the question.

Prepared by CRA Operations · Updated 2026-09-13 · Hypothetical worked examples

The situation

A monitoring device receives software that lets it command connected machinery. The manufacturer documents a new control purpose and changed failure consequences. Compare that post-market change with a design decision made before the product was first placed on the market.

Facts that change the answer

  • Was the product already placed on the Union market?
  • Does the new control function change the assessed intended purpose?
  • Which parts of the earlier assessment need to be revisited?

Compare the worked results

These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.

Monitoring becomes control after market placement

Hypothetical example 1

Assessment resultsubstantial modification by original manufacturer
Key facts in this example
Physical or software change being assessed
Add command capability to an existing monitoring device
The product was already placed on the Union market before this change
Yes
Effect on the nature or level of cybersecurity risk
changes hazard or increases risk
All recorded assumptions (10)
Product with digital elements
Hypothetical example product
Physical or software change being assessed
Add command capability to an existing monitoring device
The product was already placed on the Union market before this change
Yes
Person responsible for the change
original manufacturer
The modified product is made available on the Union market
yes
The change affects compliance with an applicable essential cybersecurity requirement
no
The change modifies the intended purpose for which the product’s conformity was assessed
yes
The change and its cybersecurity effects were foreseen in the initial risk assessment
yes
Effect on the nature or level of cybersecurity risk
changes hazard or increases risk
The affected part of the product and any product-wide cybersecurity impact are documented
Yes

New purpose assessed before first market placement

Hypothetical example 2

Assessment resultnot a post market modification
Key facts in this example
Physical or software change being assessed
Add control capability during product development
The product was already placed on the Union market before this change
No
Effect on the nature or level of cybersecurity risk
decreases risk only
All recorded assumptions (10)
Product with digital elements
Hypothetical example product
Physical or software change being assessed
Add control capability during product development
The product was already placed on the Union market before this change
No
Person responsible for the change
original manufacturer
The modified product is made available on the Union market
yes
The change affects compliance with an applicable essential cybersecurity requirement
no
The change modifies the intended purpose for which the product’s conformity was assessed
yes
The change and its cybersecurity effects were foreseen in the initial risk assessment
yes
Effect on the nature or level of cybersecurity risk
decreases risk only
The affected part of the product and any product-wide cybersecurity impact are documented
Yes

Evaluated on 2026-09-13 using EU Cyber Resilience Act substantial-modification determination, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.

Evidence to keep

  • Original and revised intended-purpose statements
  • Placement and release history
  • Control-function risk analysis and change-scope record

Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.

Your next step

Preserve the old assessment and record the changed purpose. A pre-market design change still needs conformity work but is not a post-market modification.

Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.

Sources and application dates

Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.

These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.

Related situations