The situation
A monitoring device receives software that lets it command connected machinery. The manufacturer documents a new control purpose and changed failure consequences. Compare that post-market change with a design decision made before the product was first placed on the market.
Facts that change the answer
- Was the product already placed on the Union market?
- Does the new control function change the assessed intended purpose?
- Which parts of the earlier assessment need to be revisited?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Monitoring becomes control after market placement
Hypothetical example 1
Key facts in this example
- Physical or software change being assessed
- Add command capability to an existing monitoring device
- The product was already placed on the Union market before this change
- Yes
- Effect on the nature or level of cybersecurity risk
- changes hazard or increases risk
All recorded assumptions (10)
- Product with digital elements
- Hypothetical example product
- Physical or software change being assessed
- Add command capability to an existing monitoring device
- The product was already placed on the Union market before this change
- Yes
- Person responsible for the change
- original manufacturer
- The modified product is made available on the Union market
- yes
- The change affects compliance with an applicable essential cybersecurity requirement
- no
- The change modifies the intended purpose for which the product’s conformity was assessed
- yes
- The change and its cybersecurity effects were foreseen in the initial risk assessment
- yes
- Effect on the nature or level of cybersecurity risk
- changes hazard or increases risk
- The affected part of the product and any product-wide cybersecurity impact are documented
- Yes
New purpose assessed before first market placement
Hypothetical example 2
Key facts in this example
- Physical or software change being assessed
- Add control capability during product development
- The product was already placed on the Union market before this change
- No
- Effect on the nature or level of cybersecurity risk
- decreases risk only
All recorded assumptions (10)
- Product with digital elements
- Hypothetical example product
- Physical or software change being assessed
- Add control capability during product development
- The product was already placed on the Union market before this change
- No
- Person responsible for the change
- original manufacturer
- The modified product is made available on the Union market
- yes
- The change affects compliance with an applicable essential cybersecurity requirement
- no
- The change modifies the intended purpose for which the product’s conformity was assessed
- yes
- The change and its cybersecurity effects were foreseen in the initial risk assessment
- yes
- Effect on the nature or level of cybersecurity risk
- decreases risk only
- The affected part of the product and any product-wide cybersecurity impact are documented
- Yes
Evaluated on 2026-09-13 using EU Cyber Resilience Act substantial-modification determination, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Original and revised intended-purpose statements
- Placement and release history
- Control-function risk analysis and change-scope record
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Preserve the old assessment and record the changed purpose. A pre-market design change still needs conformity work but is not a post-market modification.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Articles 3(30), 13, 14, 21 and 22; recitals 39–41
- European Commission CRA implementation guidance (2026)Section 4 — substantial modifications and their consequences
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.