The situation
A maintenance supplier replaces a failed network controller. Procurement initially describes it as the same spare, but a new radio and remotely managed firmware may make that description inaccurate. Compare the actual specifications before relying on the spare-part boundary.
Facts that change the answer
- Does the replacement have the same specifications as the original component?
- Has connectivity, firmware behaviour or intended use changed?
- Who supplies the replacement and under whose name?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Replacement with identical specifications
Hypothetical example 1
Key facts in this example
- Sector-specific or public-purpose position
- identical spare part same specifications
All recorded assumptions (8)
- Product, software or service being assessed
- Hypothetical example product
- How the assessed offering reaches the user
- hardware or software component supplied separately
- The intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network
- yes
- The offering is supplied for distribution or use on the Union market
- yes
- The supply occurs in the course of a commercial activity
- yes
- Sector-specific or public-purpose position
- identical spare part same specifications
- Free and open-source software position
- not free and open source software
- Assessed role in the supply chain
- manufacturer under own name or trademark
Redesigned connected component
Hypothetical example 2
Key facts in this example
- Sector-specific or public-purpose position
- no exclusion identified
All recorded assumptions (8)
- Product, software or service being assessed
- Hypothetical example product
- How the assessed offering reaches the user
- hardware or software component supplied separately
- The intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network
- yes
- The offering is supplied for distribution or use on the Union market
- yes
- The supply occurs in the course of a commercial activity
- yes
- Sector-specific or public-purpose position
- no exclusion identified
- Free and open-source software position
- not free and open source software
- Assessed role in the supply chain
- manufacturer under own name or trademark
Evaluated on 2026-09-13 using EU Cyber Resilience Act scope and economic-operator determination, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Original and replacement specification comparison
- Firmware and component revision identifiers
- Reasoned spare-part classification and supplier identity
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Keep the comparison attached to the product boundary. If the specifications differ, continue through normal scope and classification checks.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Articles 2, 3, 18 and 21–24; recitals 11–19
- European Commission CRA implementation guidance (2026)Sections 2, 3 and 8 — scope, free and open-source software, and remote data processing
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.