What this checker does
It screens one change, such as a security update, a feature update, a new interface, or a repair, against the Cyber Resilience Act idea of a substantial modification. That means a change after placing on the market that affects Annex I Part I essential cybersecurity requirements or modifies the intended purpose that was assessed. It does not calculate a 24-hour or 72-hour report.
Examples it can separate
- A security update that only reduces risk, with purpose, hazard, risk increase, and Annex I unchanged.
- A visual enhancement, pictogram, or interface language that does not change the original function or the risk.
- A feature update that changes original functions, product type, or performance, or that increases risk.
- A new input, API, or interface that creates a new attack surface on a version made available.
- Repair, refurbishment, or maintenance that keeps purpose, function, and risk the same.
Who should use it
Product security, firmware, and conformity teams can use it when an update or hardware change is ready and they need to see which encoded factor is present. Use the lifecycle screen for a first post-market flag, and the reporting tools for incident clocks.
How it works
Choose a closed change type and yes, no, or unknown for market status, purpose, function, performance, risk, hazard, attack surface, whether the original assessment foresaw the change, whether the updated version is on the market, and Annex I Part I. The screen returns one bounded result and the factors that fired. Unknown facts that would change the result stay on review.
How to read the result
Likely not substantial covers a security update, a minor interface change, or unchanged repair, refurbishment, or maintenance under the encoded conditions. Possible substantial means a new attack surface or one feature-change indicator on a version made available. Likely substantial covers a purpose change, an Annex I Part I effect, two feature indicators, a new interface with increased risk, or an unforeseen rise in risk or hazard. Out of scope means the product is not yet on the market. Review means a deciding fact is missing or the combination is not encoded.
Official sources
- Regulation (EU) 2024/2847 Article 3(30)
- Regulation (EU) 2024/2847 Recitals 38–42
- Regulation (EU) 2024/2847 Article 21
- Regulation (EU) 2024/2847 Article 22
- Regulation (EU) 2024/2847 Article 26
- Regulation (EU) 2024/2847 Article 32
The links are the Regulation (EU) 2024/2847 text used for Article 3(30), Recitals 38–42, and Articles 21, 22, 26, and 32. The Commission implementation guidance published on 27 July 2026 is a review trigger for this ruleset. Its URL is not in the source registry, so it is not linked here.
Limitations
This is an operational screening tool, not legal advice. The result depends on the facts entered. Commission guidance, harmonised standards, and implementing material may change applicability. Verify the latest official EU sources before a compliance decision. The screen does not certify conformity or an exemption.