BizNavi HubSign in

Post-market change

CRA Substantial Modification Checker

See whether a change after placing a product on the EU market is likely not substantial, possibly substantial, or likely substantial under the encoded Article 3(30) conditions.

What this checker does

It screens one change, such as a security update, a feature update, a new interface, or a repair, against the Cyber Resilience Act idea of a substantial modification. That means a change after placing on the market that affects Annex I Part I essential cybersecurity requirements or modifies the intended purpose that was assessed. It does not calculate a 24-hour or 72-hour report.

Examples it can separate

  • A security update that only reduces risk, with purpose, hazard, risk increase, and Annex I unchanged.
  • A visual enhancement, pictogram, or interface language that does not change the original function or the risk.
  • A feature update that changes original functions, product type, or performance, or that increases risk.
  • A new input, API, or interface that creates a new attack surface on a version made available.
  • Repair, refurbishment, or maintenance that keeps purpose, function, and risk the same.

Who should use it

Product security, firmware, and conformity teams can use it when an update or hardware change is ready and they need to see which encoded factor is present. Use the lifecycle screen for a first post-market flag, and the reporting tools for incident clocks.

How it works

Choose a closed change type and yes, no, or unknown for market status, purpose, function, performance, risk, hazard, attack surface, whether the original assessment foresaw the change, whether the updated version is on the market, and Annex I Part I. The screen returns one bounded result and the factors that fired. Unknown facts that would change the result stay on review.

How to read the result

Likely not substantial covers a security update, a minor interface change, or unchanged repair, refurbishment, or maintenance under the encoded conditions. Possible substantial means a new attack surface or one feature-change indicator on a version made available. Likely substantial covers a purpose change, an Annex I Part I effect, two feature indicators, a new interface with increased risk, or an unforeseen rise in risk or hazard. Out of scope means the product is not yet on the market. Review means a deciding fact is missing or the combination is not encoded.

Official sources

The links are the Regulation (EU) 2024/2847 text used for Article 3(30), Recitals 38–42, and Articles 21, 22, 26, and 32. The Commission implementation guidance published on 27 July 2026 is a review trigger for this ruleset. Its URL is not in the source registry, so it is not linked here.

Limitations

This is an operational screening tool, not legal advice. The result depends on the facts entered. Commission guidance, harmonised standards, and implementing material may change applicability. Verify the latest official EU sources before a compliance decision. The screen does not certify conformity or an exemption.

Questions

Is a security update a substantial modification?

A security update that only decreases cybersecurity risk, without a purpose change, a hazard change, a risk increase, or an Annex I Part I effect, is treated as likely not substantial on this screen.

How is this different from the lifecycle modification screen?

The lifecycle screen sends a post-market software or hardware change to review. This checker separates security updates, interface changes, feature updates, new interfaces, and repair using the encoded Article 3(30) conditions.

Does a feature update always require a new conformity assessment?

No. A feature update can be possible or likely substantial when the encoded indicators match. This screen does not decide that conformity assessment must be repeated.

What if a fact is unknown?

A fact that would change the result stays on review. The screen does not fill the gap.