BizNavi Hubログイン

Post-market change

CRA 実質的変更チェッカー

EU市場への上市後の変更が、符号化済みの第3条(30)の条件で、実質的変更ではなさそうか、あり得るか、ありそうかを見ます。

What this checker does

セキュリティ更新、機能追加、新しいインターフェース、修理など、一つの上市後変更をCyber Resilience Actのsubstantial modificationの考え方で見ます。評価済みの意図された目的が変わるか、Annex I Part Iの必須サイバーセキュリティ要件への適合に影響するかです。24時間・72時間の報告期限は計算しません。

Examples it can separate

  • A security update that only reduces risk, with purpose, hazard, risk increase, and Annex I unchanged.
  • A visual enhancement, pictogram, or interface language that does not change the original function or the risk.
  • A feature update that changes original functions, product type, or performance, or that increases risk.
  • A new input, API, or interface that creates a new attack surface on a version made available.
  • Repair, refurbishment, or maintenance that keeps purpose, function, and risk the same.

Who should use it

更新やハードウェア変更の前に、符号化された要因がどれかは製品セキュリティ、ファームウェア、適合性の担当者が確認できます。最初の上市後フラグは既存のlifecycle画面、インシデントの時計は報告ツールを使います。

How it works

変更種別と、上市、目的、機能、性能、リスク、ハザード、攻撃面、当初評価で予見されていたか、更新版が市場にあるか、Annex I Part Iを、はい・いいえ・不明から選びます。結果は一つで、発火した要因を示します。結果を変える不明はレビューのままです。

How to read the result

実質的変更ではなさそう、は符号化した条件のセキュリティ更新、軽微な画面変更、目的・機能・リスクが変わらない修理・改修・保守です。あり得る、は市場に出た版の新しい攻撃面、または機能変更の指標が一つです。ありそう、は目的変更、Annex I Part Iへの影響、機能指標が二つ以上、リスクが増えた新しいインターフェース、予見されていなかったリスクまたはハザードの増加です。範囲外はまだ上市していない製品です。レビューは決定に必要な事実が無いか、組み合わせが未符号化です。

Official sources

リンクは第3条(30)、前文38–42、第21・22・26・32条に使う規則(EU) 2024/2847です。2026年7月27日の欧州委員会実装ガイダンスは、このrulesetの見直し契機です。URLがソース一覧に無いため、ここにはリンクしません。

Limitations

これは実務の確認用で、法律助言ではありません。結果は入力した事実によります。委員会ガイダンス、整合規格、実施文書で当てはまりは変わり得ます。適合判断の前に最新のEU公式資料を確認してください。適合や適用除外は証明しません。

Questions

Is a security update a substantial modification?

A security update that only decreases cybersecurity risk, without a purpose change, a hazard change, a risk increase, or an Annex I Part I effect, is treated as likely not substantial on this screen.

How is this different from the lifecycle modification screen?

The lifecycle screen sends a post-market software or hardware change to review. This checker separates security updates, interface changes, feature updates, new interfaces, and repair using the encoded Article 3(30) conditions.

Does a feature update always require a new conformity assessment?

No. A feature update can be possible or likely substantial when the encoded indicators match. This screen does not decide that conformity assessment must be repeated.

What if a fact is unknown?

A fact that would change the result stays on review. The screen does not fill the gap.