Chapter II - OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
22

Article 22

Other cases in which obligations of manufacturers apply

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

(1)

A natural or legal person, other than the manufacturer, the importer or the distributor, that carries out a substantial modification of a product with digital elements and makes that product available on the market, shall be considered to be a manufacturer for the purposes of this Regulation.

(2)

The person referred to in paragraph 1 of this Article shall be subject to the obligations set out in Articles 13 and 14 for the part of the product with digital elements that is affected by the substantial modification or, if the substantial modification has an impact on the cybersecurity of the product with digital elements as a whole, for the entire product.

European Commission Interpretation

Guidance of 27 July 2026

The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.

Section 4.4Consequences of a substantial modification

A substantially modified product made available on the market counts as newly placed on the market. A third party carrying out a substantial modification becomes the manufacturer (Arts. 21/22) — but only for the modified part where the modification does not affect the product's cybersecurity as a whole. The original manufacturer may reuse documentation and tests for unchanged parts.

Key takeaways

  • Distinguish integration: assembling components into a new product of one's own makes the integrator a regular manufacturer of the whole product — not a substantial modifier of others' products (Example 51).
  • Legacy products: a substantial modification after 11 December 2027 of a product placed on the market before that date makes the modifier its manufacturer (Art. 69(2)) — with obligations limited to the modified parts as long as the product's overall cybersecurity is unaffected.
  • The original manufacturer's obligations for the original product (vulnerability handling, compliance of unchanged parts) continue to apply.
  • Conformity assessment focuses on the modified parts; existing tests and documentation may be reused for unchanged parts.

In practice

Separate two cases cleanly: if you substantially modify someone else's marketed product, you take on manufacturer obligations — but only for the modified part, as long as the product's overall cybersecurity is unaffected. If instead you assemble components into a product of your own, you are the regular manufacturer of the whole product. Existing tests and documentation for unchanged parts may be reused.

Section in the guidance overview
Browse all guidance chapters

EU Commission Guidance (C(2026) 5252 final)The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.

Related Recitals

(1)

CRA updates by email

Deadlines, official guidance, and myth-busting fact-checks on the Cyber Resilience Act — compact in our newsletter.

View newsletters

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex