Chapter VIII - TRANSITIONAL AND FINAL PROVISIONS
69

Article 69

Transitional provisions

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

Quick Answer for Manufacturers

Article 69 governs the transition between old and new legal frameworks. Products placed on the market before December 11, 2027 are generally not retroactively covered by the CRA — except in the case of substantial modifications after that date.

This quick answer + FAQ supplements the original legal text with practice-oriented interpretation. Only the original text is legally binding.

(1)

EU type-examination certificates and approval decisions issued regarding cybersecurity requirements for products with digital elements that are subject to Union harmonisation legislation other than this Regulation shall remain valid until 11 June 2028, unless they expire before that date, or unless otherwise specified in such other Union harmonisation legislation, in which case they shall remain valid as referred to in that legislation.

(2)

Products with digital elements that have been placed on the market before 11 December 2027 shall be subject to the requirements set out in this Regulation only if, from that date, those products are subject to a substantial modification.

(3)

By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027.

European Commission Interpretation

Guidance of 27 July 2026

The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.

Section 4.4Consequences of a substantial modification

A substantially modified product made available on the market counts as newly placed on the market. A third party carrying out a substantial modification becomes the manufacturer (Arts. 21/22) — but only for the modified part where the modification does not affect the product's cybersecurity as a whole. The original manufacturer may reuse documentation and tests for unchanged parts.

Key takeaways

  • Distinguish integration: assembling components into a new product of one's own makes the integrator a regular manufacturer of the whole product — not a substantial modifier of others' products (Example 51).
  • Legacy products: a substantial modification after 11 December 2027 of a product placed on the market before that date makes the modifier its manufacturer (Art. 69(2)) — with obligations limited to the modified parts as long as the product's overall cybersecurity is unaffected.
  • The original manufacturer's obligations for the original product (vulnerability handling, compliance of unchanged parts) continue to apply.
  • Conformity assessment focuses on the modified parts; existing tests and documentation may be reused for unchanged parts.

In practice

Separate two cases cleanly: if you substantially modify someone else's marketed product, you take on manufacturer obligations — but only for the modified part, as long as the product's overall cybersecurity is unaffected. If instead you assemble components into a product of your own, you are the regular manufacturer of the whole product. Existing tests and documentation for unchanged parts may be reused.

Section in the guidance overview
Section 9.1Reporting obligations: from 11 Sep 2026, 'becoming aware' and informing users

The Article 14 reporting obligations apply from 11 September 2026 to all products within the CRA's scope — including products placed on the market before 11 December 2027 and products past their support period. 'Becoming aware' means reaching a reasonable degree of certainty after an immediate initial assessment — from that moment the deadlines run (24h early warning, 72h notification, 14 days / 1 month final report).

Key takeaways

  • No retroactive reporting: active exploitation the manufacturer already knew about before 11 Sep 2026 is not reportable; where exploitation only becomes known afterwards, the obligation applies.
  • Third-party components: only an actively exploited vulnerability that is exploitable/exploited in the manufacturer's own product is reportable — otherwise voluntary reporting (Art. 15) plus upstream reporting to the component maintainer (Art. 13(6)).
  • 'Becoming aware' is deliberately aligned with the NIS 2 implementing regulation and the GDPR breach-notification guidelines.
  • Informing users (Art. 14(8)) is risk-based: no indiscriminate disclosure — for sensitive environments, detailed information may be limited to affected users; broader disclosure once fixed, and mandatory disclosure of fixed vulnerabilities under Annex I Part II point (4).
  • Unlike vulnerability handling, the reporting obligations continue to apply after the support period ends.

In practice

Define now who performs the initial assessment of suspected cases and how fast — the 24-hour clock starts at 'reasonable certainty'. The process must be in place by 11 September 2026 and also covers legacy products and products past their support period. Additionally define how you inform users in a risk-based way: affected customers first and targeted, broad disclosure once fixed.

Section in the guidance overview
Section 9.3Interplay with other EU law: vehicles, RED, Machinery Regulation

Vehicle components (Regulation (EU) 2019/2144, Regulation (EU) No 168/2013) are exempt from the CRA where they are exclusively designed, constructed and suitable for integration into such vehicles — generic components sold through open distribution channels fall within the CRA regardless of intended-use statements. EU type-examination certificates covering cybersecurity requirements (e.g. RED Delegated Act, Machinery Regulation) remain usable as evidence of conformity for the covered risks until 11 June 2028 at the latest.

Key takeaways

  • The objective conditions of supply are decisive: sale through general retail/online channels open to the public argues against the vehicle exemption; restricted B2B channels within the automotive supply chain support it.
  • Existing certificates (RED DA, Machinery Regulation Annex III 1.1.9/1.2.1) do not replace the CRA risk assessment — they only serve as evidence for the risks they cover.
  • CRA risks not covered by the certificate (e.g. vulnerability handling processes, data minimisation, attack surface reduction) must be addressed additionally.

In practice

Check your distribution channels: components also sold outside the automotive supply chain (retail, open online shop) fall under the CRA — regardless of what the datasheet says about intended use. Also inventory your RED/Machinery Regulation certificates: they count as CRA evidence only for the risks they cover and until 11 June 2028 at the latest — plan the gap closure now.

Section in the guidance overview
Browse all guidance chapters

EU Commission Guidance (C(2026) 5252 final)The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.

Common Manufacturer Questions

What happens to products on the market before the deadline?

They are generally exempt from retroactive CRA scope. But the vulnerability reporting obligation under Article 14 from September 11, 2026 also applies to these products if actively exploited vulnerabilities exist.

What counts as a 'substantial modification' that triggers the CRA?

A change that affects compliance with the regulation or alters the intended use. Security updates and bug fixes explicitly do not count as substantial modifications. Functional changes or new interfaces do.

Do we need to make all existing products CRA-compliant by December 2027?

No — only if they are placed on the market again after the deadline or undergo a substantial modification. However, for stock sold after December 11, 2027, the CRA does apply — the 'placed on market before deadline' clause does not cover 'made available on the market'.

Related Recitals

(2)

CRA updates by email

Deadlines, official guidance, and myth-busting fact-checks on the Cyber Resilience Act — compact in our newsletter.

View newsletters

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex