As is the case for physical repairs or modifications, a product with digital elements should be considered to be substantially modified by a software change where the software update modifies the intended purpose of that product and those changes were not foreseen by the manufacturer in the initial risk assessment, or where the nature of the hazard has changed or the level of cybersecurity risk has increased because of the software update, and the updated version of the product is made available on the market. Where a security update which is designed to decrease the level of cybersecurity risk of a product with digital elements does not modify the intended purpose of a product with digital elements, it is not considered to be a substantial modification. This usually includes situations where a security update entails only minor adjustments of the source code. For example, this could be the case where a security update addresses a known vulnerability, including by modifying functions or the performance of a product with digital elements for the sole purpose of decreasing the level of cybersecurity risk. Similarly, a minor functionality update, such as a visual enhancement or the addition of new pictograms or languages to the user interface, should not generally be considered to be a substantial modification. Conversely, where a feature update modifies the original intended functions or the type or performance of a product with digital elements and meets the above criteria, it should be considered to be a substantial modification, as the addition of new features typically leads to a broader attack surface, thereby increasing the cybersecurity risk. For example, this could be the case where a new input element is added to an application, requiring the manufacturer to ensure adequate input validation. In assessing whether a feature update is considered to be a substantial modification it is not relevant whether it is provided as a separate update or in combination with a security update. The Commission should issue guidance on how to determine what constitutes a substantial modification.
Recital 39
Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026
European Commission Interpretation
Guidance of 27 July 2026The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.
Section 4.3Software updates as substantial modifications
The yardstick is not the scale of the change but its effect on the risk profile: where an update alters the assessed intended purpose or introduces new risks not covered by the risk assessment, it is a substantial modification. Security updates generally are not. Four assessment criteria (para. 110) structure the case-by-case analysis.
Key takeaways
- Features already anticipated and assessed in the original risk assessment do not trigger a substantial modification — nor does later activation of assessed, dormant functionality (Examples 42/43).
- Even small features can be substantial: a 'remember me' login storing tokens locally introduces new risks (token theft, session hijacking — Example 44).
- Security updates are substantial only exceptionally — e.g. where they fundamentally alter the intended purpose, data flows or dependency structure (Examples 49/50: local encryption becomes a cloud service; external key management replaces internal).
- Assessment criteria (para. 110): new threat vectors, new attack scenarios, changed likelihood, changed impact of known scenarios.
- Regardless of classification: the risk assessment and technical documentation must be kept continuously up to date (Art. 13(7), Art. 31(2)).
In practice
Anchor a fixed review question with a documented answer in your release process: does this update introduce new threat vectors or attack scenarios, or change the likelihood/impact of known ones? No, and covered by the risk assessment → no new placing on the market. Yes → update the risk assessment and check whether a new conformity assessment is due.
EU Commission Guidance (C(2026) 5252 final) — The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.
Related Articles
(1)This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex