Substantial Modification Assessments
A change to a product after its placing on the market is a substantial modification under CRA Article 3(30) where it affects compliance with the Annex I Part I essential requirements, or changes the intended purpose the product was assessed against. A substantially modified product is newly placed on the market, which means a fresh conformity assessment and its own declared support period.
Commission guidance C(2026) 5252 point 110 turns that definition into four questions. The substantial modification panel on each product records your answers, computes a verdict and keeps the reasoning as a dated decision.
Where to find it
Open a product, then the Monitoring tab. The panel sits above Actions.
The four factors
Answer each as yes, no, or not yet answered. Every answer takes an evidence note.
- Does the update introduce new threat vectors, such as additional interfaces, communication channels, execution environments or external dependencies?
- Does it enable new attack scenarios?
- Does it change the likelihood of previously identified attack scenarios?
- Does it change their potential impact?
Three further questions carry the side conditions. Whether the intended purpose changed, whether the assumptions and mitigations in your risk assessment still hold, and whether the change serves only to reduce cybersecurity risk.
How the verdict is computed
A change of intended purpose is decisive on its own, because it is the second limb of Article 3(30).
Any single positive factor makes the change substantial. Where all four are negative but the risk assessment's assumptions no longer hold, the change is still substantial, because guidance point 111 makes the negative branch cumulative.
Where every decisive question is answered, all four factors are negative, the assumptions hold and the intended purpose is unchanged, the verdict is not substantial.
Leaving any decisive question unanswered gives a verdict of not yet determined, and the panel names what is outstanding. The tool never guesses.
Two things the tool will not do
It does not ask how big the change is. Guidance point 107 turns the test on the adverse impact on the cybersecurity risk profile rather than the scale of the change. There is no lines-changed or files-touched input, and there should never be one. A feature that stores authentication tokens locally is substantial. A large refactor that touches no interface, dependency or data flow is not.
Marking a change as a security update does not settle it. Recital 39 treats security updates as generally not substantial, but that carve-out is conditioned on the update leaving intended purpose and dependency structure alone. Where a security update trips one of the four factors, for example by introducing a third-party key management service, the panel returns substantial and says why.
What happens after a substantial verdict
The product page prompts you to re-derive the support period. Guidance points 133 to 135 are specific that a substantial modification does not by itself reset or extend the period. The question is whether the modification changed the factors that set the expected time in use. See Support Periods.
You can then capture an assessment snapshot with the reason "Substantial modification". That option stays disabled until an unconsumed substantial verdict exists for the product, because the snapshot asserts that the product was newly placed on the market and needs the reasoned determination behind it. The snapshot stores the four-factor reasoning as part of the immutable Annex VII record.
One determination backs one snapshot. Recording a second substantial modification requires running the test again.