Kilde › Guides › CRA › Substantial modification: the rule tha…

Substantial modification: the rule that decides when your old products re-enter the CRA

Current to 26 August 2026 · updates land in the changelog.

Two transitional rules divide every installed base, and conflating them produces both false alarm and false comfort. Article 69(2): products placed on the market before 11 December 2027 face the CRA's full requirements only if substantially modified after that date. Article 69(3): the Article 14 reporting duty applies to them regardless, from 11 September 2026.

What the split means in practice

Your 2019 device fleet: on the reporting clock from September 2026, but not retroactively subject to the essential requirements, CE marking or documentation duties — until a substantial modification after full application re-places it. The concept (defined at Article 3(30)) is the hinge: modify substantially, and the product is treated as newly placed, full obligations attached.

The analysis worth writing down

The exposed pattern is the long-lived product line that ships “the same product” for years while its firmware, feature set and connectivity evolve. For each line, the defensible artifact is a written position: what changes are maintenance (updates addressing security, fixes within the assessed design) versus what would constitute substantial modification — reviewed against the Commission's application guidance, which addresses the boundary. Writing it down before the December 2027 line matters because the analysis determines which roadmap items silently carry a full CRA program with them.

Three planning consequences

Related guides

Quick answers

Do products sold before 2027 have to meet the CRA's full requirements?
Only upon substantial modification after full application (Article 69(2)). The Article 14 reporting duty, by contrast, covers them regardless from 11 September 2026 (Article 69(3)).
Does a security update count as substantial modification?
The regime is built to encourage patching — updates addressing vulnerabilities are the safe lane, while significant feature or design changes are where the substantial-modification analysis (Art 3(30)) needs a written position.
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com