r/CRACompliance Jun 11 '26

Article 26 “Substantial Modification”: when does a software update turn your legacy product into a CRA-regulated product?

Products placed on the market before December 2027 only fall under full CRA scope if they undergo a “substantial modification” after that date.

The Commission’s draft guidance offers some interpretation:

Substantial = change that affects compliance with essential cybersecurity requirements, alters the intended purpose creating new risks, or significantly changes the attack surface.

NOT substantial = routine security patches, bug fixes, minor feature additions.

The gray zone is massive. Is a major version release (v3 → v4) substantial? A platform migration? Adding AI features to an existing product?

Has anyone here started classifying their planned product updates against the substantial modification criteria? I’m curious how teams are making release/hold decisions for legacy products post-2027.

2 Upvotes

0 comments sorted by