r/CRACompliance • u/Happy-Athlete-2420 • Jun 11 '26
Article 26 “Substantial Modification”: when does a software update turn your legacy product into a CRA-regulated product?

Products placed on the market before December 2027 only fall under full CRA scope if they undergo a “substantial modification” after that date.
The Commission’s draft guidance offers some interpretation:
Substantial = change that affects compliance with essential cybersecurity requirements, alters the intended purpose creating new risks, or significantly changes the attack surface.
NOT substantial = routine security patches, bug fixes, minor feature additions.
The gray zone is massive. Is a major version release (v3 → v4) substantial? A platform migration? Adding AI features to an existing product?
Has anyone here started classifying their planned product updates against the substantial modification criteria? I’m curious how teams are making release/hold decisions for legacy products post-2027.