CRA Dossier
Downstream Post-Market Modifications and Break-Glass Agreements
An emergency fix to a product you do not manufacture can assign "manufacturer" obligations and reporting duties under the Cyber Resilience Act. This dossier maps which post-market modifications and break-glass actions cross that line, and how to agree who carries the obligation before an incident forces the answer.
Written for product security, compliance and engineering teams handling post-market fixes on someone else's product.
Why it matters
Under the CRA, a substantial modification does not have to come from the original manufacturer to trigger manufacturer obligations.
Get an emergency fix wrong and there are two ways to lose: a modification that makes you responsible for the affected part under CRA Articles 13 and 14 without the technical documentation needed to demonstrate compliance, or a necessary security fix that is delayed because nobody knows who would assume the resulting manufacturer obligations, leaving an exploited vulnerability live.
This dossier gives you the CRA substantial-modification test to tell the two apart, and the break-glass agreement structure that lets a team act without guessing.
What is inside
- The legal basis for downstream substantial modification in CRA Articles 3, 13, 14 and 22, and Annex I.
- The four-factor test (new threat vectors, new attack scenarios, changed likelihood, changed impact) applied to four common emergency actions, from a security patch that changes nothing to forking a build and redistributing it.
- The “making available on the market” gate that keeps a purely internal fix outside Article 22, and why most integrator and managed-service scenarios do not qualify as internal.
- What CRA manufacturer obligations transfer to a modifier once Article 22 engages, and what the original manufacturer keeps.
- The six components a CRA break-glass agreement needs.
- The 24-hour, 72-hour and 14-day Article 14 notification deadlines and the applicable final-report deadline, which apply from 11 September 2026.
- Six recommended actions, including naming the responsible CRA Article 14 reporting entity in advance.
Who is it for
Product security, compliance and engineering teams handling post-market fixes on someone else’s product.
Written by Daniel Thompson-Yvetot (Aug ‘26 Rev), against the CRA and the Commission’s draft guidance on substantial modification (9 June 2026).
