Loading the latest actively exploited vulnerabilities…Powered by Achilles

CRA Dossier

Downstream Post-Market Modifications and Break-Glass Agreements

by Daniel Thompson-Yvetot

An emergency fix to a product you do not manufacture can assign "manufacturer" obligations and reporting duties under the Cyber Resilience Act. This dossier maps which post-market modifications and break-glass actions cross that line, and how to agree who carries the obligation before an incident forces the answer.

← Back to shop

Written for product security, compliance and engineering teams handling post-market fixes on someone else's product.

Why it matters

Under the CRA, a substantial modification does not have to come from the original manufacturer to trigger manufacturer obligations.

Get an emergency fix wrong and there are two ways to lose: a modification that makes you responsible for the affected part under CRA Articles 13 and 14 without the technical documentation needed to demonstrate compliance, or a necessary security fix that is delayed because nobody knows who would assume the resulting manufacturer obligations, leaving an exploited vulnerability live.

This dossier gives you the CRA substantial-modification test to tell the two apart, and the break-glass agreement structure that lets a team act without guessing.

What is inside

  • The legal basis for downstream substantial modification in CRA Articles 3, 13, 14 and 22, and Annex I.
  • The four-factor test (new threat vectors, new attack scenarios, changed likelihood, changed impact) applied to four common emergency actions, from a security patch that changes nothing to forking a build and redistributing it.
  • The “making available on the market” gate that keeps a purely internal fix outside Article 22, and why most integrator and managed-service scenarios do not qualify as internal.
  • What CRA manufacturer obligations transfer to a modifier once Article 22 engages, and what the original manufacturer keeps.
  • The six components a CRA break-glass agreement needs.
  • The 24-hour, 72-hour and 14-day Article 14 notification deadlines and the applicable final-report deadline, which apply from 11 September 2026.
  • Six recommended actions, including naming the responsible CRA Article 14 reporting entity in advance.

Who is it for

Product security, compliance and engineering teams handling post-market fixes on someone else’s product.

Written by Daniel Thompson-Yvetot (Aug ‘26 Rev), against the CRA and the Commission’s draft guidance on substantial modification (9 June 2026).

Basis. CRA Articles 3, 13, 14, 22 and Annex I

Reference: link to follow

Continue exploring CRA reporting and modification

Explore our related dossiers for practical analysis of other Cyber Resilience Act requirements and compliance topics.

Explore related dossiers

If you need advice tailored to your product, reporting process or compliance obligations, our CRA experts can help you identify the appropriate next steps.

Contact a CRA expert