My product is already on the market — is it grandfathered under the Cyber Resilience Act?
There is a transitional rule, and it is narrower than the word "grandfathered" suggests.
Products placed on the market before 11 December 2027 are subject to the Regulation only if they are substantially modified after that date [1]. But one duty cuts straight through the transition: Article 14 — reporting actively exploited vulnerabilities and severe incidents — applies to those products regardless [1]. So a legacy product is exempt from the conformity stack until modified, and exempt from the reporting duty never [1] [2].
What "substantially modified" means
A substantial modification is a change after placing on the market that affects the product's compliance with the essential requirements, or that modifies its intended purpose — and the person who substantially modifies a product becomes its manufacturer [3].
For software, this is the load-bearing definition, because software changes constantly. The line the definition draws is not "big release versus small release" but effect: a security patch or a bug fix does not affect compliance with the essential requirements; a new remote-access capability, a change to the security architecture, or a repurposing of the product plausibly does [3]. Every roadmap item on a legacy product should be read against that definition, because the first change that crosses it ends the transitional treatment for the product [3] [1].
The market will not wait for the law
The transitional rule binds regulators, not customers. Purchasers and distributors may ask for conformity evidence on a legacy product anyway, and nothing prevents them preferring vendors who have it [4]. Enterprise procurement already treats supplier security posture as a gating question; expect the declaration and the support-period statement to join that questionnaire before the transitional period ends [4].
What a legacy-product owner should actually do
Three moves, in order of urgency. First, stand up the reporting path now, because that duty applies from 11 September 2026 with 24-hour early-warning deadlines that are unmeetable without preparation [2] [5]. Second, put a substantial-modification check into release planning, so the transition-ending change is a decision rather than an accident [3]. Third, prepare the conformity stack on your own schedule while it is cheap — the transitional rule buys time, and time is only worth something if the work happens inside it [1].
And when you want to ship the big change, the calculus inverts: bundle the compliance work with it, declare, and turn the modification into the moment your product becomes one of the conforming ones customers are starting to ask for [3] [4].
Check where you stand
The checker asks when the product was placed on the market and what you plan to change, and tells you which duties apply now and which arrive with your next substantial modification, with citations.
What to do next
Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.
Sources
- Products placed on the market before 11 December 2027 are subject to the Regulation only if substantially modified after that date; Article 14 applies to them regardless. Art. 69(2)–(3) — EUR-Lex ↩
- Article 14 (reporting obligations of manufacturers) applies from 11 September 2026. Art. 71(2) — EUR-Lex ↩
- Substantial modification: a change after placing on the market affecting compliance with essential requirements or resulting in a modification of the intended purpose; a person who substantially modifies a product becomes its manufacturer. Art. 3(30), Art. 22 — EUR-Lex ↩
- For products already on the market, conformity is not required until substantial modification, but customers and distributors may ask for it; Article 14 applies regardless. Art. 69(2)–(3) — EUR-Lex ↩
- Actively exploited vulnerability: early warning within 24 hours of awareness; notification within 72 hours; final report within 14 days after a corrective or mitigating measure is available. Art. 14(1)–(2) — EUR-Lex ↩
Related
- What are the fines and penalties under the Cyber Resilience Act?
Fines reach EUR 15 million or 2.5% of worldwide annual turnover for breaching the essential requirements or the core manufacturer obligations, and market surveillance authorities can order withdrawal or recall.
- Does the CRA apply to non-EU manufacturers?
Yes. The Regulation follows the product, not the company: making a product available on the EU market commercially puts you in scope wherever you are, with an authorised representative anchoring the paperwork inside the Union.
- Does the CRA require a coordinated vulnerability disclosure policy?
Yes. Every manufacturer must have a coordinated vulnerability disclosure policy in place, a contact address for reports, a single point of contact for users, and a practice of publishing fixed vulnerabilities.
- What are the CRA rules on security updates?
Security updates must be free, timely, securely distributed and accompanied by advisories; consumer products install them automatically by default with an easy opt-out; and the duty runs for the whole declared support period.
CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 10 September 2026 (Facts v2026.09.4). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.