When a Quick Patch Makes You the Manufacturer: The Hidden Trap in Europe's Cyber Rules
Published on 10/06/2026 at 17:32 | Editorial boerse-global.de
A managed service provider spots a critical flaw in a third-party application at 2 a.m. The vendor's fix is weeks away. Patching it in-house seems like the responsible move — yet under European law, that single act of diligence can quietly transfer an entire catalogue of legal duties onto the provider's shoulders.
That scenario sits at the heart of a new dossier from Comply.Land titled "Downstream Post-Market Modification and Break-Glass Agreements." Written by Daniel Thompson-Yvetot, the paper examines when downstream players — system integrators, managed service providers, software resellers — cross the line into becoming manufacturers themselves under Article 22 of the EU's Cyber Resilience Act (CRA).
Emergency fixes carry legal weight
Everyday operations frequently push IT service firms into a corner: a severe security hole needs closing now, and the original vendor is not moving fast enough. Once an emergency patch or software modification on a third-party product amounts to a substantial change, Article 22 kicks in. The full set of obligations that once belonged to the primary manufacturer then lands entirely on the company that made the alteration.
Comply.Land's answer is prevention. The dossier, the third instalment in its ongoing "CRA Fringe" series, urges IT players to sign so-called break-glass agreements well before any incident occurs. Such contracts set out in advance how emergency interventions may proceed and which party carries liability for downstream changes.
A regulatory calendar with hard dates
The analysis also places these obligations within the broader European timeline. The Cyber Resilience Act has been in force since 10 December 2024, with a 36-month transition period attached. The first milestones concern conformity assessment bodies, whose notification is scheduled from 11 June 2026.
Reporting duties follow: from 11 September 2026, actively exploited vulnerabilities and serious security incidents must be reported within 24 hours to the EU Agency for Cybersecurity (ENISA) and the relevant national computer emergency response teams.
By 9 December 2026, the implementation deadline for the European product liability directive expires — a framework that introduces strict, no-fault liability for defective software.
Full application of the CRA, including complete technical documentation, mandatory CE marking and the requirement to appoint an EU representative, takes effect from 11 December 2027.
Drawing the line in the supply chain
For companies along the software supply chain, the distinction between routine maintenance and manufacturer-equivalent product modification is becoming urgent. Modify systems without contractual cover, and integrators and resellers face the full weight of regulatory proof requirements plus potential liability claims under the new product liability rules. Transparent processes and contractually defined emergency protocols are turning into a core element of operational risk management.
