Your product passed compliance testing. What happens when you change it?
A product goes through verification and compliance testing. The CE requirements are addressed, perhaps UL certification is completed, the technical documentation is prepared, and the product is released.
Then normal development carries on. A component goes obsolete and engineering picks a replacement. A PCB is revised. Firmware is updated. A supplier changes. A different material goes in. Production moves to another site.
At that point the most important question is usually no longer whether the new solution works. It is whether the change affects the basis on which you demonstrated compliance in the first place.
Those are not the same question, and a team focused on the first can quietly invalidate the answer to the second without noticing.
CE and UL both force you to confront this, but they do it in genuinely different ways, and the difference matters for how you handle change.
For CE marking, no fixed percentage makes a change "significant"
The European Commission's Blue Guide is clear that modifications have to be assessed case by case, not against a threshold. For a product modified after it has been put into service, it sets out the circumstances in which the modified product must be treated as a new product: where the original performance, purpose or type is changed beyond what the original risk assessment foresaw; where the nature of the hazard changes or the level of risk increases under the relevant EU legislation; and where the product is then made available or put into service under legislation that covers it. If a modification produces what counts as a new product, conformity with the applicable requirements has to be reassessed, and whoever carried out the substantial modification takes on the corresponding manufacturer obligations.
That gives you a far better engineering question than whether the part number changed. For any relevant change, I would ask:
Does it change the intended use or performance?
Does it introduce a new hazard?
Does it increase an existing risk?
Does it affect an essential requirement of the applicable legislation?
Does it invalidate or weaken any evidence you previously relied on to demonstrate conformity?
The point of the questions is that the same change can be trivial or decisive depending on what it touches. A different enclosure material might change fire behaviour. A new power supply could affect electrical safety or EMC.
A PCB revision could shift creepage and clearance, EMC or thermal behaviour. Firmware could alter a safety-related function. A radio-module change could undermine your RED evidence.
So the answer is rarely "repeat the entire conformity assessment". It is "work out what the change actually affects, and revisit the evidence that covers it".
UL works the other way around
With a UL Certified product, the certified construction itself is what matters. UL's Follow-Up Services exist precisely to verify that products still carrying the UL Mark remain consistent with the construction and requirements that were originally evaluated, and UL expects the materials and components to correspond with what is described in the Follow-Up Services Procedure. For that reason I would not let an engineering team decide on its own that a change to a UL Certified construction is "small enough" to ignore.
UL's own guidance is that construction changes should be submitted for UL acceptance before they are implemented on products bearing the Mark. UL then evaluates the change and, if it is accepted, updates the Follow-Up Services Procedure. That is not the same as retesting everything: UL decides whether additional testing, examination or evaluation is actually needed.
There are also product-specific rules worth knowing. UL's AV/ICT guidance, for instance, illustrates what counts as a significant change in that context: a new technology or feature involving safety-critical components, such as wireless power transfer, a new voltage range, a different method of mains connection, or a new installation environment like outdoor use. An alternate component on its own is generally not treated as a significant change in that particular process.
This is exactly why I would resist a blanket internal rule in either direction. "Component change means retest" and "minor change means no action" are both wrong often enough to be dangerous. The judgement has to follow what the change touches, not the size of the change on paper.
Put the compliance question inside the change process you already have
The practical answer is not another standalone compliance process running alongside engineering. It is a single decision point built into the engineering change control the team already uses. When a relevant product change comes through, it has to clear one question before release: does this affect the basis of our compliance, and if so, what do we do about it?
The chain I want visible for each relevant change is:
What changed → which requirement or risk it may affect → which existing compliance evidence covers that → is that evidence still valid → is further analysis, testing or certification-body involvement needed → who approves release
The output can be very short. Sometimes it is:
No compliance impact. Existing evidence remains valid. Rationale recorded.
Sometimes it is:
Potential EMC impact. Partial testing required before release.
Sometimes, for a UL construction:
UL Certified construction affected. Submit the revision to UL before implementing it on UL-marked production.
And occasionally, at the far end:
The modification changes the product enough that a new conformity assessment is required.
Whatever the outcome, that decision and its rationale become part of the technical product record. Over time you build a documented history of why each change was, or was not, a compliance event, and that history is worth a great deal the next time someone has to show how you know the product is still compliant.
Compliance is a lifecycle process, not a certification event
This is what I mean when I say that product compliance is not a one-time certification event but a lifecycle process. The evaluation that earns you the CE marking or the UL listing is a milestone, not the finish line. From then on, every obsolete component, PCB revision, firmware update, supplier switch and site move is a quiet test of whether the basis of that compliance still holds.
Getting a product through CE or UL evaluation is one problem. Keeping it compliant while engineering, suppliers and production keep changing it is another, and for a scaling hardware company it is usually the harder one. Treating compliance as something you achieved once is how a product that passed every test ends up non-compliant without a single failed test to warn you.
Quality Agency builds the compliance and engineering change controls that keep CE and UL evidence valid through obsolescence, revisions, supplier changes and production moves. The aim is a product that stays compliant as it evolves, not one that was compliant only on the day it was certified.

