My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/482 CHAPTER I — GENERAL PROVISIONS

Article 1–Article 6 · 6 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Subject matter and scope

Article 1

This Regulation sets out the European Common Criteria-based cybersecurity certification scheme (EUCC). This Regulation applies to all information and communication technologies (‘ICT’) products, including their documentation, which are submitted for certification under the EUCC, and to all protection profiles which are submitted for certification as part of the ICT process leading to the certification of ICT products.

Definitions

Article 2

For the purposes of this Regulation, the following definitions shall apply: (1) ‘Common Criteria’ mean the Common Criteria for Information Technology Security Evaluation, as set out in ISO standard ISO/IEC 15408; (2) ‘Common Evaluation Methodology’ means the Common Methodology for Information Technology Security Evaluation, as set out in ISO/IEC standard ISO/IEC 18045; (3) ‘target of evaluation’ means an ICT product or part thereof, or a protection profile as part of an ICT process, which is subjected to cybersecurity evaluation to receive EUCC certification; (4) ‘security target’ means a claim of implementation-dependent security requirements for a specific ICT product; (5) ‘protection profile’ means an ICT process that lays down the security requirements for a specific category of ICT products, addressing implementation-independent security needs, and that may be used to assess ICT products falling into that specific category for the purpose of their certification; (6) ‘evaluation technical report’ means a document produced by an ITSEF to present the findings, verdicts and justifications obtained during the evaluation of an ICT product or a protection profile in accordance with the rules and obligations set out in this Regulation; (7) ‘ITSEF’ means an Information Technology Security Evaluation Facility, which is a conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008 that performs evaluation tasks; (8) ‘AVA_VAN level’ means an assurance vulnerability analysis level that indicates the degree of cybersecurity evaluation activities carried out to determine the level of resistance against potential exploitability of flaws or weaknesses in the target of evaluation in its operational environment as set out in the Common Criteria; (9) ‘EUCC certificate’ means a cybersecurity certificate issued under the EUCC for ICT products, or for protection profiles that can be used exclusively in the ICT process of certification of ICT products; (10) ‘composite product’ means an ICT product that is evaluated together with another underlying ICT product that has already received an EUCC certificate and on whose security functionality the composite ICT product depends; (11) ‘national cybersecurity certification authority’ means an authority designated by a Member State pursuant to Article 58(1) of Regulation (EU) 2019/881; (12) ‘certification body’ means a conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008, which performs certification activities; (13) ‘technical domain’ means a common technical framework related to a particular technology for the harmonised certification with a set of characteristic security requirements; (14) ‘state-of-the-art document’ means a document which specifies evaluation methods, techniques and tools that apply to the certification of ICT products, or security requirements of a generic ICT product category, or any other requirements necessary for certification, in order to harmonise evaluation, in particular of technical domains or protection profiles; (15) ‘market surveillance authority’ means an authority defined in Article 3(4) of Regulation (EU) 2019/1020.

Evaluation standards

Article 3

The following standards shall apply to evaluations performed under the EUCC scheme: (a) the Common Criteria; (b) the Common Evaluation Methodology.

Assurance levels

Article 4

1.   Certification bodies shall issue EUCC certificates at assurance level ‘substantial’ or ‘high’. 2.   EUCC certificates at assurance level ‘substantial’ shall correspond to certificates that cover AVA_VAN level 1 or 2. 3.   EUCC certificates at assurance level ‘high’ shall correspond to certificates that cover AVA_VAN level 3, 4 or 5. 4.   The assurance level confirmed in a EUCC certificate shall distinguish between the conformant and augmented use of the assurance components as specified in the Common Criteria in accordance with Annex VIII. 5.   Conformity assessment bodies shall apply those assurance components on which the selected AVA_VAN level depends in accordance with the standards referred to in Article 3.

Methods for certifying ICT products

Article 5

1.   Certification of an ICT product shall be carried out against its security target: (a) as defined by the applicant; or (b) incorporating a certified protection profile as part of the ICT process, where the ICT product falls in the ICT product category covered by that protection profile. 2.   Protection profiles shall be certified for the sole purpose of the certification of ICT products falling in the specific category of ICT products covered by the protection profile.

Conformity self-assessment

Article 6

A conformity self-assessment within the meaning of Article 53 of Regulation (EU) 2019/881 shall not be permitted.

Back to Commission Implementing Regulation (EU) 2024/482 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next