Subject matter and scope
This Regulation sets out the European Common Criteria-based cybersecurity certification scheme (EUCC).
This Regulation applies to all information and communication technologies (‘ICT’) products, including their documentation, which are submitted for certification under the EUCC, and to all protection profiles which are submitted for certification as part of the ICT process leading to the certification of ICT products.
Definitions
For the purposes of this Regulation, the following definitions shall apply:
(1)
‘Common Criteria’ mean the Common Criteria for Information Technology Security Evaluation, as set out in ISO standard ISO/IEC 15408;
(2)
‘Common Evaluation Methodology’ means the Common Methodology for Information Technology Security Evaluation, as set out in ISO/IEC standard ISO/IEC 18045;
(3)
‘target of evaluation’ means an ICT product or part thereof, or a protection profile as part of an ICT process, which is subjected to cybersecurity evaluation to receive EUCC certification;
(4)
‘security target’ means a claim of implementation-dependent security requirements for a specific ICT product;
(5)
‘protection profile’ means an ICT process that lays down the security requirements for a specific category of ICT products, addressing implementation-independent security needs, and that may be used to assess ICT products falling into that specific category for the purpose of their certification;
(6)
‘evaluation technical report’ means a document produced by an ITSEF to present the findings, verdicts and justifications obtained during the evaluation of an ICT product or a protection profile in accordance with the rules and obligations set out in this Regulation;
(7)
‘ITSEF’ means an Information Technology Security Evaluation Facility, which is a conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008 that performs evaluation tasks;
(8)
‘AVA_VAN level’ means an assurance vulnerability analysis level that indicates the degree of cybersecurity evaluation activities carried out to determine the level of resistance against potential exploitability of flaws or weaknesses in the target of evaluation in its operational environment as set out in the Common Criteria;
(9)
‘EUCC certificate’ means a cybersecurity certificate issued under the EUCC for ICT products, or for protection profiles that can be used exclusively in the ICT process of certification of ICT products;
(10)
‘composite product’ means an ICT product that is evaluated together with another underlying ICT product that has already received an EUCC certificate and on whose security functionality the composite ICT product depends;
(11)
‘national cybersecurity certification authority’ means an authority designated by a Member State pursuant to Article 58(1) of Regulation (EU) 2019/881;
(12)
‘certification body’ means a conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008, which performs certification activities;
(13)
‘technical domain’ means a common technical framework related to a particular technology for the harmonised certification with a set of characteristic security requirements;
(14)
‘state-of-the-art document’ means a document which specifies evaluation methods, techniques and tools that apply to the certification of ICT products, or security requirements of a generic ICT product category, or any other requirements necessary for certification, in order to harmonise evaluation, in particular of technical domains or protection profiles;
(15)
‘market surveillance authority’ means an authority defined in Article 3(4) of Regulation (EU) 2019/1020.
Evaluation standards
The following standards shall apply to evaluations performed under the EUCC scheme:
(a)
the Common Criteria;
(b)
the Common Evaluation Methodology.
Assurance levels
1. Certification bodies shall issue EUCC certificates at assurance level ‘substantial’ or ‘high’.
2. EUCC certificates at assurance level ‘substantial’ shall correspond to certificates that cover AVA_VAN level 1 or 2.
3. EUCC certificates at assurance level ‘high’ shall correspond to certificates that cover AVA_VAN level 3, 4 or 5.
4. The assurance level confirmed in a EUCC certificate shall distinguish between the conformant and augmented use of the assurance components as specified in the Common Criteria in accordance with Annex VIII.
5. Conformity assessment bodies shall apply those assurance components on which the selected AVA_VAN level depends in accordance with the standards referred to in Article 3.
Methods for certifying ICT products
1. Certification of an ICT product shall be carried out against its security target:
(a)
as defined by the applicant; or
(b)
incorporating a certified protection profile as part of the ICT process, where the ICT product falls in the ICT product category covered by that protection profile.
2. Protection profiles shall be certified for the sole purpose of the certification of ICT products falling in the specific category of ICT products covered by the protection profile.
Conformity self-assessment
A conformity self-assessment within the meaning of Article 53 of Regulation (EU) 2019/881 shall not be permitted.