My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/482 CHAPTER II — CERTIFICATION OF ICT PRODUCTS

Article 7–Article 14 · 8 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

SECTION I — Specific standards and requirements for evaluation

Evaluation criteria and methods for ICT products

Article 7

1.   An ICT product submitted for certification shall, as a minimum, be evaluated in accordance with the following: (a) the applicable elements of the standards referred to in Article 3; (b) the security assurance requirements classes for vulnerability assessment and independent functional testing, as set out in the evaluation standards referred to in Article 3; (c) the level of risk associated with the intended use of the ICT products concerned pursuant to Article 52 of Regulation (EU) 2019/881 and their security functions that support the security objectives set out in Article 51 of Regulation (EU) 2019/881; (d) the applicable state-of-the-art documents listed in Annex I; and (e) the applicable certified protection profiles listed in Annex II. 2.   In exceptional and duly justified cases, a conformity assessment body may request to refrain from applying the relevant state-of-the-art document. In such cases the conformity assessment body shall inform the national cybersecurity certification authority with a duly reasoned justification for its request. The national cybersecurity certification authority shall assess the justification for an exception and, where justified, approve it. Pending the decision of the national cybersecurity certification authority, the conformity assessment body shall not issue any certificate. The national cybersecurity certification authority shall notify the approved exception, without undue delay, to the European Cybersecurity Certification Group, which may issue an opinion. The national cybersecurity certification authority shall take utmost account of the opinion of the European Cybersecurity Certification Group. 3.   Certification of ICT products at AVA_VAN level 4 or 5 shall only be possible in the following scenarios: (a) where the ICT product is covered by any technical domain listed in Annex I, it shall be evaluated in accordance with the applicable state-of-the-art documents of those technical domains, (b) where the ICT product falls into a category of ICT products covered by a certified protection profile that includes AVA_VAN levels 4 or 5 and that has been listed as a state-of-the-art protection profile in Annex II, it shall be evaluated in accordance with the evaluation methodology specified for that protection profile, (c) where points a) and b) of this paragraph are not applicable and where the inclusion of a technical domain in Annex I or of a certified protection profile in Annex II is unlikely in the foreseeable future, and only in exceptional and duly justified cases, subject to the conditions set out in paragraph 4. 4.   Where a conformity assessment body considers to be in an exceptional and duly justified case referred to in point c) of paragraph 3, it shall notify the intended certification to the national cybersecurity certification authority with a justification and a proposed evaluation methodology. The national cybersecurity certification authority shall assess the justification for an exception and, where justified, approve or amend the evaluation methodology to be applied by the conformity assessment body. Pending the decision of the national cybersecurity certification authority, the conformity assessment body shall not issue any certificate. The national cybersecurity certification authority shall report, without undue delay, the intended certification to the European Cybersecurity Certification Group, which may issue an opinion. The national cybersecurity certification authority shall take utmost account of the opinion of the European Cybersecurity Certification Group. 5.   In the case of an ICT product undergoing a composite product evaluation in accordance with the relevant state-of-the-art documents, the ITSEF that carried out the evaluation of the underlying ICT product shall share the relevant information with the ITSEF performing the evaluation of the composite ICT product.

SECTION II — Issuance, renewal and withdrawal of EUCC certificates

Information necessary for certification

Article 8

1.   An applicant for certification under EUCC shall provide or otherwise make available to the certification body and the ITSEF all information necessary for the certification activities. 2.   The information referred to in paragraph 1 shall include all relevant evidence in accordance with the sections on ‘Developer action elements’ in the appropriate format as set out in the sections on ‘Content and presentation of evidence element’ of the Common Criteria and Common Evaluation Methodology for the selected assurance level and associated security assurance requirements. The evidence shall include, where necessary, details on the ICT product and its source code in accordance with this Regulation, subject to safeguards against unauthorised disclosure. 3.   Applicants for certification may provide to the certification body and ITSEF appropriate evaluation results from prior certification pursuant to: (a) this Regulation; (b) another European cybersecurity certification scheme adopted pursuant to Article 49 of Regulation (EU) 2019/881; (c) a national scheme referred to in Article 49 of this Regulation. 4.   Where the evaluation results are pertinent to its tasks, the ITSEF may reuse the evaluation results provided that such results conform to the applicable requirements and its authenticity is confirmed. 5.   Where the certification body allows the product to undergo a composite product certification, the applicant for certification shall make available to the certification body and the ITSEF all necessary elements, where applicable, in accordance with the state-of-the-art document. 6.   Applicants for certification shall also provide the certification body and the ITSEF with the following information: (a) the link to their website containing the supplementary cybersecurity information referred to in Article 55 of Regulation (EU) 2019/881; (b) a description of the applicant’s vulnerability management and vulnerability disclosure procedures. 7.   All relevant documentation referred to in this Article shall be retained by the certification body, the ITSEF and the applicant for a period of 5 years after the expiry of the certificate.

Conditions for issuance of an EUCC certificate

Article 9

1.   The certification bodies shall issue an EUCC certificate where all of the following conditions are met: (a) the category of ICT product falls within the scope of the accreditation, and where applicable of the authorisation, of the certification body and the ITSEF involved in the certification; (b) the applicant for certification has signed a statement undertaking all commitments listed in paragraph 2; (c) the ITSEF has concluded the evaluation without objection in accordance with the evaluation standards, criteria and methods referred to in Articles 3 and 7; (d) the certification body has concluded the review of the evaluation results without objection; (e) the certification body has verified that the evaluation technical reports provided by the ITSEF are consistent with the provided evidence and that the evaluation standards, criteria and methods referred to in Articles 3 and 7 have been correctly applied. 2.   The applicant for certification shall undertake the following commitments: (a) to provide the certification body and the ITSEF with all the necessary complete and correct information, and to provide additional necessary information if requested; (b) not to promote the ICT product as being certified under the EUCC before the EUCC certificate has been issued; (c) to promote the ICT product as being certified only with respect to the scope set out in the EUCC certificate; (d) to cease immediately the promotion of the ICT product as being certified in the event of the suspension, withdrawal or expiry of the EUCC certificate; (e) to ensure that the ICT products sold with reference to the EUCC certificate are strictly identical to the ICT product subject to the certification; (f) to respect the rules of use of the mark and label established for the EUCC certificate in accordance with Article 11. 3.   In the case of an ICT product undergoing a composite product certification, in accordance with the relevant state-of-the-art documents, the certification body that carried out the certification of the underlying ICT product shall share the relevant information with the certification body performing the certification of the composite ICT product.

Content and format of an EUCC certificate

Article 10

1.   An EUCC certificate shall include at least the information set out in Annex VII. 2.   The scope and boundaries of the certified ICT product shall be unambiguously specified in the EUCC certificate or the certification report, indicating whether the entire ICT product has been certified or only parts thereof. 3.   The certification body shall provide the applicant with the EUCC certificate at least in electronic form. 4.   The certification body shall produce a certification report in accordance with Annex V for each EUCC certificate it issues. The certification report shall be based on the evaluation technical report issued by the ITSEF. The evaluation technical report and the certification report shall indicate the specific evaluation criteria and methods referred to in Article 7 used for the evaluation. 5.   The certification body shall provide the national cybersecurity certification authority and ENISA with every EUCC certificate and every certification report in electronic form.

Mark and label

Article 11

1.   The holder of a certificate may affix a mark and label to a certified ICT product. Mark and label demonstrate that the ICT product has been certified in accordance with this Regulation. Mark and label shall be affixed in accordance with this Article and with Annex IX. 2.   The mark and label shall be affixed visibly, legibly and indelibly to the certified ICT product or its data plate. Where that is not possible or not warranted on account of the nature of the product, it shall be affixed to the packaging and to the accompanying documents. Where the certified ICT product is delivered in the form of software, the mark and label shall visibly, legibly and indelibly appear in its accompanying documentation or this documentation shall be made easily and directly accessible to users by means of a website. 3.   The mark and label shall be set out as in Annex IX and contain: (a) the assurance level and the AVA_VAN level of the certified ICT product; (b) the unique identification of the certificate, consisting of: (1) the name of the scheme; (2) the name and the reference number of the accreditation of the certification body that has issued the certificate; (3) year and month of issuance; (4) identification number assigned by the certification body that has issued the certificate. 4.   The mark and label shall be accompanied by a QR code with a link to a website containing at least: (a) the information on the validity of the certificate; (b) the necessary certification information as set out in Annexes V and VII; (c) the information to be made publicly available by the holder of the certificate in accordance with Article 55 of Regulation (EU) 2019/881; and (d) where applicable, the historic information related to the specific certification or certifications of the ICT product to enable traceability.

Period of validity of an EUCC certificate

Article 12

1.   The certification body shall set a period of validity for each EUCC certificate issued taking into account the characteristics of the certified ICT product. 2.   The period of validity of the EUCC certificate shall not exceed 5 years. 3.   By derogation from paragraph 2 that period may exceed 5 years, subject to the prior approval of the national cybersecurity certification authority. The national cybersecurity certification authority shall notify the European Cybersecurity Certification Group of the granted approval without undue delay.

Review of an EUCC certificate

Article 13

1.   Upon request of the holder of the certificate or for other justified reasons, the certification body may decide to review the EUCC certificate for an ICT product. The review shall be carried out in accordance with Annex IV. The certification body shall determine the extent of the review. Where necessary for the review, the certification body shall request the ITSEF to perform a re-evaluation of the certified ICT product. 2.   Following the results of the review, and where applicable of the re-evaluation, the certification body shall: (a) confirm the EUCC certificate; (b) withdraw the EUCC certificate in accordance with Article 14; (c) withdraw the EUCC certificate in accordance with Article 14 and issue a new EUCC certificate with an identical scope and an extended validity period; or (d) withdraw the EUCC certificate in accordance with Article 14 and issue a new EUCC certificate with a different scope. 3.   The certification body may decide to suspend, without undue delay, the EUCC certificate in accordance with Article 30, pending remedial action by the holder of the EUCC certificate.

Withdrawal of an EUCC certificate

Article 14

1.   Without prejudice to Article 58(8), point (e), of Regulation (EU) 2019/881, an EUCC certificate shall be withdrawn by the certification body that issued that certificate. 2.   The certification body referred to in paragraph 1 shall notify the national cybersecurity certification authority of the withdrawal of the certificate. It shall also notify ENISA of such withdrawal in view of facilitating the performance of its task under Article 50 of Regulation (EU) 2019/881. The national cybersecurity certification authority shall notify other relevant market surveillance authorities. 3.   The holder of an EUCC certificate may request the withdrawal of the certificate.

Back to Commission Implementing Regulation (EU) 2024/482 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next