SECTION I — Specific standards and requirements for evaluation
Evaluation criteria and methods
1. A protection profile shall be evaluated, as a minimum, in accordance with the following:
(a)
the applicable elements of the standards referred to in Article 3;
(b)
the level of risk associated with the intended use of the ICT products concerned pursuant to Article 52 of Regulation (EU) 2019/881 and their security functions that support the security objectives set out in Article 51 of that; and
(c)
the applicable state-of-the-art documents listed in Annex I. A protection profile covered by a technical domain shall be certified against the requirements set out in that technical domain.
2. In exceptional and duly justified cases, a conformity assessment body may certify a protection profile without applying the relevant state-of-the-art documents. In such cases, it shall inform the competent national cybersecurity certification authority and provide a justification for the intended certification without application of the relevant state-of-the-art documents as well as the proposed evaluation methodology. The national cybersecurity certification authority shall assess the justification and, where justified, approve the non-application of the relevant state-of-the-art documents, and approve or amend, where appropriate, the evaluation methodology to be applied by the conformity assessment body. Pending the decision of the national cybersecurity certification authority, the conformity assessment body shall not issue any certificate for the protection profile. The national cybersecurity certification authority shall notify, without undue delay, the authorised non-application of the relevant state-of-the-art documents to the European Cybersecurity Certification Group, which may issue an opinion. The national cybersecurity certification authority shall take utmost account of the opinion of the European Cybersecurity Certification Group.
SECTION II — Issuing, renewing and withdrawing EUCC certificates for protection profiles
Information necessary for certification of protection profiles
An applicant for certification of a protection profile shall provide or otherwise make available to the certification body and the ITSEF all information necessary for the certification activities. Article 8(2), (3), (4) and (7) shall apply mutatis mutandis.
Issuance of EUCC certificates for protection profiles
1. The applicant for certification shall provide the certification body and the ITSEF with all the necessary complete and correct information.
2. Articles 9 and 10 shall apply mutatis mutandis.
3. The ITSEF shall evaluate whether a protection profile is complete, consistent, technically sound and effective for the intended use and the security objectives of the ICT product’s category covered by that protection profile.
4. A protection profile shall be certified solely by:
(a)
a national cybersecurity certification authority or another public body accredited as certification body; or
(b)
a certification body, upon prior approval by the national cybersecurity certification authority for each individual protection profile.
Period of validity of an EUCC certificate for protection profiles
1. The certification body shall set a period of validity for each EUCC certificate.
2. The period of validity may be up to the lifetime of the protection profile concerned.
Review of an EUCC certificate for protection profiles
1. Upon request of the holder of the certificate or for other justified reasons, the certification body may decide to review an EUCC certificate for a protection profile. The review shall be carried out by applying the conditions set out in Article 15. The certification body shall determine the extent of the review. Where necessary for the review, the certification body shall request the ITSEF to perform a re-evaluation of the certified protection profile.
2. Following the results of the review, and where applicable of the re-evaluation, the certification body shall do one of the following:
(a)
confirm the EUCC certificate;
(b)
withdraw the EUCC certificate in accordance with Article 20;
(c)
withdraw the EUCC certificate in accordance with Article 20 and issue a new EUCC certificate with an identical scope and an extended validity period;
(d)
withdraw the EUCC certificate in accordance with Article 20 and issue a new EUCC certificate with a different scope.
Withdrawal of an EUCC certificate for a protection profile
1. Without prejudice to Article 58(8), point (e) of Regulation (EU) 2019/881, an EUCC certificate for a protection profile shall be withdrawn by the certification body that issued that certificate. Article 14 shall apply mutatis mutandis.
2. A certificate for a protection profile issued in accordance with Article 17(4), point (b) shall be withdrawn by the national cybersecurity certification authority that approved that certificate.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.