My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/482 CHAPTER III — CERTIFICATION OF PROTECTION PROFILES

Article 15–Article 20 · 6 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

SECTION I — Specific standards and requirements for evaluation

Evaluation criteria and methods

Article 15

1.   A protection profile shall be evaluated, as a minimum, in accordance with the following: (a) the applicable elements of the standards referred to in Article 3; (b) the level of risk associated with the intended use of the ICT products concerned pursuant to Article 52 of Regulation (EU) 2019/881 and their security functions that support the security objectives set out in Article 51 of that; and (c) the applicable state-of-the-art documents listed in Annex I. A protection profile covered by a technical domain shall be certified against the requirements set out in that technical domain. 2.   In exceptional and duly justified cases, a conformity assessment body may certify a protection profile without applying the relevant state-of-the-art documents. In such cases, it shall inform the competent national cybersecurity certification authority and provide a justification for the intended certification without application of the relevant state-of-the-art documents as well as the proposed evaluation methodology. The national cybersecurity certification authority shall assess the justification and, where justified, approve the non-application of the relevant state-of-the-art documents, and approve or amend, where appropriate, the evaluation methodology to be applied by the conformity assessment body. Pending the decision of the national cybersecurity certification authority, the conformity assessment body shall not issue any certificate for the protection profile. The national cybersecurity certification authority shall notify, without undue delay, the authorised non-application of the relevant state-of-the-art documents to the European Cybersecurity Certification Group, which may issue an opinion. The national cybersecurity certification authority shall take utmost account of the opinion of the European Cybersecurity Certification Group.

SECTION II — Issuing, renewing and withdrawing EUCC certificates for protection profiles

Information necessary for certification of protection profiles

Article 16

An applicant for certification of a protection profile shall provide or otherwise make available to the certification body and the ITSEF all information necessary for the certification activities. Article 8(2), (3), (4) and (7) shall apply mutatis mutandis.

Issuance of EUCC certificates for protection profiles

Article 17

1.   The applicant for certification shall provide the certification body and the ITSEF with all the necessary complete and correct information. 2.   Articles 9 and 10 shall apply mutatis mutandis. 3.   The ITSEF shall evaluate whether a protection profile is complete, consistent, technically sound and effective for the intended use and the security objectives of the ICT product’s category covered by that protection profile. 4.   A protection profile shall be certified solely by: (a) a national cybersecurity certification authority or another public body accredited as certification body; or (b) a certification body, upon prior approval by the national cybersecurity certification authority for each individual protection profile.

Period of validity of an EUCC certificate for protection profiles

Article 18

1.   The certification body shall set a period of validity for each EUCC certificate. 2.   The period of validity may be up to the lifetime of the protection profile concerned.

Review of an EUCC certificate for protection profiles

Article 19

1.   Upon request of the holder of the certificate or for other justified reasons, the certification body may decide to review an EUCC certificate for a protection profile. The review shall be carried out by applying the conditions set out in Article 15. The certification body shall determine the extent of the review. Where necessary for the review, the certification body shall request the ITSEF to perform a re-evaluation of the certified protection profile. 2.   Following the results of the review, and where applicable of the re-evaluation, the certification body shall do one of the following: (a) confirm the EUCC certificate; (b) withdraw the EUCC certificate in accordance with Article 20; (c) withdraw the EUCC certificate in accordance with Article 20 and issue a new EUCC certificate with an identical scope and an extended validity period; (d) withdraw the EUCC certificate in accordance with Article 20 and issue a new EUCC certificate with a different scope.

Withdrawal of an EUCC certificate for a protection profile

Article 20

1.   Without prejudice to Article 58(8), point (e) of Regulation (EU) 2019/881, an EUCC certificate for a protection profile shall be withdrawn by the certification body that issued that certificate. Article 14 shall apply mutatis mutandis. 2.   A certificate for a protection profile issued in accordance with Article 17(4), point (b) shall be withdrawn by the national cybersecurity certification authority that approved that certificate.

Back to Commission Implementing Regulation (EU) 2024/482 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next