Additional or specific requirements for a certification body
1. A certification body shall be authorised by the national cybersecurity certification authority to issue EUCC certificates at assurance level ‘high’ where that body demonstrates that, in addition to meeting the requirements laid down in Article 60(1) and the Annex to Regulation (EU) 2019/881 regarding accreditation of conformity assessment bodies, the following:
(a)
it has the expertise and competences required for the certification decision at assurance level ‘high’;
(b)
it conducts its certification activities in cooperation with an ITSEF authorised in accordance with Article 22; and
(c)
it has the requisite competences and put in place appropriate technical and operational measures to effectively protect confidential and sensitive information for assurance level ‘high’, in addition to the requirements set out in Article 43.
2. The national cybersecurity certification authority shall assess whether a certification body fulfils all the requirements set out in paragraph 1. That assessment shall include at least structured interviews and a review of at least one pilot certification performed by the certification body in accordance with this Regulation.
In its assessment, the national cybersecurity certification authority may reuse any appropriate evidence from prior authorisation or similar activities granted pursuant to:
(a)
this Regulation;
(b)
another European cybersecurity certification scheme adopted pursuant to Article 49 of Regulation (EU) 2019/881;
(c)
a national scheme referred to in Article 49 of this Regulation.
3. The national cybersecurity certification authority shall produce an authorisation report which is subject to peer review in accordance with Article 59(3), point (d), of Regulation (EU) 2019/881.
4. The national cybersecurity certification authority shall specify the ICT product categories and protection profiles to which the authorisation extends. The authorisation shall be valid for a period no longer than the validity of the accreditation. It may be renewed upon request provided that the certification body still meets the requirements set out in this Article. For the renewal of the authorisation, no pilot evaluations are required.
5. The national cybersecurity certification authority shall withdraw the authorisation of the certification body where it no longer meets the conditions set out in this Article. Upon withdrawal of the authorisation, the certification body shall cease immediately promoting itself as an authorised certification body.
Additional or specific requirements for an ITSEF
1. An ITSEF shall be authorised by the national cybersecurity certification authority to carry out the evaluation of ICT products which are subject to certification under the assurance level ‘high’, where the ITSEF demonstrates that, in addition to meeting the requirements laid down in Article 60(1) and the Annex to Regulation (EU) 2019/881 regarding accreditation of conformity assessment bodies, it complies with all of the following conditions:
(a)
it has the necessary expertise for performing the evaluation activities to determine the resistance to state-of-the-art cyberattacks carried out by actors with significant skills and resources;
(b)
for the technical domains and protection profiles, which are part of the ICT process for those ICT products, it has:
(1)
the expertise to perform the specific evaluation activities necessary to methodically determine a target of evaluation’s resistance against skilled attackers in its operational environment assuming an attack potential of ‘moderate’ or ‘high’ as set out in the standards referred to in Article 3;
(2)
the technical competences as specified in the state-of-the-art documents listed in Annex I;
(c)
it has the requisite competences and put in place appropriate technical and operational measures to effectively protect confidential and sensitive information for assurance level ’high’ in addition to the requirements set out in Article 43.
2. The national cybersecurity certification authority shall assess whether an ITSEF fulfils all the requirements set out in paragraph 1. That assessment shall include at least structured interviews and a review of at least one pilot evaluation performed by the ITSEF in accordance with this Regulation.
3. In its assessment, the national cybersecurity certification authority may reuse any appropriate evidence from prior authorisation or similar activities granted pursuant to:
(a)
this Regulation;
(b)
another European cybersecurity certification scheme adopted pursuant to Article 49 of Regulation (EU) 2019/881;
(c)
a national scheme referred to in Article 49 of this Regulation.
4. The national cybersecurity certification authority shall produce an authorisation report which is subject to peer review in accordance with Article 59(3), point (d) of Regulation (EU) 2019/881.
5. The national cybersecurity certification authority shall specify the ICT product categories and protection profiles to which the authorisation extends. The authorisation shall be valid for period no longer than the validity of the accreditation. It may be renewed upon request provided that the ITSEF still meets the requirements set out in this Article. For the renewal of the authorisation, no pilot evaluations should be required.
6. The national cybersecurity certification authority shall withdraw the authorisation of the ITSEF where it no longer meets the conditions set out in this Article. Upon withdrawal of the authorisation, the ITSEF shall stop promoting itself as being an authorised ITSEF.
Notification of certification bodies
1. The national cybersecurity certification authority shall notify the Commission of the certification bodies in its territory that are competent to certify at assurance level ‘substantial’ based on their accreditation.
2. The national cybersecurity certification authority shall notify the Commission of the certification bodies in their territory that are competent to certify at assurance level ‘high’ based on their accreditation and the authorisation decision.
3. The national cybersecurity certification authority shall provide at least the following information when notifying the Commission of the certification bodies:
(a)
the assurance level or levels for which the certification body is competent to issue EUCC certificates;
(b)
the following information related to accreditation:
(1)
date of the accreditation;
(2)
name and address of the certification body;
(3)
country of registration of the certification body;
(4)
reference number of the accreditation;
(5)
scope and duration of validity of the accreditation;
(6)
the address, location and link to the relevant website of the national accreditation body; and
(c)
the following information related to authorisation for level ‘high’:
(1)
date of the authorisation;
(2)
reference number of the authorisation;
(3)
duration of validity of the authorisation;
(4)
scope of the authorisation including the highest AVA_VAN level and, where applicable, the covered technical domain.
4. The national cybersecurity certification authority shall send a copy of the notification referred to in paragraphs 1 and 2 to ENISA for the publication of accurate information on the cybersecurity certification website regarding the eligibility of certification bodies.
5. The national cybersecurity certification authority shall examine without undue delay any information regarding a change in the status of the accreditation provided by the national accreditation body. Where the accreditation or authorisation have been withdrawn, the national cybersecurity certification authority shall inform the Commission thereof, and may submit to the Commission a request in accordance with Article 61(4) of Regulation (EU) 2019/881.
Notification of ITSEF
The notification obligations of the national cybersecurity certification authorities set out in Article 23 shall also apply to ITSEF. The notification shall include the address of the ITSEF, the valid accreditation and, where applicable, the valid authorisation of that ITSEF.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.