My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/482 CHAPTER V — MONITORING, NON-CONFORMITY AND NON-COMPLIANCE

Article 25–Article 31 · 7 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

SECTION I — Compliance monitoring

Monitoring activities by the national cybersecurity certification authority

Article 25

1.   Without prejudice to Article 58(7) of Regulation (EU) 2019/881, the national cybersecurity certification authority shall monitor the compliance of: (a) the certification body and the ITSEF with their obligations pursuant to this Regulation and Regulation (EU) 2019/881; (b) the holders of an EUCC certificate with their obligations pursuant to this Regulation and Regulation (EU) 2019/881; (c) the certified ICT products with the requirements set out in the EUCC; (d) the assurance expressed in the EUCC certificate addressing the evolving threat landscape. 2.   The national cybersecurity certification authority shall perform its monitoring activities in particular on the basis of: (a) information coming from certification bodies, national accreditation bodies and relevant market surveillance authorities; (b) information resulting from its own or another authority’s audits and investigations; (c) sampling, carried out in accordance with paragraph 3; (d) complaints received. 3.   The national cybersecurity certification authority shall, in cooperation with other market surveillance authorities, sample annually at least 4% of the EUCC certificates as determined by a risk assessment. Upon request and acting on behalf of the competent national cybersecurity certification authority, certification bodies and, if necessary, ITSEF shall assist that authority in monitoring compliance. 4.   The national cybersecurity certification authority shall select the sample of certified ICT products to be checked using objective criteria, including: (a) product category; (b) assurance levels of products; (c) holder of a certificate; (d) certification body and, where applicable, the subcontracted ITSEF; (e) any other information brought to the authority’s attention. 5.   The national cybersecurity certification authority shall inform the holders of the EUCC certificate about the selected ICT products and the selection criteria. 6.   The certification body that certified the sampled ICT product shall, upon request of the national cybersecurity certification authority, with the assistance of the respective ITSEF, conduct additional review in accordance with the procedure laid down in Section IV.2 of Annex IV and inform the national cybersecurity certification authority of the results. 7.   Where the national cybersecurity certification authority has sufficient reason to believe that a certified ICT product is no longer in compliance with this Regulation or Regulation (EU) 2019/881, it may carry out investigations or make use of any other monitoring powers set out in Article 58(8) of Regulation (EU) 2019/881. 8.   The national cybersecurity certification authority shall inform the certification body and ITSEF concerned about ongoing investigations regarding selected ICT products. 9.   Where the national cybersecurity certification authority identifies that an ongoing investigation concerns ICT products that are certified by certification bodies established in other Member States, it shall inform thereof the national cybersecurity certification authorities of the relevant Member States in order to collaborate in the investigations, where relevant. Such national cybersecurity certification authority shall also notify the European Cybersecurity Certification Group of the cross-border investigations and the subsequent results.

Monitoring activities by the certification body

Article 26

1.   The certification body shall monitor: (a) the compliance of the holders of a certificate with their obligations under this Regulation and Regulation (EU) 2019/881 towards the EUCC certificate that was issued by the certification body; (b) the compliance of the ICT products it has certified with their respective security requirements; (c) the assurance expressed in the certified protection profiles. 2.   The certification body shall undertake its monitoring activities on the basis of: (a) the information provided on the basis of the commitments of the applicant for certification referred to in Article 9(2); (b) information resulting from activities of other relevant market surveillance authorities; (c) complaints received; (d) vulnerability information that could impact the ICT products it has certified. 3.   The national cybersecurity certification authority may draw up rules for a periodical dialogue between certification bodies and holders of EUCC certificates to verify and report on compliance with the commitments made pursuant to Article 9(2), without prejudice to activities related to other relevant market surveillance authorities.

Monitoring activities by the holder of the certificate

Article 27

1.   The holder of an EUCC certificate shall perform the following tasks to monitor the conformity of the certified ICT product with its security requirements: (a) monitor vulnerability information regarding the certified ICT product, including known dependencies by its own means but also in consideration of: (1) a publication or a submission regarding vulnerability information by a user or security researcher referred to in Article 55(1), point (c) of Regulation (EU) 2019/881; (2) a submission by any other source; (b) monitor the assurance expressed in the EUCC certificate. 2.   The holder of an EUCC certificate shall work in cooperation with the certification body, the ITSEF, and, where applicable, the national cybersecurity certification authority to support their monitoring activities.

SECTION II — Conformity and compliance

Consequences of non-conformity of a certified ICT product or protection profile

Article 28

1.   Where a certified ICT product or protection profile does not conform with the requirements laid down in this Regulation and in Regulation (EU) 2019/881, the certification body shall inform the holder of the EUCC certificate about the identified non-conformity and request remedial actions. 2.   Where an instance of non-conformity with the provisions of this Regulation might affect compliance with other relevant Union legislation, which provides for the possibility to demonstrate the presumption of conformity with the requirements of that legal act by using the EUCC certificate, the certification body shall inform the national cybersecurity certification authority without delay. The national cybersecurity certification authority shall immediately notify the market surveillance authority responsible for such other relevant Union legislation regulation about the instance of non-conformity identified. 3.   Upon receipt of the information referred to in paragraph 1, the holder of the EUCC certificate shall within the time period set by the certification body, which shall not exceed 30 days, propose to the certification body the remedial action necessary to address the non-conformity. 4.   The certification body may suspend, without undue delay, the EUCC certificate in accordance with Article 30 in case of emergency, or where the holder of the EUCC certificate does not duly cooperate with the certification body. 5.   The certification body shall carry out a review in accordance with Articles 13 and 19, assessing whether the remedial action addresses the non-conformity. 6.   Where the holder of the EUCC certificate does not propose appropriate remedial action during the period referred to in paragraph 3, the certificate shall be suspended in accordance with Article 30 or withdrawn in accordance with Articles 14 or 20. 7.   This Article shall not apply to cases of vulnerabilities affecting a certified ICT product, which shall be handled in accordance with Chapter VI.

Consequences of non-compliance by the holder of the certificate

Article 29

1.   Where the certification body finds that: (a) the holder of the EUCC certificate or the applicant for certification is not compliant with its commitments and obligations as set out in Articles 9(2), 17(2), 27 and 41; or (b) the holder of the EUCC certificate does not comply with Article 56(8) of Regulation (EU) 2019/881 or Chapter VI of this Regulation; it shall set a time period of not more than 30 days within which the holder of the EUCC certificate shall take remedial action. 2.   Where the holder of the EUCC certificate does not propose appropriate remedial action during the time period referred to in paragraph 1, the certificate shall be suspended in accordance with Article 30 or withdrawn in accordance with Article 14 and Article 20. 3.   Continued or recurring infringement by the holder of the EUCC certificate of the obligations referred to in paragraph 1 shall trigger the withdrawal of the EUCC certificate in accordance with Articles 14 or Article 20. 4.   The certification body shall inform the national cybersecurity certification authority of the findings referred to in paragraph 1. Where the instance of non-compliance affects compliance with other relevant Union legislation, the national cybersecurity certification authority shall immediately notify the market surveillance authority responsible for such other relevant Union legislation about the instance of non-compliance identified.

Suspension of the EUCC certificate

Article 30

1.   Where this Regulation refers to suspension of an EUCC certificate, the certification body shall suspend an EUCC certificate concerned for a period appropriate to the circumstances triggering suspension, that does not exceed 42 days. The suspension period shall begin on the day following the day of the decision of the certification body. The suspension shall not affect the validity of the certificate. 2.   The certification body shall notify the holder of the certificate and the national cybersecurity certification authority of the suspension without undue delay and shall provide the reasons for the suspension, the requested actions to be taken and the suspension period. 3.   Certification holders shall notify the purchasers of the ICT products concerned about the suspension and the reasons provided by the certification body for the suspension, except those parts of the reasons the sharing of which would constitute a security risk or which contain sensitive information. This information shall also be made publicly available by the holder of the certificate. 4.   Where other relevant Union legislation provides for a presumption of conformity based on certificates issued under the provisions of this Regulation, the national cybersecurity certification authority shall inform the market surveillance authority responsible for such other relevant Union legislation about the suspension. 5.   The suspension of a certificate shall be notified to ENISA in accordance with Article 42(3). 6.   In duly justified cases, the national cybersecurity certification authority may authorise an extension of the period of suspension of an EUCC certificate. The total period of suspension may not exceed 1 year.

Consequences of non-compliance by the conformity assessment body

Article 31

1.   In case of non-compliance by a certification body with its obligations, or by the relevant certification body in case of identifying non-compliance by an ITSEF, the national cybersecurity certification authority shall, without undue delay: (a) identify, with the support of the concerned ITSEF, the potentially affected EUCC certificates; (b) where necessary, request evaluation activities to be performed on one or more ICT products or protection profiles by either the ITSEF which performed the evaluation, or any other accredited and, where applicable, authorised ITSEF that may be in a better technical position to support that identification; (c) analyse the impacts of non-compliance; (d) notify the holder of the EUCC certificate affected by non-compliance. 2.   On the basis of the measures referred to in paragraph 1, the certification body shall adopt either of the following decisions with respect to each affected EUCC certificate: (a) maintain the EUCC certificate unaltered; (b) withdraw the EUCC certificate in accordance with Article 14 or Article 20, and, where appropriate, issue a new EUCC certificate. 3.   On the basis of the measures referred to in paragraph 1, the national cybersecurity certification authority shall: (a) where necessary, report the non-compliance of the certification body or related ITSEF to the national accreditation body; (b) where applicable, assess the potential impact on the authorisation.

Back to Commission Implementing Regulation (EU) 2024/482 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next