My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/482 CHAPTER VII — RETENTION, DISCLOSURE AND PROTECTION OF INFORMATION

Article 40–Article 43 · 4 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Retention of records by certification bodies and the ITSEF

Article 40

1.   The ITSEF and certification bodies shall maintain a record system, which shall contain all documents produced in connection with each evaluation and certification they perform. 2.   Certification bodies and the ITSEF shall store the records in a secure manner and shall keep those records for the period necessary for the purposes of this Regulation and for at least 5 years after the withdrawal of the relevant EUCC certificate. When the certification body has issued a new EUCC certificate in accordance with Article 13(2), point (c), it shall retain the documentation of the withdrawn EUCC certificate together with and as long as for the new EUCC certificate.

Information made available by the holder of a certificate

Article 41

1.   The information referred to in Article 55 of Regulation (EU) 2019/881 shall be available in a language that can be easily accessible to users. 2.   The holder of an EUCC certificate shall store the following securely for the period necessary for the purposes of this Regulation and for at least 5 years after the withdrawal of the relevant EUCC certificate: (a) records of the information provided to the certification body and to the ITSEF during the certification process; (b) specimen of the certified ICT product. 3.   When the certification body has issued a new EUCC certificate in accordance with Article 13(2), point (c), the holder shall retain the documentation of the withdrawn EUCC certificate together with and as long as for the new EUCC certificate. 4.   Upon request by the certification body or the national cybersecurity certification authority, the holder of an EUCC certificate shall make available the records and copies referred to in paragraph 2.

Information to be made available by ENISA

Article 42

1.   ENISA shall publish the following information on the website referred to in Article 50(1) of Regulation (EU) 2019/881: (a) all EUCC certificates; (b) the information on the status of an EUCC certificate, notably whether it is in force, suspended, withdrawn, or expired; (c) certification reports corresponding to each EUCC certificate; (d) a list of accredited conformity assessment bodies; (e) a list of authorised conformity assessment bodies; (f) the state-of-the-art documents listed in Annex I (g) the opinions of the European Cybersecurity Certification Group referred to in Article 62(4), point (c), of Regulation (EU) 2019/881; (h) peer assessment reports issued in accordance with Article 47. 2.   The information referred to in paragraph 1 shall be made available at least in English. 3.   Certification bodies and, where applicable, national cybersecurity certification authorities shall inform ENISA without delay about their decisions which affect the content or the status of an EUCC certificate referred to in paragraph 1, point (b). 4.   ENISA shall ensure that the information published in accordance with paragraph 1 points (a), (b) and (c), clearly identifies the versions of a certified ICT product which are covered by an EUCC certificate.

Protection of information

Article 43

Conformity assessment bodies, national cybersecurity certification authorities, ECCG, ENISA, the Commission and all other parties shall ensure the security and protection of business secrets and other confidential information, including trade secrets, as well as the preserving intellectual property rights, and take the necessary and appropriate technical and organisational measures.

Back to Commission Implementing Regulation (EU) 2024/482 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next