Retention of records by certification bodies and the ITSEF
1. The ITSEF and certification bodies shall maintain a record system, which shall contain all documents produced in connection with each evaluation and certification they perform.
2. Certification bodies and the ITSEF shall store the records in a secure manner and shall keep those records for the period necessary for the purposes of this Regulation and for at least 5 years after the withdrawal of the relevant EUCC certificate. When the certification body has issued a new EUCC certificate in accordance with Article 13(2), point (c), it shall retain the documentation of the withdrawn EUCC certificate together with and as long as for the new EUCC certificate.
Information made available by the holder of a certificate
1. The information referred to in Article 55 of Regulation (EU) 2019/881 shall be available in a language that can be easily accessible to users.
2. The holder of an EUCC certificate shall store the following securely for the period necessary for the purposes of this Regulation and for at least 5 years after the withdrawal of the relevant EUCC certificate:
(a)
records of the information provided to the certification body and to the ITSEF during the certification process;
(b)
specimen of the certified ICT product.
3. When the certification body has issued a new EUCC certificate in accordance with Article 13(2), point (c), the holder shall retain the documentation of the withdrawn EUCC certificate together with and as long as for the new EUCC certificate.
4. Upon request by the certification body or the national cybersecurity certification authority, the holder of an EUCC certificate shall make available the records and copies referred to in paragraph 2.
Information to be made available by ENISA
1. ENISA shall publish the following information on the website referred to in Article 50(1) of Regulation (EU) 2019/881:
(a)
all EUCC certificates;
(b)
the information on the status of an EUCC certificate, notably whether it is in force, suspended, withdrawn, or expired;
(c)
certification reports corresponding to each EUCC certificate;
(d)
a list of accredited conformity assessment bodies;
(e)
a list of authorised conformity assessment bodies;
(f)
the state-of-the-art documents listed in Annex I
(g)
the opinions of the European Cybersecurity Certification Group referred to in Article 62(4), point (c), of Regulation (EU) 2019/881;
(h)
peer assessment reports issued in accordance with Article 47.
2. The information referred to in paragraph 1 shall be made available at least in English.
3. Certification bodies and, where applicable, national cybersecurity certification authorities shall inform ENISA without delay about their decisions which affect the content or the status of an EUCC certificate referred to in paragraph 1, point (b).
4. ENISA shall ensure that the information published in accordance with paragraph 1 points (a), (b) and (c), clearly identifies the versions of a certified ICT product which are covered by an EUCC certificate.
Protection of information
Conformity assessment bodies, national cybersecurity certification authorities, ECCG, ENISA, the Commission and all other parties shall ensure the security and protection of business secrets and other confidential information, including trade secrets, as well as the preserving intellectual property rights, and take the necessary and appropriate technical and organisational measures.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.