Conditions
Article 44
1. Third countries willing to certify their products in accordance with this Regulation, and who wish to have such certification recognised within the Union, shall conclude a mutual recognition agreement with the Union. 2. The mutual recognition agreement shall cover the applicable assurance levels for certified ICT products and, where applicable, protection profiles. 3. Mutual recognition agreements referred to in paragraph 1, may only be concluded with third countries that meet the following conditions: (a) have an authority that: (1) is a public body, independent of the entities it supervises and monitors in terms of organisational and legal structure, financial funding and decision making; (2) has appropriate monitoring and supervising powers to carry out investigations and is empowered to take appropriate corrective measures to ensure compliance; (3) has an effective, proportionate and dissuasive penalty system to ensure compliance; (4) agrees to collaborate with the European Cybersecurity Certification Group and ENISA to exchange best practice and relevant developments in the field of cybersecurity certification and to work towards a uniform interpretation of the currently applicable evaluation criteria and methods, amongst others, by applying harmonised documentation that is equivalent to the state-of-the-art documents listed in Annex I (b) have an independent accreditation body performing accreditations using equivalent standards to those referred to in Regulation (EC) No 765/2008; (c) commit that the evaluation and certification processes and procedures will be carried out in a duly professional manner, taking into account compliance with the international standards referred to in this Regulation, in particular in Article 3; (d) have the capacity to report previously undetected vulnerabilities and an established, adequate vulnerability management and disclosure procedure in place; (e) have established procedures that enable it to effectively lodge and handle complaints and provide effective legal remedy for the complainant; (f) establishing a mechanism for cooperation with other Union and Member States’ bodies relevant to the cybersecurity certification under this Regulation including the sharing of information about the possible non-compliance of certificates, monitoring relevant developments in the field of certification and ensuring a joint approach on certification maintenance and review. 4. In addition to the conditions set out in paragraph 3, a mutual recognition agreement referred to in paragraph 1 covering assurance level “high” may only be concluded with third countries where also the following conditions are met: (a) the third country has an independent and public cybersecurity certification authority performing or delegating evaluation activities necessary to allow certification under assurance level ‘high’ that are equivalent to the requirements and procedures laid down for national cybersecurity authorities in this Regulation and in Regulation (EU) 2019/881; (b) the mutual recognition agreement establishes a joint mechanism equivalent to the peer assessment for EUCC certification to enhance the exchange of practices and jointly solve issues in the area of evaluation and certification.