Evaluation activities
1. National certification schemes shall contain methods and procedures to be used by the conformity assessment bodies when conducting their evaluation activities in accordance with EN ISO/IEC 17065:2012, which shall cover at least the following aspects:
(a)
the methods and procedures to conduct evaluation activities, including those related to WSCD, as set out in Annex IV;
(b)
the audit of the implementation of the wallet solution and the electronic identification scheme under which they are provided, based on the risk register, set out in Annex I and complemented where necessary by implementation-specific risks;
(c)
functional testing activities, based, when available and appropriate, on test suites that are defined according to technical specifications or standards;
(d)
assessment of the existence and suitability of maintenance processes, including at least version management, update management and vulnerability management;
(e)
assessment of the operating effectiveness of the maintenance processes, including at least version management, update management and vulnerability management;
(f)
dependency analysis provided by the wallet provider, including a methodology to assess the acceptability of assurance information, which shall include the elements set out in Annex VI;
(g)
vulnerability assessment, at the appropriate level, including:
—
a review of the design of the wallet solution, and where applicable, of its source code;
—
testing of the resistance of the wallet solution against attackers with high attack potential for assurance level ‘high’ pursuant to Section 2.2.1 of the Annex to Implementing Regulation (EU) 2015/1502;
(h)
assessment of the evolution of the threat environment and its impact on the coverage of the risks by the wallet solution, to determine which evaluation activities are required on the various components of the wallet solution.
2. National certification schemes shall contain an evaluation to determine whether the implementation of wallet solutions and the electronic identification scheme under which those wallet solutions are provided match the architecture set out in Article 3 paragraph 5, point (a), as well as an evaluation to determine whether the evaluation plan proposed together with the implementation matches the evaluation plan referred to in Article 3 paragraph 5, point (c).
3. National certification schemes shall set out sampling rules, in order to avoid the repetition of identical evaluation activities and to focus on activities that are specific to a given variant. Those sampling rules shall allow functional and security tests to be performed only on a sample of variants of a target component of a wallet solution and the electronic identification scheme under which they a provided and on a sample of target devices. National certification schemes shall require all certification bodies to justify their use of sampling.
4. National certification schemes shall require the evaluation, by the certification body, of the WSCA based on the methods and procedures set out in Annex IV.
Certification activities
1. National certification schemes shall set out an attestation activity for the purpose of issuing a certificate of conformity, in accordance with section V(a) of EN ISO/IEC 17067:2013, Table 1, including the following aspects:
(a)
the content of the certificate of conformity as set out in Annex VII;
(b)
how the results of the evaluation are to be reported in the public certification report, including at least a summary of the preliminary audit and validation plan, as set out in Annex VIII;
(c)
the content of the evaluation results reported in the certification assessment report, including the elements set out in Annex VIII.
2. The certification assessment report may be made available to the Cooperation Group and to the Commission.
Complaints and appeals
National certification schemes shall contain procedures or references to the applicable national legislation, which define the mechanism to effectively lodge and handle complaints and appeals in relation to their implementation of the certification scheme or to a certificate of conformity issued. These procedures shall include the provision of information to the complainant of the progress of the proceedings and on the decision taken, and information to the complainant on the right to an effective judicial remedy. National certification schemes shall require that all complaints and appeals that have not been or cannot be resolved by the certification body are sent to the scheme owner for assessment and resolution.
Surveillance activities
1. National certification schemes shall require certification bodies to implement surveillance activities consisting of surveillance evaluation of processes combined with random tests or inspections.
2. National certification schemes shall contain requirements for scheme owners to monitor the compliance of certification bodies with their obligations pursuant to Regulation (EU) No 910/2014 and pursuant to national certification schemes, if applicable.
3. National certification schemes shall contain requirements for certification bodies to monitor the following:
(a)
compliance by holders of a certificate of conformity issued under national certification schemes with their obligations concerning certification pursuant to Regulation (EU) No 910/2014 and pursuant to national certification schemes;
(b)
compliance of the certified wallet solution with the requirements set out in national certification schemes.
Consequences of non-compliance
National certification schemes shall set out the consequences of non-conformity of a certified wallet solution and of the electronic identification scheme under which they are provided, with the requirements set out in this Regulation. Those consequences shall include the following aspects:
(1)
the obligation on the certification body to inform the holder of the certificate of conformity and to request the holder of the certificate of conformity to apply remedial actions;
(2)
the obligation on the certification body to inform other relevant market surveillance authorities where the non-conformity concerns relevant Union legislation;
(3)
the conditions for carrying out remedial actions by the holder of the certificate of conformity;
(4)
the conditions for the suspension of a certificate of conformity by the certification body and for restoration of the certificate of conformity after the non-conformity has been remediated;
(5)
the conditions for cancellation of a certificate of conformity by the certification body;
(6)
the consequences of non-compliance by the certification body with the requirements of the national certification scheme.