Evaluation standards
Article 1
Implementing Regulation (EU) 2024/482 is amended as follows: (1) in Article 2, points (1) and (2) are replaced by the following: ‘(1) “Common Criteria” means the Common Criteria for Information Technology Security Evaluation, as set out in standards ISO/IEC 15408-1:2022, ISO/IEC 15408-2:2022, ISO/IEC 15408-3:2022, ISO/IEC 15408-4:2022 or ISO/IEC 15408-5:2022, or set out in Common Criteria for Information Technology Security Evaluation, version CC:2022, Parts 1 through 5, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security; (2) “Common Evaluation Methodology” means the Common Methodology for Information Technology Security Evaluation, as set out in standard ISO/IEC 18045:2022, or the Common Methodology for Information Technology Security Evaluation, version CEM:2022, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security;’; (2) Article 3 is replaced by the following: ‘Article 3 Evaluation standards 1. The following standards shall apply to evaluations performed under the EUCC scheme: (a) the Common Criteria; (b) the Common Evaluation Methodology. 2. Until 31 December 2027, a certificate may be issued under the EUCC scheme applying either of the following standards: (a) ISO/IEC 15408-1:2009, ISO/IEC 15408-2:2008 or ISO/IEC 15408-3:2008; (b) Common Criteria for Information Technology Security Evaluation, version 3.1, revision 5, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security; (c) ISO/IEC 18045:2008; (d) Common Methodology for Information Technology Security Evaluation, revision 5, version 3.1, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security. 3. Until 31 December 2027, a certificate applying the standards referred to in paragraph 1 may be issued under the EUCC scheme claiming conformance to a protection profile that has applied the standards listed in paragraph 2. 4. A certificate applying the standards referred to in paragraph 1 may also be issued under the EUCC scheme claiming conformance to a protection profile that has applied either of the following standards, provided that the use of such protection profile is required under Commission Implementing Regulation (EU) 2016/799 ( *1 ) , Regulation (EU) No 910/2014 of the European Parliament and of the Council ( *2 ) or Commission Implementing Decision (EU) 2016/650 ( *3 ) : (a) Common Criteria for Information Technology Security Evaluation, version 3.1, revision 1 to 4, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security; (b) Common Methodology for Information Technology Security Evaluation, version 3.1., revision 1 to 4, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security. ( *1 ) Commission Implementing Regulation (EU) 2016/799 of 18 March 2016 implementing Regulation (EU) No 165/2014 of the European Parliament and of the Council laying down the requirements for the construction, testing, installation, operation and repair of tachographs and their components ( OJ L 139, 26.5.2016, p. 1 , ELI: http://data.europa.eu/eli/reg_impl/2016/799/oj )." ( *2 ) Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC ( OJ L 257, 28.8.2014, p. 73 , ELI: http://data.europa.eu/eli/reg/2014/910/oj )." ( *3 ) Commission Implementing Decision (EU) 2016/650 of 25 April 2016 laying down standards for the security assessment of qualified signature and seal creation devices pursuant to Articles 30(3) and 39(2) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market ( OJ L 109, 26.4.2016, p. 40 , ELI: http://data.europa.eu/eli/dec_impl/2016/650/oj ).’;" (3) in Chapter IV the following Article 20a is inserted: ‘Article 20a Specification of requirements for accreditation of conformity assessment bodies The accreditation of conformity assessment bodies shall take into account the specification of requirements for accreditation of certification bodies and ITSEFs as laid down in the applicable state-of-the-art documents listed in point 2 of Annex I.’ ; (4) Articles 23 and 24 are deleted; (5) in Article 48, the following paragraph 4 is added: ‘4. Unless specified otherwise in Annex I or II, state-of-the-art documents shall apply from the date of application of the amending act by which they have been incorporated in Annex I or II.’ ; (6) in Article 49, the following paragraph 4 is added: ‘4. When conducting the review referred to in paragraph 3 within two years of the issuance of initial certificate and where such a review leads to the issuance of a new certificate in accordance with this Regulation, the standards listed in Article 3(2) may be applied. The date of issuance of the initial certificate shall be understood as the date of issuance of the last certificate for a ICT product or protection profile on which the current certification is based on.’ ; (7) Annex I is replaced by the text in Annex I to this Regulation; (8) Annex IV is amended in accordance with Annex II to this Regulation.