My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/3144 of 18 December 2024 amending Implementing Regulation (EU) 2024/482 as regards applicable international standards and correcting that Implementing Regulation

Commission Implementing Regulation (EU) 2024/3144 of 18 December 2024 amending Implementing Regulation (EU) 2024/482 as regards applicable international standards and correcting that Implementing Regulation

Implementing Regulation (EU) 2024/3144 · Regulation · 5 articles

Data as of 2026-07-04 · Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Evaluation standards

Article 1

Implementing Regulation (EU) 2024/482 is amended as follows: (1) in Article 2, points (1) and (2) are replaced by the following: ‘(1) “Common Criteria” means the Common Criteria for Information Technology Security Evaluation, as set out in standards ISO/IEC 15408-1:2022, ISO/IEC 15408-2:2022, ISO/IEC 15408-3:2022, ISO/IEC 15408-4:2022 or ISO/IEC 15408-5:2022, or set out in Common Criteria for Information Technology Security Evaluation, version CC:2022, Parts 1 through 5, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security; (2) “Common Evaluation Methodology” means the Common Methodology for Information Technology Security Evaluation, as set out in standard ISO/IEC 18045:2022, or the Common Methodology for Information Technology Security Evaluation, version CEM:2022, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security;’; (2) Article 3 is replaced by the following: ‘Article 3 Evaluation standards 1.   The following standards shall apply to evaluations performed under the EUCC scheme: (a) the Common Criteria; (b) the Common Evaluation Methodology. 2.   Until 31 December 2027, a certificate may be issued under the EUCC scheme applying either of the following standards: (a) ISO/IEC 15408-1:2009, ISO/IEC 15408-2:2008 or ISO/IEC 15408-3:2008; (b) Common Criteria for Information Technology Security Evaluation, version 3.1, revision 5, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security; (c) ISO/IEC 18045:2008; (d) Common Methodology for Information Technology Security Evaluation, revision 5, version 3.1, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security. 3.   Until 31 December 2027, a certificate applying the standards referred to in paragraph 1 may be issued under the EUCC scheme claiming conformance to a protection profile that has applied the standards listed in paragraph 2. 4.   A certificate applying the standards referred to in paragraph 1 may also be issued under the EUCC scheme claiming conformance to a protection profile that has applied either of the following standards, provided that the use of such protection profile is required under Commission Implementing Regulation (EU) 2016/799  ( *1 ) , Regulation (EU) No 910/2014 of the European Parliament and of the Council  ( *2 ) or Commission Implementing Decision (EU) 2016/650  ( *3 ) : (a) Common Criteria for Information Technology Security Evaluation, version 3.1, revision 1 to 4, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security; (b) Common Methodology for Information Technology Security Evaluation, version 3.1., revision 1 to 4, published by the participants of the Arrangement on the Recognition of Common Criteria Certificates in the field of IT Security. ( *1 )   Commission Implementing Regulation (EU) 2016/799 of 18 March 2016 implementing Regulation (EU) No 165/2014 of the European Parliament and of the Council laying down the requirements for the construction, testing, installation, operation and repair of tachographs and their components ( OJ L 139, 26.5.2016, p. 1 , ELI: http://data.europa.eu/eli/reg_impl/2016/799/oj )." ( *2 )   Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC ( OJ L 257, 28.8.2014, p. 73 , ELI: http://data.europa.eu/eli/reg/2014/910/oj )." ( *3 )   Commission Implementing Decision (EU) 2016/650 of 25 April 2016 laying down standards for the security assessment of qualified signature and seal creation devices pursuant to Articles 30(3) and 39(2) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market ( OJ L 109, 26.4.2016, p. 40 , ELI: http://data.europa.eu/eli/dec_impl/2016/650/oj ).’;" (3) in Chapter IV the following Article 20a is inserted: ‘Article 20a Specification of requirements for accreditation of conformity assessment bodies The accreditation of conformity assessment bodies shall take into account the specification of requirements for accreditation of certification bodies and ITSEFs as laid down in the applicable state-of-the-art documents listed in point 2 of Annex I.’ ; (4) Articles 23 and 24 are deleted; (5) in Article 48, the following paragraph 4 is added: ‘4.   Unless specified otherwise in Annex I or II, state-of-the-art documents shall apply from the date of application of the amending act by which they have been incorporated in Annex I or II.’ ; (6) in Article 49, the following paragraph 4 is added: ‘4.   When conducting the review referred to in paragraph 3 within two years of the issuance of initial certificate and where such a review leads to the issuance of a new certificate in accordance with this Regulation, the standards listed in Article 3(2) may be applied. The date of issuance of the initial certificate shall be understood as the date of issuance of the last certificate for a ICT product or protection profile on which the current certification is based on.’ ; (7) Annex I is replaced by the text in Annex I to this Regulation; (8) Annex IV is amended in accordance with Annex II to this Regulation.

Information necessary for certification and evaluation of protection profiles

Article 2

Implementing Regulation (EU) 2024/482 is corrected as follows: (1) in Article 5(1), point (b) is replaced by the following: ‘(b) claiming conformance to a certified protection profile as part of the ICT process, where the ICT product falls in the ICT product category covered by that protection profile.’; (2) Article 8 is corrected as follows: (a) the title is replaced by the following: ‘Information necessary for certification and evaluation’; (b) paragraph 1 is replaced by the following: ‘1.   An applicant for certification under EUCC shall provide or otherwise make available to the certification body and the ITSEF all information necessary for the certification and evaluation activities.’ ; (3) Article 16 is replaced by the following: ‘Article 16 Information necessary for certification and evaluation of protection profiles An applicant for certification of a protection profile shall provide or otherwise make available to the certification body and the ITSEF all information necessary for the certification and evaluation activities in a complete and correct form. Article 8(2), (3), (4) and (7) shall apply mutatis mutandis .’ ; (4) in Article 17, paragraph 1 is deleted; (5) in Article 29, paragraph 2 is replaced by the following: ‘2.   Where the holder of the EUCC certificate does not propose appropriate remedial action during the time period referred to in paragraph 1, the certificate shall be suspended in accordance with Article 30 or withdrawn in accordance with Article 14 or Article 20.’.

Article 3

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union . Article 1(4) shall apply from 8 January 2025.

Supplementary provisions

ANNEX ISupplementary provisions

ANNEX I ‘ANNEX I State-of-the-art documents supporting technical domains and other state-of-the-art documents 1.    State-of-the-art documents supporting technical domains at AVA_VAN level 4 or 5: (a) the following documents related to the harmonised evaluation of technical domain “smart cards and similar devices”: (1) “Minimum ITSEF requirements for security evaluations of smart cards and similar devices”, version 1.1; (2) “Minimum Site Security Requirements”, version 1.1; (3) “Application of Common Criteria to integrated circuits”, version 1.1; (4) “Security Architecture requirements (ADV_ARC) for smart cards and similar devices”, version 1.1; (5) “Certification of ‘open’ smart card products”, version 1.1; (6) “Composite product evaluation for smart cards and similar devices”, version 1.1; (7) “Application of Attack Potential to Smartcards and Similar Devices”, version 1.2; (b) the following documents related to the harmonised evaluation of technical domain “hardware devices with security boxes”: (1) “Minimum ITSEF requirements for security evaluations of hardware devices with security boxes”, version 1.1; (2) “Minimum Site Security Requirements”, version 1.1; (3) “Application of Attack Potential to hardware devices with security boxes”, version 1.2. 2.    State-of-the-art documents related to the harmonised accreditation of conformity assessment bodies: (a) “Accreditation of ITSEFs for the EUCC”, version 1.1 for accreditations issued before 8 July 2025. (b) “Accreditation of ITSEFs for the EUCC”, version 1.6c, for accreditations that are newly issued or reviewed after 8 July 2025. (c) “Accreditation of CBs for the EUCC”, version 1.6b. ’.

ANNEX IISupplementary provisions

ANNEX II In Annex IV to Implementing Regulation (EU) 2024/482, Section IV.3, points 5 and 6 are replaced by the following: ‘5. Where the changes have been confirmed by the certification body to be minor, no new certificate shall be issued for the modified ICT product and a maintenance report to the initial certification report shall be established. The maintenance report shall be included as a subset of the impact analysis report, containing following sections: (a) introduction; (b) description of changes; (c) affected developer evidence. 6. The maintenance report referred to in point 5 shall be provided to ENISA for publication on its cybersecurity certification website.’.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next