Assurance continuity and certificate review
ANNEX IVSupplementary provisions
ANNEX IV Assurance continuity and certificate review IV.1 Assurance continuity: scope 1. The following requirements for assurance continuity apply to the maintenance activities related to the following: (a) a re-assessment if an unchanged certified ICT product still meets its security requirements; (b) an evaluation of the impacts of changes to a certified ICT product on its certification; (c) if included in the certification, the application of patches in accordance with an assessed patch management process; (d) if included, the review of the certificate holder’s lifecycle management or production processes. 2. The holder of an EUCC certificate may request the review of the certificate in the following cases: (a) the EUCC certificate is due to expire within nine months; (b) there has been a change either in the certified ICT product or in another factor which could impact its security functionality; (c) the holder of the certificate demands that the vulnerability assessment is carried out again in order to reconfirm the EUCC certificate’s assurance associated with the ICT product’s resistance against present cyberattacks. IV.2 Re-assessment 1. Where there is a need to assess the impact of changes in the threat environment of an unchanged certified ICT product, a re-assessment request shall be submitted to the certification body. 2. The re-assessment shall be carried out by the same ITSEF that was involved in the previous evaluation by reusing all its results that still apply. The evaluation shall focus on assurance activities which are potentially impacted by the changed threat environment of the certified ICT product, in particular the relevant AVA_VAN family and in addition the assurance lifecycle (ALC) family where sufficient evidence about the maintenance of the development environment shall be collected again. 3. The ITSEF shall describe the changes and detail the results of the re-assessment with an update of the previous evaluation technical report. 4. The certification body shall review the updated evaluation technical report and establish a re-assessment report. The status of the initial certificate shall then be modified in accordance with Article 13. 5. The re-assessment report and updated certificate shall be provided to the national cybersecurity certification authority and ENISA for publication on its cybersecurity certification website. IV.3 Changes to a certified ICT product 1. Where a certified ICT product has been subject to changes, the holder of the certificate wishing to maintain the certificate shall provide to the certification body an impact analysis report. 2. The impact analysis report shall provide the following elements: (a) an introduction containing necessary information to identify the impact analysis report and the target of evaluation subject to changes; (b) a description of the changes to the product; (c) the identification of affected developer evidence; (d) a description of the developer evidence modifications; (e) the findings and the conclusions on the impact on assurance for each change. 3. The certification body shall examine the changes described in the impact analysis report in order to validate their impact upon the assurance of the certified target of evaluation, as proposed in the conclusions of the impact analysis report. 4. Following the examination, the certification body determines the scale of a change as minor or major in correspondence to its impact. 5. Where the changes have been confirmed by the certification body to be minor, a new certificate shall be issued for the modified ICT product and a maintenance report to the initial certification report shall be established, under following conditions: (a) the maintenance report shall be included as a subset of the impact analysis report, containing following sections: (1) introduction; (2) description of changes; (3) affected developer evidence; (b) the validity date of the new certificate shall not exceed the date of the initial certificate. 6. The new certificate including the maintenance report shall be provided to ENISA for publication on its cybersecurity certification website. 7. Where the changes have been confirmed to be major, a re-evaluation shall be carried out in the context of the previous evaluation and by reusing any results from the previous evaluation that still apply. 8. After completion of the evaluation of the changed target of evaluation, the ITSEF shall establish a new evaluation technical report. The certification body shall review the updated evaluation technical report and, where applicable, establish a new certificate with a new certification report. 9. The new certificate and certification report shall be provided to ENISA for publication. IV.4 Patch management 1. A patch management procedure provides for a structured process of updating a certified ICT product. The patch management procedure including the mechanism as implemented into the ICT product by the applicant for certification can be used after the certification of the ICT product under the responsibility of the conformity assessment body. 2. The applicant for certification may include into the certification of the ICT product a patch mechanism as part of a certified management procedure implemented into the ICT product under one of the following conditions: (a) the functionalities affected by the patch reside outside the target of evaluation of the certified ICT product; (b) the patch relates to a predetermined minor change to the certified ICT product; (c) the patch relates to a confirmed vulnerability with critical effects on the security of the certified ICT product. 3. If the patch relates to a major change to the target of evaluation of the certified ICT product in relation to a previously undetected vulnerability having no critical effects to the security of the ICT product, the provisions of Article 13 apply. 4. The patch management procedure for an ICT product will be composed of the following elements: (a) the process for the development and release of the patch for the ICT product; (b) the technical mechanism and functions for the adoption of the patch into the ICT product; (c) a set of evaluation activities related to the effectiveness and performance of the technical mechanism. 5. During the certification of the ICT product: (a) the applicant for certification of the ICT product shall provide the description of the patch management procedure; (b) the ITSEF shall verify the following elements: (1) the developer implemented the patch mechanisms into the ICT product in accordance to the patch management procedure that was submitted to certification; (2) the target of evaluation boundaries are separated in a way that the changes made to the separated processes do not affect the security of the target of evaluation; (3) the technical patch mechanism performs in accordance with the provisions of this section and the applicant’s claims; (c) the certification body shall include in the certification report the outcome of the assessed patch management procedure. 6. The holder of the certificate may proceed to apply the patch produced in compliance of the certified patch management procedure to the concerned certified ICT product and shall take the following steps within 5 working days in the following cases: (a) in the case referred to in point 2(a), report the patch concerned to the certification body that shall not change the corresponding EUCC certificate; (b) in the case referred to in point 2(b), submit the patch concerned to the ITSEF for review. The ITSEF shall inform the certification body after the reception of the patch upon which the certification body takes the appropriate action on the issuance of a new version of the corresponding EUCC certificate and the update of the certification report; (c) in the case referred to in point 2(c), submit the patch concerned to the ITSEF for the necessary re-evaluation but may deploy the patch in parallel. The ITSEF shall inform the certification body after which the certification body starts the related certification activities.