My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/482 ANNEX VI

Commission Implementing Regulation (EU) 2024/482 ANNEX VI

SCOPE AND TEAM COMPOSITION FOR PEER ASSESSMENTS

ANNEX VISupplementary provisions

ANNEX VI SCOPE AND TEAM COMPOSITION FOR PEER ASSESSMENTS VI.1    Scope of the peer assessment 1. The following types of peer assessments are covered: (a) Type 1: when a certification body performs certification activities at the AVA_VAN.3 level; (b) Type 2: when a certification body performs certification activities related to a technical domain listed as state-of-the-art documents in Annex I; (c) Type 3: when a certification body performs certification activities above the AVA_VAN.3 level making use of a protection profile listed as state-of-the-art documents in Annex II or III. 2. The peer-assessed certification body shall submit the list of certified ICT products that may be candidate to the review by the peer assessment team, in accordance with the following rules: (a) the candidate products shall cover the technical scope of the certification body authorisation, of which at least two different products evaluations at assurance level ‘high’ will be analysed through the peer assessment, and one protection profile if the certification body has issued certificate at assurance level ‘high’; (b) for a Type 2 peer assessment, the certification body shall submit at least one product per technical domain and per concerned ITSEF; (c) for a Type 3 peer assessment, at least one candidate product shall be evaluated in accordance with an applicable and relevant protection profiles. VI.2    Peer assessment team 1. The assessment team shall consist of at least two experts each selected from a different certification body from different Member States that issues certificates at the assurance level ‘high’. The experts should demonstrate the relevant expertise in the standards as referred in Article 3 and state-of-the-art documents that are in scope of the peer assessment. 2. In the case of a delegation of certificate issuance or prior approval of certificates as referred to in Article 56(6) of Regulation (EU) 2019/881, an expert from the national cybersecurity certification authority related to the concerned certification body shall in addition participate in the team of experts selected in accordance with paragraph 1 of this Section. 3. For a Type 2 peer assessment the team members shall be selected from certification bodies being authorised for the concerned technical domain. 4. Each member of the assessment team shall have at least two years of experience of carrying out certification activities in a certification body; 5. For a Type 2 or 3 peer assessment, each member of the assessment team shall have at least two years of experience of carrying out certification activities in that relevant technical domain or protection profile and proven expertise and participation in the authorisation of an ITSEF 6. The national cybersecurity certification authority monitoring and supervising the peer-assessed certification body and at least one national cybersecurity certification authority whose certification body is not subject to the peer assessment shall participate in the peer assessment as an observer. ENISA may also participate in the peer assessment as an observer. 7. The peer-assessed certification body is presented with the composition of the peer assessment team. In justified cases, it may challenge the composition of the peer assessment team and ask for its review.

Read the full instrument →

Other provisions in Commission Implementing Regulation (EU) 2024/482

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationANNEX VI of Commission Implementing Regulation (EU) 2024/482 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next