1. The certification body shall set a period of validity for each EUCC certificate issued taking into account the characteristics of the certified ICT product.
2. The period of validity of the EUCC certificate shall not exceed 5 years.
3. By derogation from paragraph 2 that period may exceed 5 years, subject to the prior approval of the national cybersecurity certification authority. The national cybersecurity certification authority shall notify the European Cybersecurity Certification Group of the granted approval without undue delay.
Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04
CitationArticle 12 of Commission Implementing Regulation (EU) 2024/482 (LawPlayer, data as of 2026-07-04)