My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/482 Article 23

Commission Implementing Regulation (EU) 2024/482 Article 23

Notification of certification bodies

Article 23

1.   The national cybersecurity certification authority shall notify the Commission of the certification bodies in its territory that are competent to certify at assurance level ‘substantial’ based on their accreditation. 2.   The national cybersecurity certification authority shall notify the Commission of the certification bodies in their territory that are competent to certify at assurance level ‘high’ based on their accreditation and the authorisation decision. 3.   The national cybersecurity certification authority shall provide at least the following information when notifying the Commission of the certification bodies: (a) the assurance level or levels for which the certification body is competent to issue EUCC certificates; (b) the following information related to accreditation: (1) date of the accreditation; (2) name and address of the certification body; (3) country of registration of the certification body; (4) reference number of the accreditation; (5) scope and duration of validity of the accreditation; (6) the address, location and link to the relevant website of the national accreditation body; and (c) the following information related to authorisation for level ‘high’: (1) date of the authorisation; (2) reference number of the authorisation; (3) duration of validity of the authorisation; (4) scope of the authorisation including the highest AVA_VAN level and, where applicable, the covered technical domain. 4.   The national cybersecurity certification authority shall send a copy of the notification referred to in paragraphs 1 and 2 to ENISA for the publication of accurate information on the cybersecurity certification website regarding the eligibility of certification bodies. 5.   The national cybersecurity certification authority shall examine without undue delay any information regarding a change in the status of the accreditation provided by the national accreditation body. Where the accreditation or authorisation have been withdrawn, the national cybersecurity certification authority shall inform the Commission thereof, and may submit to the Commission a request in accordance with Article 61(4) of Regulation (EU) 2019/881.

Read the full instrument → · Read this in context: CHAPTER IV — CONFORMITY ASSESSMENT BODIES →

Other provisions in CHAPTER IV — CONFORMITY ASSESSMENT BODIES

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 23 of Commission Implementing Regulation (EU) 2024/482 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next