Monitoring activities by the certification body
Article 26
1. The certification body shall monitor: (a) the compliance of the holders of a certificate with their obligations under this Regulation and Regulation (EU) 2019/881 towards the EUCC certificate that was issued by the certification body; (b) the compliance of the ICT products it has certified with their respective security requirements; (c) the assurance expressed in the certified protection profiles. 2. The certification body shall undertake its monitoring activities on the basis of: (a) the information provided on the basis of the commitments of the applicant for certification referred to in Article 9(2); (b) information resulting from activities of other relevant market surveillance authorities; (c) complaints received; (d) vulnerability information that could impact the ICT products it has certified. 3. The national cybersecurity certification authority may draw up rules for a periodical dialogue between certification bodies and holders of EUCC certificates to verify and report on compliance with the commitments made pursuant to Article 9(2), without prejudice to activities related to other relevant market surveillance authorities.