Monitoring activities by the holder of the certificate
Article 27
1. The holder of an EUCC certificate shall perform the following tasks to monitor the conformity of the certified ICT product with its security requirements: (a) monitor vulnerability information regarding the certified ICT product, including known dependencies by its own means but also in consideration of: (1) a publication or a submission regarding vulnerability information by a user or security researcher referred to in Article 55(1), point (c) of Regulation (EU) 2019/881; (2) a submission by any other source; (b) monitor the assurance expressed in the EUCC certificate. 2. The holder of an EUCC certificate shall work in cooperation with the certification body, the ITSEF, and, where applicable, the national cybersecurity certification authority to support their monitoring activities.