Consequences of non-compliance by the conformity assessment body
Article 31
1. In case of non-compliance by a certification body with its obligations, or by the relevant certification body in case of identifying non-compliance by an ITSEF, the national cybersecurity certification authority shall, without undue delay: (a) identify, with the support of the concerned ITSEF, the potentially affected EUCC certificates; (b) where necessary, request evaluation activities to be performed on one or more ICT products or protection profiles by either the ITSEF which performed the evaluation, or any other accredited and, where applicable, authorised ITSEF that may be in a better technical position to support that identification; (c) analyse the impacts of non-compliance; (d) notify the holder of the EUCC certificate affected by non-compliance. 2. On the basis of the measures referred to in paragraph 1, the certification body shall adopt either of the following decisions with respect to each affected EUCC certificate: (a) maintain the EUCC certificate unaltered; (b) withdraw the EUCC certificate in accordance with Article 14 or Article 20, and, where appropriate, issue a new EUCC certificate. 3. On the basis of the measures referred to in paragraph 1, the national cybersecurity certification authority shall: (a) where necessary, report the non-compliance of the certification body or related ITSEF to the national accreditation body; (b) where applicable, assess the potential impact on the authorisation.