My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/482 Article 35

Commission Implementing Regulation (EU) 2024/482 Article 35

Vulnerability impact analysis report

Article 35

1.   The holder shall produce a vulnerability impact analysis report where the impact analysis shows that the vulnerability has a likely impact on the conformity of the ICT product with its certificate. 2.   The vulnerability impact analysis report shall contain an assessment of the following elements: (a) the impact of the vulnerability on the certified ICT product; (b) possible risks associated with the proximity or availability of an attack; (c) whether the vulnerability may be remedied; (d) where the vulnerability may be remedied, possible resolutions of the vulnerability. 3.   The vulnerability impact analysis report shall, where applicable, contain details about the possible means of exploitation of the vulnerability. Information pertaining to possible means of exploitation of the vulnerability shall be handled in accordance with appropriate security measures to protect its confidentiality and ensure, where necessary, its limited distribution. 4.   The holder of an EUCC certificate shall transmit a vulnerability impact analysis report to the certification body or the national cybersecurity certification authority in accordance with Article 56(8) of Regulation (EU) 2019/881, without undue delay. 5.   Where the vulnerability impact analysis report determines that the vulnerability is not residual within the meaning of standards referred to in Article 3, and that it can be remedied, Article 36 shall apply. 6.   Where the vulnerability impact analysis report determines that the vulnerability is not residual and that it cannot be remedied, the EUCC certificate shall be withdrawn in accordance with Article 14. 7.   The holder of the EUCC certificate shall monitor any residual vulnerabilities to ensure that it cannot be exploited in case of the changes in the operational environment.

Read the full instrument → · Read this in context: SECTION I — Vulnerability management →

Other provisions in SECTION I — Vulnerability management

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 35 of Commission Implementing Regulation (EU) 2024/482 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next