My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/482 Article 37

Commission Implementing Regulation (EU) 2024/482 Article 37

Information shared with the national cybersecurity certification authority

Article 37

1.   The information provided by the certification body to the national cybersecurity certification authority shall include all elements necessary for the national cybersecurity certification authority to understand the impact of the vulnerability, the changes to be made to the ICT product and, where available, any information from the certification body on the broader implications of the vulnerability for other certified ICT products. 2.   The information provided in accordance with paragraph 1 shall not contain details of the means of exploitation of the vulnerability. This provision is without prejudice to the investigative powers of the national cybersecurity certification authority.

Read the full instrument → · Read this in context: SECTION II — Vulnerability disclosure →

Other provisions in SECTION II — Vulnerability disclosure

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 37 of Commission Implementing Regulation (EU) 2024/482 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next