Peer assessment procedure
Article 45
1. A certification body issuing EUCC certificates at assurance level ‘high’ shall undergo a peer assessment on a regular basis and at least every 5 years. The different types of peer assessment are listed in Annex VI. 2. The European Cybersecurity Certification Group shall draw up and maintain a schedule of peer assessments ensuring that such periodicity is respected. Except in duly justified cases, peer assessments shall be performed on-site. 3. The peer assessment may rely on evidence gathered in the course of previous peer assessments or equivalent procedures of the peer-assessed certification body or national cybersecurity certification authority, provided that: (a) the results are not older than 5 years; (b) the results are accompanied by a description of the peer assessment procedures established for that scheme where they relate to a peer assessment conducted under a different certification scheme; (c) the peer assessment report referred to in Article 47 specifies which results were reused with or without further assessment. 4. Where a peer assessment covers a technical domain, the concerned ITSEF shall also be assessed. 5. The peer-assessed certification body and, where necessary, the national cybersecurity certification authority shall ensure that all relevant information is made available to the peer assessment team. 6. The peer assessment shall be carried out by a peer assessment team set up in accordance with Annex VI.