My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/482 Article 8

Commission Implementing Regulation (EU) 2024/482 Article 8

Information necessary for certification

Article 8

1.   An applicant for certification under EUCC shall provide or otherwise make available to the certification body and the ITSEF all information necessary for the certification activities. 2.   The information referred to in paragraph 1 shall include all relevant evidence in accordance with the sections on ‘Developer action elements’ in the appropriate format as set out in the sections on ‘Content and presentation of evidence element’ of the Common Criteria and Common Evaluation Methodology for the selected assurance level and associated security assurance requirements. The evidence shall include, where necessary, details on the ICT product and its source code in accordance with this Regulation, subject to safeguards against unauthorised disclosure. 3.   Applicants for certification may provide to the certification body and ITSEF appropriate evaluation results from prior certification pursuant to: (a) this Regulation; (b) another European cybersecurity certification scheme adopted pursuant to Article 49 of Regulation (EU) 2019/881; (c) a national scheme referred to in Article 49 of this Regulation. 4.   Where the evaluation results are pertinent to its tasks, the ITSEF may reuse the evaluation results provided that such results conform to the applicable requirements and its authenticity is confirmed. 5.   Where the certification body allows the product to undergo a composite product certification, the applicant for certification shall make available to the certification body and the ITSEF all necessary elements, where applicable, in accordance with the state-of-the-art document. 6.   Applicants for certification shall also provide the certification body and the ITSEF with the following information: (a) the link to their website containing the supplementary cybersecurity information referred to in Article 55 of Regulation (EU) 2019/881; (b) a description of the applicant’s vulnerability management and vulnerability disclosure procedures. 7.   All relevant documentation referred to in this Article shall be retained by the certification body, the ITSEF and the applicant for a period of 5 years after the expiry of the certificate.

Read the full instrument → · Read this in context: SECTION II — Issuance, renewal and withdrawal of EUCC certificates →

Other provisions in SECTION II — Issuance, renewal and withdrawal of EUCC certificates

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 8 of Commission Implementing Regulation (EU) 2024/482 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next