EUCC Certification Scheme, Vulnerability Management by the Holder of a Certificate
Commission Implementing Regulation (EU) 2024/482, Arts. 32-34 and 36
In force since .
A product security requirements rule binding public and private bodies.
- Obligation class
- Security, Governance
As of .
What it requires
- It reaches you if you hold an EUCC certificate for an ICT product issued under the European Common Criteria-based cybersecurity certification scheme; Chapter VI applies to ICT products for which an EUCC certificate was issued (Article 32). Establish and maintain all necessary vulnerability management procedures in accordance with Chapter VI, supplemented where necessary by the procedures set out in EN ISO/IEC 30111 (Article 33(1)).
- Maintain and publish appropriate methods for receiving information on vulnerabilities related to your products from external sources, including users, certification bodies and security researchers (Article 33(2)).
- When you detect or receive information about a potential vulnerability affecting a certified ICT product, record it and carry out a vulnerability impact analysis (Article 33(3)).
- Refer the vulnerability impact analysis to the target of evaluation and the assurance statements contained in the certificate, carry it out in a timeframe appropriate for the exploitability and criticality of the potential vulnerability and, where applicable, perform an attack potential calculation to determine its exploitability, taking the AVA_VAN level of the certificate into account (Article 34(1) and (2)).
- When a potential vulnerability impacts a composite product, inform the holders of dependent EUCC certificates (Article 33(4)).
- In response to a reasonable request by the certification body that issued the certificate, transmit all relevant information about potential vulnerabilities to that certification body (Article 33(5)).
- Where the vulnerability impact analysis report determines that a vulnerability is not residual and can be remedied, submit a proposal for an appropriate remedial action to the certification body (Article 35(5) and Article 36).
Who enforces it
Enforcement body
The certification body that issued the certificate, which sets a period of not more than 30 days for remedial action when the holder does not comply with Chapter VI and then suspends or withdraws the certificate (Article 29(1), point (b), and (2)), and the national cybersecurity certification authority, which monitors the compliance of holders of an EUCC certificate with their obligations (Article 25(1), point (b)).
What this law does
Article 32 of Commission Implementing Regulation (EU) 2024/482 provides that Chapter VI applies to ICT products for which an EUCC certificate was issued. Article 1 applies the Regulation to all ICT products, including their documentation, that are submitted for certification under the EUCC.
Article 33(1) requires the holder of an EUCC certificate to establish and maintain all necessary vulnerability management procedures, supplemented where necessary by the procedures set out in EN ISO/IEC 30111. Article 33(2) requires the holder to maintain and publish appropriate methods for receiving information on vulnerabilities related to its products from external sources, including users, certification bodies and security researchers.
Article 33(3) requires the holder, when it detects or receives information about a potential vulnerability affecting a certified ICT product, to record it and carry out a vulnerability impact analysis. Article 33(4) requires the holder, when a potential vulnerability impacts a composite product, to inform the holder of dependent EUCC certificates.
Article 33(5) requires the holder, in response to a reasonable request by the certification body that issued the certificate, to transmit all relevant information about potential vulnerabilities to that certification body. Article 34(1) requires the vulnerability impact analysis to refer to the target of evaluation and the assurance statements contained in the certificate and to be carried out in a timeframe appropriate for the exploitability and criticality of the potential vulnerability.
Article 34(2) requires, where applicable, an attack potential calculation to determine the exploitability of the vulnerability, and requires the AVA_VAN level of the certificate to be taken into account. Article 35(5) provides that Article 36 applies where the vulnerability impact analysis report determines that the vulnerability is not residual and that it can be remedied. Article 36 requires the holder to submit a proposal for an appropriate remedial action to the certification body.
Article 29(1), point (b), requires the certification body, where the holder does not comply with Chapter VI, to set a time period of not more than 30 days within which the holder shall take remedial action. Article 29(2) provides that, where the holder does not propose appropriate remedial action in that period, the certificate shall be suspended or withdrawn.
Article 25(1), point (b), makes the national cybersecurity certification authority responsible for monitoring the compliance of holders of an EUCC certificate with their obligations. Article 50 applies the Regulation from .
When LexLint raises it
When your app profile says your app distributes a software product.