Law / European Union

EUCC Certification Scheme, Vulnerability Impact Analysis Report and Disclosure

Commission Implementing Regulation (EU) 2024/482, Arts. 35 and 39

In force since .

A vulnerability and incident reporting rule binding public and private bodies.

Obligation class
Reporting, Disclosure

As of .

What it requires

  • It reaches you if you hold an EUCC certificate for an ICT product (Article 32). Where your vulnerability impact analysis shows that a vulnerability has a likely impact on the conformity of the ICT product with its certificate, produce a vulnerability impact analysis report that assesses the impact of the vulnerability on the certified ICT product, possible risks associated with the proximity or availability of an attack, whether the vulnerability may be remedied and, where it may, possible resolutions (Article 35(1) and (2)).
  • Include in the report, where applicable, details about the possible means of exploitation of the vulnerability, and handle that information under appropriate security measures that protect its confidentiality and ensure, where necessary, its limited distribution (Article 35(3)).
  • Transmit the report to the certification body or the national cybersecurity certification authority, in accordance with Article 56(8) of Regulation (EU) 2019/881, without undue delay (Article 35(4)).
  • Monitor any residual vulnerabilities to ensure that they cannot be exploited if the operational environment changes (Article 35(7)).
  • Upon withdrawal of the certificate, disclose and register any publicly known and remediated vulnerability in the ICT product on the European vulnerability database established under Article 12 of Directive (EU) 2022/2555, or on the other online repositories referred to in Article 55(1), point (d), of Regulation (EU) 2019/881 (Article 39).

Who enforces it

Enforcement body

The certification body that issued the certificate, which sets a period of not more than 30 days for remedial action when the holder does not comply with Chapter VI and then suspends or withdraws the certificate (Article 29(1), point (b), and (2)), and the national cybersecurity certification authority, which monitors the compliance of holders of an EUCC certificate with their obligations (Article 25(1), point (b)).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 35(1) of Commission Implementing Regulation (EU) 2024/482 requires the holder of an EUCC certificate to produce a vulnerability impact analysis report where the impact analysis shows that the vulnerability has a likely impact on the conformity of the ICT product with its certificate.

Article 35(2) requires the report to assess the impact of the vulnerability on the certified ICT product, possible risks associated with the proximity or availability of an attack, whether the vulnerability may be remedied and, where it may, possible resolutions of the vulnerability.

Article 35(3) requires the report, where applicable, to contain details about the possible means of exploitation of the vulnerability, which must be handled under appropriate security measures to protect its confidentiality and ensure, where necessary, its limited distribution. Article 35(4) requires the holder to transmit the report to the certification body or the national cybersecurity certification authority, in accordance with Article 56(8) of Regulation (EU) 2019/881, without undue delay.

Article 35(6) provides that, where the report determines that the vulnerability is not residual and that it cannot be remedied, the EUCC certificate shall be withdrawn in accordance with Article 14. Article 35(7) requires the holder to monitor any residual vulnerabilities to ensure that they cannot be exploited if the operational environment changes.

Article 39 requires the holder, upon withdrawal of a certificate, to disclose and register any publicly known and remediated vulnerability in the ICT product on the European vulnerability database established under Article 12 of Directive (EU) 2022/2555 or on the other online repositories referred to in Article 55(1), point (d), of Regulation (EU) 2019/881.

Article 37(2) provides that the information the certification body gives to the national cybersecurity certification authority shall not contain details of the means of exploitation of the vulnerability, without prejudice to the investigative powers of that authority. Article 38(1) requires the national cybersecurity certification authority to share the relevant information it receives under Article 37 with other national cybersecurity certification authorities and ENISA.

Article 29(1), point (b), gives a holder that does not comply with Article 56(8) of Regulation (EU) 2019/881 or Chapter VI a period of not more than 30 days to take remedial action. Article 29(3) provides that continued or recurring infringement of those obligations by the holder triggers the withdrawal of the certificate. Article 50 applies the Regulation from .

When LexLint raises it

When your app profile says your app distributes a software product.

Back to the example  ·  Lint your app