Commission Implementing Regulation (EU) 2024/3144of 18 December 2024amending Implementing Regulation (EU) 2024/482 as regards applicable international standards and correcting that Implementing Regulation(Text with EEA relevance)
32024R3144
European Union
§ Article 1
Article 1(4) shall apply from 8 January 2025.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 18 December 2024.
For the Commission
The President
Ursula von der Leyen
Annex
ANNEX I
.
Annex
ANNEX I
State-of-the-art documents supporting technical domains and other state-of-the-art documents
- State-of-the-art documents supporting technical domains at AVA_VAN level 4 or 5:
(a) the following documents related to the harmonised evaluation of technical domain smart cards and similar devices:
(1) Minimum ITSEF requirements for security evaluations of smart cards and similar devices, version 1.1;
(2) Minimum Site Security Requirements, version 1.1;
(3) Application of Common Criteria to integrated circuits, version 1.1;
(4) Security Architecture requirements (ADV_ARC) for smart cards and similar devices, version 1.1;
(5) Certification of open smart card products, version 1.1;
(6) Composite product evaluation for smart cards and similar devices, version 1.1;
(7) Application of Attack Potential to Smartcards and Similar Devices, version 1.2;
(b) the following documents related to the harmonised evaluation of technical domain hardware devices with security boxes:
(1) Minimum ITSEF requirements for security evaluations of hardware devices with security boxes, version 1.1;
(2) Minimum Site Security Requirements, version 1.1;
(3) Application of Attack Potential to hardware devices with security boxes, version 1.2.
- State-of-the-art documents related to the harmonised accreditation of conformity assessment bodies:
(a) Accreditation of ITSEFs for the EUCC, version 1.1 for accreditations issued before 8 July 2025.
(b) Accreditation of ITSEFs for the EUCC, version 1.6c, for accreditations that are newly issued or reviewed after 8 July 2025.
(c) Accreditation of CBs for the EUCC, version 1.6b.
Annex
ANNEX II
In Annex IV to Implementing Regulation (EU) 2024/482, Section IV.3, points 5 and 6 are replaced by the following:
- Where the changes have been confirmed by the certification body to be minor, no new certificate shall be issued for the modified ICT product and a maintenance report to the initial certification report shall be established.
The maintenance report shall be included as a subset of the impact analysis report, containing following sections:
(a) introduction;
(b) description of changes;
(c) affected developer evidence.
- The maintenance report referred to in point 5 shall be provided to ENISA for publication on its cybersecurity certification website..
Metadata
- Type
- Forordning
- År
- 2024
- Ikrafttrædelsesdato
- 1. januar 1970