emendrix

Art. 52

Cybersecurity Act · 32019R0881 · every event for this act · on EUR-Lex

Assurance levels of European cybersecurity certification schemes

1 change recorded across 1 event, newest first.

in force 2025-02-04 MODIFIED+314 −109

Amended by Regulation (EU) 2025/37 32025R0037

applies from: unchanged

Paragraphs 1, 3, 5, 6 and 7 of Article 52 now add references to managed security services alongside ICT products, ICT services and ICT processes wherever those categories are listed as subject to assurance levels, security requirements, and evaluation activities.

The prior version of these same paragraphs referred only to ICT products, ICT services and ICT processes, without mention of managed security services.

Cited: Art. 52, v2 · Art. 52, v1

text before / after

32019R088102019R0881-20250204

Article 52 Assurance levels of European cybersecurity certification schemes 1. A European cybersecurity certification scheme may specify one or more of the following assurance levels for ICT products, ICT services services, ICT processes and ICT processes: managed security services: basic, substantial or high. The assurance level shall be commensurate with the level of the risk associated with the intended use of the ICT product, ICT service service, ICT process or ICT process, managed security service, in terms of the probability and impact of an incident. 2. European cybersecurity certificates and EU statements of conformity shall refer to any assurance level specified in the European cybersecurity certification scheme under which the European cybersecurity certificate or EU statement of conformity is issued. 3. The security requirements corresponding to each assurance level shall be provided in the relevant European cybersecurity certification scheme, including the corresponding security functionalities and the corresponding rigour and depth of the evaluation that the ICT product, ICT service or service, ICT process or managed security service is to undergo. 4. The certificate or the EU statement of conformity shall refer to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of, or to prevent cybersecurity incidents. 5. A European cybersecurity certificate or EU statement of conformity that refers to assurance level basic shall provide assurance that the ICT products, ICT services and services, ICT processes or managed security services for which that certificate or that EU statement of conformity is issued meet the corresponding security requirements, including security functionalities, and that they have been evaluated at a level intended to minimise the known basic risks of incidents and cyberattacks. The evaluation activities to be undertaken shall include at least a review of technical documentation. Where such a review is not appropriate, substitute evaluation activities with equivalent effect shall be undertaken. 6. A European cybersecurity certificate that refers to assurance level substantial shall provide assurance that the ICT products, ICT services and services, ICT processes or managed security services for which that certificate is issued meet the corresponding security requirements, including security functionalities, and that they have been evaluated at a level intended to minimise the known cybersecurity risks, and the risk of incidents and cyberattacks carried out by actors with limited skills and resources. The evaluation activities to be undertaken shall include at least the following: a review to demonstrate the absence of publicly known vulnerabilities and testing to demonstrate that the ICT products, ICT services or services, ICT processes or managed security services correctly implement the necessary security functionalities. Where any such evaluation activities are not appropriate, substitute evaluation activities with equivalent effect shall be undertaken. 7. A European cybersecurity certificate that refers to assurance level high shall provide assurance that the ICT products, ICT services and services, ICT processes or managed security services for which that certificate is issued meet the corresponding security requirements, including security functionalities, and that they have been evaluated at a level intended to minimise the risk of state-of-the-art cyberattacks carried out by actors with significant skills and resources. The evaluation activities to be undertaken shall include at least the following: a review to demonstrate the absence of publicly known vulnerabilities; testing to demonstrate that the ICT products, ICT services or services, ICT processes or managed security services correctly implement the necessary security functionalities at the state of the art; and an assessment of their resistance to skilled attackers, using penetration testing. Where any such evaluation activities are not appropriate, substitute activities with equivalent effect shall be undertaken. 8. A European cybersecurity certification scheme may specify several evaluation levels depending on the rigour and depth of the evaluation methodology used. Each of the evaluation levels shall correspond to one of the assurance levels and shall be defined by an appropriate combination of assurance components.