On January 28th, our experts took part in a webinar on the EUCC scheme, where they explained the differences between EUCC and CCRA/SOG-IS.
In the second part of our webinar, our experts discussed how the EUCC scheme will impact North American vendors. Lachlan Turner from Lightship Security engaged in an insightful panel with our European experts, Javier Tallon and Jose Ruiz, addressing key questions and concerns from North American clients about the EUCC scheme. Below is a summary of the main topics discussed.
EUCC certification is not mandatory by itself but may be required by other regulations such as the Cyber Resilience Act. Vendors previously needing SOG-IS certification will likely need EUCC certification. Additionally, marketing and sales considerations may drive the need for EUCC certification to stay competitive.
Member States can individually decide to recognize CCRA certificates for a transition period of up to five years. However, this decision is up to each Member State and may vary.
In the absence of mutual recognition agreements, vendors may need to obtain separate certificates for NIAP and EUCC. However, much of the evaluation work can be reused, and larger labs with multiple locations can facilitate this process efficiently.
While the core standard remains the same, EUCC introduces new obligations such as vulnerability handling and reporting. Additionally, the EUCC certificate will include specific assurance levels like AVA_VAN.1.
Vendors must have vulnerability handling procedures in place and report vulnerabilities to the ITSEF and certification body. The specifics of the reporting process are still being defined, but it will include timelines for notification and remediation.
State-of-the-art documents are mandatory and provide guidance on evaluation processes. These documents are dynamically updated and must be followed during evaluations.
This Q&A session provided valuable insights into the EUCC scheme, helping vendors understand the requirements and processes involved. Stay tuned for more updates and detailed guidance as the EUCC scheme continues to evolve.
Watch the full video:
Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.
They allow the operation of the website, loading media content and its security. See the cookies we store in our Cookies Policy.
They allow us to know how you interact with the website, the number of visits in the different sections and to create statistics to improve our business practices. See the cookies we store in our Cookies Policy.