- Articles 12-21 support voluntary assurance, testing and certification body qualifications, mandatory catalogue-product assurance, and mandatory service certification.
References and citations
- Articles 2 and 6-15 support the distinct system-level purpose, lifecycle, evidence, retention, and filing of application security assessment.
- Use as a current example of the separate commercial cryptography product certification catalogue and its product descriptions and certification bases.
- Articles 3, 5, and 15-20 support testing-body qualification and approved scope, independence, authorized-signatory and seal checks, six-year record retention, sample controls, and annual reporting.
- Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- Lists representative commercial cryptography product types used in official assessment and testing knowledge materials; the list supports examples, not a mandatory-catalogue conclusion.
- Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- Article 25 supports the current network critical equipment and network security-specific product assurance requirement.
- Supports the amendment's 1 January 2026 effective date.
- Articles 9 and 11-15 support the separate CII product, service, technology, and application-assessment requirements.