- The joint-authority catalogue supplies the current product categories and technical thresholds and records that it replaced the 2017 catalogue from 3 July 2023.
References and citations
- Articles 11-34 and 38-42 support the detailed standards, testing, certification, electronic certification, import/export, and CII requirements.
- Articles 13-15 support self-assessment sign-off, six-year retention, filing within 30 days, sampling, and incident response.
- Articles 5, 12, and 15-20 support approved-scope, authorized-signatory, seal, six-year retention, and 15 January annual-report duties for testing bodies.
- Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- Articles 2-3 and 10-17 support the license, five-year term, 30-day change filing, renewal timing, annual compliance assessment, annual training hours, and operating requirements effective 1 July 2026.
- Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- Use for the current text, including Article 23 graded protection, Article 25 product assurance, and Articles 33-40 CII duties.
- Supports the amendment's 1 January 2026 effective date.
- Articles 2 and 5-15 support the CII actor boundary, accountable main person, qualified roles, funding, product, service, technology, data-protection, planning, assessment, 31 January annual reporting, and review duties.