Source: OJ L, 2025/2392, 1.12.2025

Current language: EN

Article 1 Definitions


Summary What does Article 1 of the Technical description of product categories say?

This is a definitions article, establishing the precise meaning of two key technical terms used throughout the regulation.

Rather than creating new standalone definitions, it anchors both terms directly to an existing piece of EU law — Implementing Regulation (EU) 2024/482 — meaning the definitions are imported from and dependent on that separate regulatory instrument.

Important points:

  • Two definitions are established: Common Criteria and Common Evaluation Methodology, both relating to IT security evaluation.
  • Both definitions draw their meaning from Implementing Regulation (EU) 2024/482, creating a direct legal dependency on that act.
  • These definitions lay the terminological foundation for the rest of this regulation, so understanding their source in Implementing Regulation (EU) 2024/482 is essential for interpreting subsequent articles.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

For the purposes of this Regulation, the following definitions shall apply:

  1. Common Criteria’ means the Common Criteria for Information Technology Security Evaluation as defined in Article 2(1) of Implementing Regulation (EU) 2024/482 or as set out in the standards referred to in Article 3(2), points (a) and (b), of that Implementing Regulation;

  2. Common Evaluation Methodology’ means the Common Methodology for Information Technology Security Evaluation as defined in Article 2(2) of Implementing Regulation (EU) 2024/482 or as set out in the standards referred to in Article 3(2), points (c) and (d), of that Implementing Regulation.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod