PD CEN-CLC-TS 18072 2025.docx
PDCEN/CLC/TS18072:2025BSIStandardsPublicationRequirementsforConformityAssessmentBodiescertifyingCloudServicesbsi.NationalforewordThisPublishedDocumentistheUKimplementationofCENCLCTS18072:2025.TheUKparticipationinitspreparationwasentrustedtoTechnicalCommitteeIST/33/3,SecurityEvaluation,TestingandSpecification.Alistoforganizationsrepresentedonthiscommitteecanbeobtainedonrequesttoitscommitteemanager.ContractualandlegalconsiderationsThispublicationhasbeenpreparedingoodfaith,howevernorepresentation,warranty,assuranceorundertaking(expressorimplied)isorwillbemade,andnoresponsibilityorliabilityisorwillbeacceptedbyBSIinrelationtotheadequacy,accuracy,completenessorreasonablenessofthispublication.Allandanysuchresponsibilityandliabilityisexpresslydisclaimedtothefullextentpermittedbythelaw.Thispublicationisprovidedasis,andistobeusedattherecipientsownrisk.Therecipientisadvisedtoconsiderseekingprofessionalguidancewithrespecttoitsuseofthispublication.Thispublicationisnotintendedtoconstituteacontract.Usersareresponsibleforitscorrectapplication.ThispublicationisnottoberegardedasaBritishStandard.©TheBritishStandardsInstitution2025PublishedbyBSIStandardsLimited2025ISBN9780539314526ICS03.120.20;35.030CompliancewithaPublishedDocumentcannotconferimmunityfromlegalobligations.ThisPublishedDocumentwaspublishedundertheauthorityoftheStandardsPolicyandStrategyCommitteeon30April2025.Amendments/corrigendaissuedsincepublicationDateTextaffectedTECHNICALSPECIFICATIONCEN/CLC/TS18072SPECIFICATIONTECHNIQUETECHNlSCHESPEZlFIKATlONApril2025ICS03.120.20;35.030EnglishversionRequirementsforConformityAssessmentBodiescertifyingCloudServicesExigencesapplicablesauxOrganismesd'evaluationdeAnforderungenanKonformitatsbewertungsstellen,dielaConformitepourlacertificationdesservicesenCloud-DiensteZertifizierennuageThisTechnicalSpecification(CENTS)wasapprovedbyCENon13October2024forprovisionalapplication.TheperiodofvalidityofthisCEN/TSislimitedinitiallytothreeyears.AftertwoyearsthemembersofCENandCENELECwillberequestedtosubmittheircomments,particularlyonthequestionwhethertheCEN/TScanbeconvertedintoaEuropeanStandard.CENandCENELECmembersarerequiredtoannouncetheexistenceofthisCEN/TSinthesamewayasforanENandtomaketheCEN/TSavailablepromptlyatnationallevelinanappropriateform.Itispermissibletokeepconflictingnationalstandardsinforce(inparalleltotheCEN/TS)untilthefinaldecisionaboutthepossibleconversionoftheCEN/TSintoanENisreached.CENandCENELECmembersarethenationalstandardsbodiesandnationalelectrotechnicalcommitteesofAustria,Belgium,Bulgaria,Croatia,Cyprus,CzechRepublic,Denmark,Estonia,Finland,France,Germany,Greece,Hungary,Iceland,Ireland,Italy,Latvia,Lithuania,Luxembourg,Malta,Netherlands,Norway,Poland,Portugal,RepublicofNorthMacedonia,Romania,Serbia,Slovakia,Slovenia,Spain,Sweden,Switzerland,TiirkiyeandUnitedKingdom.CEN-CENELECManagementCentre:RuedelaScience23,B-1040BrusselsRef.No.CEN/CLC/TS18072:2025E©2025CEN/CENELECAllrightsofexploitationinanyformandbyanymeansreservedworldwideforCENnationalMembersandforCENELECMembers.ContentsPageIntroduction51 Scope62 Normativereferences63 Termsanddefinitions64 Generalrequirements84.1 Legalandcontractualmatters84.1.1 Legalresponsibility84.1.2 Certificationagreement84.1.3 Useoflicense,certificatesandmarksofconformity84.2 Managementofimpartiality84.2.1 General84.2.2 Nonconflictingactivities84.3 Liabilityandfinancing84.4 Non-discriminatoryconditions84.5 Confidentiality94.6 Publiclyavailableinformation95 StructuralRequirements95.1 Organizationalstructureandtopmanagement95.2 Mechanismsforsafeguardingimpartiality96 ResourceRequirements96.1 CertificationbodypersonnelDeterminationofcompetencecriteria96.2 ResourcesforEvaluation97 Processrequirements97.1 Generalrequirements97.2 Application97.3 Applicationreview97.4 Evaluation107.4.1 General107.4.2 Typesofevaluations107.4.3 Preparationoftheevaluation107.4.4 Conductingevaluations177.4.5 Generalrequirementsonconductingevaluations257.5 Review297.6 Certificationdecision297.7 CertificationDocumentation297.8 Directoryofcertifiedproducts307.9 Surveillance307.9.1 Introduction307.9.2 General307.9.3 SurveillanceEvaluation307.9.4 RecertificationEvaluation307.9.5 SpecialEvaluation317.10 Changesaffectingcertification317.11 Termination,reduction,suspensionorwithdrawalofcertification327.12 Records327.13 Complaintsandappeals328 Managementsystemrequirements328.1 Options328.1.1 General328.1.2 OptionA328.1.3 OptionB328.2 Managementsystemdocumentation(OptionA)328.3 Controlofdocuments(OptionA)328.4 Controlofrecords(OptionA)328.5 Managementreview(OptionA)328.5.1 General328.5.2 Reviewinputs328.5.3 Reviewoutputs328.6 InternalAudits(OptionA)328.7 Correctiveactions(OptionA)338.8 Preventiveactions(OptionA)33Annex A (normative)RequiredKnow