detailed setup and procedure such that the results could be reproduced. 4. Results on the search for potential vulnerabilities in the public domain, including the list of search terms. 5. Test cases and results of the penetration testing. The test cases could be described in high level. Recording of detailed setup and procedures are required only for test cases which succeeded in exploiting the DUT. 6.5.2 The testing laboratory shall also arrange for a meeting with CCC to present the results. 6.5.3 The testing laboratory may be required to perform additional testing if CCC deems the testing performed to be inadequate. 6.5.4 During the course of testing, if the testing laboratory discovers any discrepancies or false declarations in the developer’s declaration of conformance to the Security Baseline Requirements or Lifecycle requirements, the testing laboratory is to provide the information to CCC, CCC reserves the full rights to enforce actions as described in Chapter 8.7 of CLS Publication #1 – Overview of the Scheme [3]. CLS Publication #2 | Page 19 of 49

Select target paragraph3