5.6.2 If vulnerabilities are identified during testing, the testing laboratory shall
describe the identified vulnerabilities in the report and state the method of
resolution undertaken by the developer.
5.6.3 During the course of testing, if the testing laboratory discovers any
discrepancies or false declarations in the developer’s declaration of
conformance to the Security Baseline Requirements or Lifecycle
requirements, the testing laboratory is to provide the information to CCC,
CCC reserves the full rights to enforce actions as described in Chapter 8.7
of CLS Publication #1 – Overview of the Scheme [3].
CLS Publication #2 | Page 14 of 49