How long is information security service Qualification (CCRC) valid? Where is the issuing authority?

20 19-202 1, 10, 18, valid for one year, issued by: China Network Security Review Technology and Certification Center; At present, the latest certification requirements are revised as: the validity period is three years, and at least 1 times of supervision and audit shall be conducted within 12- 18 months after obtaining the certificate.

The latest notice is as follows:

According to the present situation and development demand of information security service's qualification certification business, China Network Security Review Technology and Certification Center revised the service qualification certification specification and implementation rules, and the new versions of CCRC-ISV-C01:2021information security service Specification and CCRC-ISV-R0 1 information security service Qualification Certification Implementation Rules.

In order to implement the requirements of the new version of service qualification certification standards and implementation rules, do a good job in the corresponding replacement work, and ensure that the certified institutions in our center continue to meet the requirements of information security qualification service qualification certification, we hereby notify you of the replacement work arrangements in our center as follows:

1. From now on, our center will begin to accept certification applications in accordance with the new version of the certification implementation rules, and will no longer accept certification applications in accordance with the old version of the certification implementation rules.

2. During the validity period, all certificates issued in accordance with the old implementation rules are still valid, and the certified institutions can convert certificates according to annual supervision and inspection or actual needs. The organization holding the newly issued certification certificate shall be abolished at the same time according to the original implementation rules of the old version.

3. All information security service qualification certificates issued in accordance with the requirements of the implementation rules of the old version of certification will be converted before September 30, 2022, and the certificates that have not been converted within the time limit will be suspended.