Kjartan Kvassness Jæger

Co-founder, Nenkin Technologies AS
Kjartan brings two decades of hands-on Common Criteria experience to the Nenkin editorial team. He spent 18 years at the Norwegian national security authority, the last six as Technical Manager of the country’s CC certification scheme, where he represented Norway in the Common Criteria Development Board, the SOG-IS Joint Interpretation Working Group, and ISO SC 27/WG3. Today he also runs Scandicert AS, providing high-assurance certification services to the Dutch government scheme for SESIP IoT platform certifications and eIDAS QSCD evaluations.
Kjartan is the editorial owner of the Nenkin blog and writes about Common Criteria certification, the EUCC framework, and the broader assurance scheme landscape that NenkinTracker tracks day to day.
Areas of expertise
- Common Criteria evaluation and certification
- High-assurance security certification
- Secure hardware: smart cards, SoCs, and Trusted Execution Environments
- SESIP IoT platform certification
- eIDAS QSCD certification for digital signatures
Posts by Kjartan Kvassness Jæger
Common Criteria and Post-Quantum Cryptography: What Changes for Certified Products
Post-quantum algorithms are now standardised, and the certified products that ship cryptography will have to follow. Here is what PQC means for Common Criteria and EUCC evaluations.
The EU Cyber Resilience Act and EUCC: How Common Criteria Fits the New Rules
The Cyber Resilience Act makes security a condition of selling digital products in the EU. Here is how it connects to EUCC and Common Criteria, and what changes for vendors and buyers.
Smart Card Chip Vendors Compared: ST, NXP, Infineon, Samsung by the Numbers
A factual head-to-head of the four largest secure-element vendors using NenkinTracker certification data: total certs, EAL distribution, top Protection Profiles, scheme coverage, and year-by-year volume.
The Least-Used Protection Profiles: a Procurement Caution Tale
Half of the 267 Protection Profiles in our catalogue have just one conforming product. Specifying a rare PP in procurement can mean vendor lock-in or no certified products at all.
May 2026 in Common Criteria: 32 New Certifications Across Five Schemes
A monthly recap of what got certified in May 2026, who shipped it, and what we noticed. French electronic identity led the month, and year-to-date CCRA volume is the highest in five years.
EUCC Migration Tracker: 30 Certificates In, How Many Are Real Migrations?
An honest progress check on the EU's EUCC scheme after 14 months. Issuance velocity, NCCA distribution, and whether the 30 EUCC certificates replace CCRA predecessors or just layer on top.
EAL 6+ vs FIPS 140-3: How the High End of Each Standard Actually Compares
EAL 6+ and FIPS 140-3 Level 4 are often described as 'the highest tier' of their respective standards, but they evaluate different things. Here is how they actually compare for HSMs, smart cards, and high-assurance products.
The FIPS 140-2 Sunset in September 2026: What Procurement and Vendors Need to Check Now
FIPS 140-2 certificates move to the CMVP historical list in September 2026. Here is what shifts on that date, the RFP language that breaks, and the re-validation lead times procurement and vendor teams should plan against.
Why "EAL4" and "EAL4+" Are Not the Same Thing for Procurement
Two products labelled EAL4+ can carry very different augmentations. A procurement-focused look at why the plus sign hides what matters and how to specify it correctly.
Procurement Planning Before the Certificate Exists
Knowing which products are currently under evaluation at the major certification bodies extends procurement, compliance, and vendor planning horizons by roughly a year. Use cases for each.
How to Read a Common Criteria Security Target as a Buyer (Not an Evaluator)
A buyer-side reading guide for Common Criteria Security Targets: match the TOE to the SKU, read assumptions against your deployment, and decide buy or no-buy before signature.
Six Years on the Certifier's Side of the Table: What Buyers Should Know
Six years as Technical Manager of Norway's Common Criteria scheme. What that vantage point reveals about the certificates buyers are actually relying on.
The 12 Red Flags We Look for in a Vendor's Certified-Product Bid
Twelve recurring patterns that turn a clean-looking certified-product bid into one that needs rework. A buyer-side checklist from the certifier's side of the table.
What to watch at ICCC26: a curtain-raiser for Common Criteria in Rome
ICCC26 brings the Common Criteria community to Rome from 28 September to 1 October 2026. A curtain-raiser on the tracks, the EUCC and CRA undercurrents, the sponsor roster, and the host scheme's own transition.
EUCC at 30 certifications: a year-one check-in
EUCC has crossed 30 published certificates just over a year after the scheme became operational. A look at what the corpus says about scheme maturity, the CAB landscape, and the categories of products being certified.
When the source moves silently: a quiet EUCC reformat and what it tells us about CC publishing
ENISA changed the EUCC certificate identifier format catalogue-wide on its public portal, with no announcement and no changelog. The episode is a reminder that the Common Criteria publishing layer needs a shared contract, not just goodwill.
App Defense Alliance: Google's Android security program is now tracked
NenkinTracker added the App Defense Alliance (ADA) as our 8th certification scheme. Around 220 Android-app certifications are now ingested, including Standard ADA and the lighter Legacy MASA track.
432 Certifications Expire in the Next 12 Months: A Procurement Planning View
Across the schemes we track, 432 certificates expire between May 2026 and May 2027. Here is the by-scheme, by-month, and by-vendor view procurement and compliance teams need to plan re-evaluation.
The Origin of Mutual Recognition: From SOG-IS to CCRA and EUCC
A short history of mutual recognition in IT security evaluations, from early European cooperation through SOG-IS and ITSEC, to the global CCRA, and onward into the EUCC regulatory framework.
From SOG-IS to CCRA and EUCC: The New Landscape of Common Criteria Recognition
How European Common Criteria recognition evolved from ITSEC and SOG-IS through the global CCRA into today's EUCC regulatory framework, and what their coexistence means for vendors and procurement authorities.
CAB and Lab Independence in Common Criteria: When the Separation Matters Most
Why independence between the evaluation lab (ITSEF) and certification body matters in Common Criteria and EUCC, and how to apply ISO 31000-style risk assessment to combined lab/CB structures at substantial versus high assurance.
Anatomy of an EUCC Certificate: A Walkthrough of EUCC-3095-2026-01
An EUCC certificate from April 2026, taken apart piece by piece. Cert ID structure, NCCA versus CAB, the document set, EAL choice, and what is distinctive about EUCC compared with classical CCRA certificates.
April 2026 in Common Criteria: 31 New Certifications Across Five Schemes
A monthly recap of what got certified, who shipped it, and what we noticed in the document trail. Plus year-to-date context on a busy first four months of 2026.
Common Criteria in 2026 So Far: 243 Certifications, Heavy on Smart Card Silicon
Where the first four months of 2026 went in Common Criteria and adjacent schemes: issuance volume by month and scheme, top vendors, EAL distribution, and what the data tells us.
The Most-Used Protection Profiles in Common Criteria, by Product Count
Of the 267 Protection Profiles tracked in NenkinTracker, a small number account for the majority of certified products. Here is the head and the long tail.
What Actually Changes After a Product Is Certified
Field notes from monitoring document updates across seven certification schemes, from cosmetic PDF rewrites to substantive changes that arguably warrant re-evaluation.
Common Criteria vs EUCC: A Migration Guide for Vendors and Buyers
EUCC is the EU's regulatory Common Criteria scheme replacing SOG-IS. What changes, what stays the same, and how vendors and buyers should plan the transition.
How to Read a Common Criteria Certificate
A field guide to the parts of a Common Criteria certificate: what each line means, what to verify, and where the real scope of the evaluation actually lives.
SESIP vs Common Criteria: When to Choose Each
SESIP and Common Criteria both certify the security of IT products. They are not interchangeable. A practical comparison for IoT product makers, integrators, and procurement teams.
Which EAL Do I Need? A Procurement Decision Guide
Pick the right Common Criteria Evaluation Assurance Level by working from threat model and procurement requirements, not vendor marketing. A practical decision guide.
Common Criteria vs FIPS 140-3: What's the Difference?
Common Criteria and FIPS 140-3 are both IT security evaluation standards, but they serve different purposes. Learn when each applies and how they compare.
Guide to EAL Levels: What EAL2, EAL4, and EAL5+ Actually Mean
Evaluation Assurance Levels (EAL1-EAL7) determine how rigorously a product is tested under Common Criteria. Learn what each level requires and which one your procurement needs.
Common Criteria Certification Process Explained
A step-by-step guide to how Common Criteria certification works, from preparation to certificate issuance, including timelines, costs, and key participants.
EUCC: What the EU Cybersecurity Certification Scheme Means for Common Criteria
The EUCC brings Common Criteria-based certification under the EU Cybersecurity Act. Learn what changes, who is affected, and what it means for existing CC certificates.
Common Criteria Schemes by Country: BSI, ANSSI, NIAP, and Others
A reference guide to the major Common Criteria certification schemes worldwide: who runs them, what they certify, and how they differ.
Introducing the Nenkin Blog
Welcome to the Nenkin blog, your source for Common Criteria certification news, guides, and industry insights.