Common Criteria and Post-Quantum Cryptography: What Changes for Certified Products
The cryptography inside certified products is about to change in a way it has not since the move from single DES. Not because anything is broken today, but because the algorithms that protect long-lived data and devices are being replaced before a large quantum computer exists to break the old ones. The standards landed in 2024. The certificates have to follow.
This post is about that follow-on. What post-quantum cryptography (PQC) actually is at this point, how Common Criteria and EUCC handle cryptography, and what the transition means for the smart cards, secure elements, and security appliances that carry certificates.
The standards are no longer hypothetical
For years PQC was a NIST competition and a research topic. That phase is over. In August 2024 NIST published the first three finished standards:
- FIPS 203, ML-KEM: a key-encapsulation mechanism derived from CRYSTALS-Kyber, for establishing shared keys.
- FIPS 204, ML-DSA: a digital signature scheme derived from CRYSTALS-Dilithium.
- FIPS 205, SLH-DSA: a stateless hash-based signature scheme derived from SPHINCS+, valued because its security rests on hash functions rather than lattice problems.
NIST has since selected HQC as a backup key-encapsulation mechanism, to be standardised separately, so the ecosystem is not betting everything on lattice-based maths. The authoritative reference is the NIST Post-Quantum Cryptography project.
The point for our world is simple: these are now named, versioned algorithms that an evaluation can reference, the same way it references AES or ECDSA today.
Why the pressure is here before the threat is
The usual objection is that there is no quantum computer that can break RSA or elliptic-curve cryptography yet. That is true, and it does not buy as much time as it sounds.
Two reasons. First, harvest now, decrypt later: an adversary can record encrypted data today and decrypt it once the capability exists. Anything with a long confidentiality lifetime, government records, health data, identity credentials, is already at risk. Second, certified products are long-lived. A secure element designed into a passport, a payment card, or an industrial controller may be in the field for ten or fifteen years. If it cannot be updated, the algorithm it ships with has to be safe for that whole window. The product that needs PQC first is precisely the kind that gets a Common Criteria certificate.
How Common Criteria handles cryptography today
This is where people misread the impact. Common Criteria does not usually re-prove the mathematics of an algorithm. As we covered in Common Criteria vs FIPS 140-3, CC evaluations typically defer algorithm-level correctness to a cryptographic catalogue and focus on the security architecture around it.
In the US that catalogue is FIPS and the Cryptographic Algorithm Validation Program. In Europe, evaluations under EUCC and the national CC schemes lean on the SOG-IS Agreed Cryptographic Mechanisms document, the reference for which algorithms and parameters are acceptable in an evaluated product. So the first gate for PQC in European certification is not each lab; it is that catalogue adding the new algorithms and their approved parameters.
What CC does assess directly is the implementation. For a smart card or secure element, that is the hard part. A lattice-based scheme like ML-KEM or ML-DSA has a different side-channel and fault-attack surface than RSA or ECC, and the augmented vulnerability analysis (AVA_VAN) that high-assurance hardware undergoes has to be redone against the new code and the new attack surface. That is genuine evaluation work, which is why a PQC update is rarely a free ride on an existing certificate.
What changes for a certified product
Walk it through the way a vendor experiences it:
- The Security Target changes. Adding a post-quantum algorithm changes the cryptographic claims the product makes. A claim change means the Security Target is no longer the document that was evaluated.
- That triggers maintenance or re-evaluation. Depending on the scope of the change, the vendor goes through an assurance continuity or maintenance process, or a fresh evaluation. We described the spectrum of post-issuance change in What Actually Changes After a Product Is Certified; a new algorithm sits at the heavier end of it.
- Hybrid is the common first step. Many early movers do not rip out classical cryptography. They ship a hybrid scheme that runs a classical and a post-quantum mechanism together, so the product is no weaker than before even if the new algorithm has a surprise. Germany’s BSI has been an early and vocal proponent of this hybrid approach in its guidance.
- Crypto-agility becomes a design question. A product that can swap algorithms in firmware has a short path through all of the above. A product that baked one algorithm into silicon needs a new part. Buyers are starting to ask which one they are getting.
What this means for procurement
For procurement teams, PQC adds a question to the list you already ask about a certificate. It is not enough that a product is certified; for anything with a long deployment life, the relevant questions are whether it has a post-quantum path, whether that path is a firmware update or a hardware refresh, and whether the certificate you are relying on still describes the configuration you will actually run once PQC is enabled.
This is the same discipline that already applies to assurance level and evaluated scope, extended to the algorithm layer. A certificate issued in 2024 against classical-only cryptography is still a valid certificate. It just may not describe the post-quantum configuration you will need by the end of the decade.
What to watch
The transition will show up in the catalogue as a wave of maintenance updates and re-issuances rather than a single event. Concretely, the things worth tracking over the next few years are the SOG-IS catalogue adding the new algorithms and parameters, the first EUCC and CCRA certificates citing ML-KEM or ML-DSA in their Security Targets, and national roadmaps (the US CNSA 2.0 suite, the EU coordinated transition roadmap) firming up their dates. The standards are done. The certified ecosystem catching up is the part that will play out in public, one updated certificate at a time.
How NenkinTracker helps you see the transition
PQC migration is going to be visible as document changes: updated Security Targets, new certification reports, fresh issuances of familiar products. NenkinTracker versions the documents behind every certification it tracks and flags when they change, so you can watch specific products and vendors move to post-quantum cryptography instead of rechecking scheme portals by hand. If you maintain a portfolio of certified hardware, you can start tracking for free.
See also
- Common Criteria vs FIPS 140-3: how CC and FIPS split responsibility for cryptography
- What Actually Changes After a Product Is Certified: the maintenance and re-evaluation path a PQC update follows
- What is a Security Target?: where a product states its cryptographic claims
- BSI (German scheme): an early mover on post-quantum guidance and hybrid schemes
- What is Common Criteria?: the evaluation methodology under discussion