Skip to content
Nenkin

EAL 6+ vs FIPS 140-3: How the High End of Each Standard Actually Compares

Procurement specs for high-assurance products often pin both a Common Criteria EAL and a FIPS 140-3 level. A typical line item: “EAL 5+ or higher, FIPS 140-3 Level 3 or higher.” That phrasing is fine, because each clause picks one standard’s ladder. The trouble starts when someone tries to collapse the two into a single tier: “EAL 6+ is roughly FIPS 140-3 Level 4, right?”

It is not. The question is asking which level on ladder A corresponds to which level on ladder B, when the two ladders measure different buildings.

This guide is the answer for the high end specifically: EAL 6, EAL 6+, and EAL 7 on the Common Criteria side, and FIPS 140-3 Level 3 and Level 4 on the cryptographic side. If you want the general comparison, start with the Common Criteria vs FIPS 140-3 overview.

The short answer

EAL 6+ and FIPS 140-3 Level 4 are not equivalent, comparable, or interchangeable. They evaluate different things:

  • EAL 6+ evaluates the whole product’s design and implementation, using semiformal verification of the security policy and High attack potential vulnerability analysis. Scope: whatever the Security Target says it is, typically a smart card OS, separation kernel, or high-assurance embedded platform.
  • FIPS 140-3 Level 4 evaluates a cryptographic module’s algorithms, key management, physical tamper resistance, and environmental failure protection against NIST-defined module requirements. Scope: the cryptographic boundary, not the surrounding product.

A product can hold both, one, or neither. High-end HSMs and government smart cards usually hold both. Neither programme references the other as a prerequisite.

EAL 6+ scope: the whole TOESemiformal design, ADV_SPM.1, ADV_INT.3, ALC_DVS.2, AVA_VAN.5Security architectureRoles, audit, lifecycleMemory protectionSide-channel hardeningLayered TCB internalsSecure boot, attestationFIPS 140-3 Level 4 scopeCAVP-validated algorithmsKey management lifecycleActive tamper responseEnvironmental failure protectionSelf-tests and RNG
The cryptographic module covered by FIPS 140-3 Level 4 sits inside the larger TOE covered by EAL 6+. Both can be true of the same product, but each certificate stops at its own boundary.

What EAL 6+ actually evaluates

EAL 6 is the second-highest Common Criteria assurance level. It is defined in ISO/IEC 15408-3 and demands semiformal verification of design correspondence, layered internal structure, and vulnerability analysis at High attack potential. The ”+” adds augmentations on top of base EAL 6.

The key assurance components at EAL 6 include:

  • ADV_SPM.1: a formal security policy model, written in a mathematically precise notation
  • ADV_TDS.5: a complete semiformal modular design of the TOE
  • ADV_INT.3: minimally complex, layered TOE internals, so the trusted computing base can be minimized
  • ADV_IMP.2: a complete mapping of the implementation representation
  • ALC_CMC.5 and ALC_DVS.2: hardened life-cycle controls and demonstrated sufficiency of development security measures
  • AVA_VAN.5: advanced methodical vulnerability analysis assuming High attack potential (experts with specialized equipment and extended time)

Two things to note. First, EAL 6 already includes AVA_VAN.5, so the ”+” in EAL 6+ is usually flaw remediation (ALC_FLR.2 or ALC_FLR.3) rather than a stronger attack model. Always read the Security Target to see exactly what was augmented. Second, the gap between EAL 5+ with AVA_VAN.5 and base EAL 6 is in design assurance, not attacker model: both resist High attack potential, but EAL 6 forces a formal policy model, semiformal design verification, and layered internals on top.

Where you actually see EAL 6 and EAL 6+ certificates: top-tier smart card ICs, smart card operating systems, a small set of high-assurance separation kernels, and a handful of defense or critical-infrastructure trust anchors. Almost all of them come out of BSI or ANSSI, which were the SOG-IS schemes that historically issued the highest-assurance smart card certificates and that pattern carried into EUCC.

EAL 7 sits above EAL 6 by replacing semiformal artifacts with formal ones across the functional specification (ADV_FSP.6), TOE design (ADV_TDS.6), and correspondence between them. Vulnerability analysis stays at AVA_VAN.5. For a cryptographic product the practical effect is that EAL 7 forces the TOE scope down to a small, formally tractable core. That is why HSMs and smart card OSes target EAL 5+ or EAL 6+ rather than EAL 7: the useful TOE is too large to verify formally end to end. EAL 7 is reserved for things like separation kernels, where the formally verified core is the product.

What FIPS 140-3 actually evaluates

FIPS 140-3 is the NIST cryptographic module standard, derived from ISO/IEC 19790. A FIPS 140-3 evaluation runs against the cryptographic module boundary, defined by the vendor and reviewed by an accredited Cryptographic and Security Testing (CST) laboratory. The Cryptographic Module Validation Program (CMVP), run jointly by NIST and CCCS, issues the certificate.

Eleven requirement areas are tested across four assurance levels. The two relevant to this comparison are Level 3 and Level 4.

FIPS 140-3 Level 3

Level 3 introduces serious physical security expectations:

  • Identity-based authentication: operators authenticate as individuals, not just roles
  • Strong tamper resistance: enclosures detect tampering and actively zeroize plaintext critical security parameters (CSPs) when attacked
  • Operator authentication for service entry: cryptographic services that touch CSPs require authenticated access
  • Trusted channels: critical security parameters cross module boundaries only over trusted channels with strong cryptographic protection
  • Module software/firmware integrity: digitally signed and version-controlled

Level 3 is the realistic ceiling for most commercial HSMs that need to fit into PCIe slots, USB form factors, or 1U appliances. The vast majority of HSM cryptographic modules on the CMVP validated list are Level 3.

FIPS 140-3 Level 4

Level 4 adds two things that drive cost and engineering effort significantly:

  • Environmental failure protection (EFP) or environmental failure testing (EFT): the module must detect and respond safely to extreme voltage, temperature, and frequency conditions designed to subvert it. This is meant to defeat attacks that try to glitch or freeze the module into leaking keys.
  • Multi-factor identity-based authentication for cryptographic officers
  • Physical security at the highest level: full enclosure protection against intrusion, including grids, conductive shields, or potting that triggers active zeroization on penetration

In practice, Level 4 modules are tamper-active in a way Level 3 modules typically are not: physical attack does not just leave evidence, it causes the module to destroy its own keys before the attacker can extract them. The form factor cost is significant. Level 4 modules are usually large, expensive, and dedicated to high-value protection use cases (root key storage for PKIs, certificate authorities, military and intelligence cryptographic systems).

The Level 4 validated module list at CMVP is much shorter than Level 3. Many vendors who could technically reach Level 4 stop at Level 3 because procurement does not demand the extra cost.

Why a direct mapping does not work

It is tempting to line up the two ladders. EAL 6+ at the top of the practical CC range, FIPS 140-3 Level 4 at the top of the FIPS range, and call them comparable tiers. The mapping fails for three independent reasons.

Different attack surfaces. EAL 6+ resists High attack potential against the security policy claimed in the Security Target. That covers logical attacks, side channels, fault injection, and physical attacks against the whole product, scoped by whatever the ST says is in scope. FIPS 140-3 Level 4 resists physical and environmental attacks against the cryptographic module specifically. The two cover overlapping but not identical surfaces. A cryptographic module’s tamper response is one thing the CC evaluator might check via AVA_VAN.5, but it is not what the EAL number itself promises.

Different evaluation methodology. EAL 6+ verifies that the design correctly implements the security policy through formal modelling and semiformal correspondence. FIPS 140-3 verifies that the cryptographic module passes specific NIST-defined tests, including CAVP algorithm validation. The CC evaluator reads design documents and reasons about correspondence; the CST lab runs algorithm test vectors and physical tamper tests. Both are rigorous, but they answer different questions.

Different scope. EAL 6+ TOEs can be very large: a smart card OS includes a memory manager, file system, applet runtime, communication stack, and crypto library. FIPS 140-3 cuts a smaller boundary inside that: just the cryptographic engine. The CC certificate says something about the whole TOE; the FIPS certificate says something about a subset of it.

Put together: an EAL 6+ smart card OS without a FIPS 140-3 validation on its crypto module gives you assurance about the OS design and side-channel resistance, but no NIST-blessed statement that the algorithm implementations match the standards. A FIPS 140-3 Level 4 cryptographic module without a CC certificate around it gives you assurance about the crypto and physical tamper resistance, but no statement about how the surrounding product handles roles, audit, or secure boot.

Where they coincide in real products

Most products at the high end carry both. The pairing follows a pattern by product category.

Product categoryTypical CC targetTypical FIPS 140-3 target
Top-tier smart card IC (chip)EAL 5+ or EAL 6+ with AVA_VAN.5, against a chip PPOften validated as part of a composite; the chip itself may not carry a separate FIPS cert
Smart card OS / Java Card platformEAL 5+ or EAL 6+, composite with the chip certFIPS 140-3 Level 3 on the cryptographic services
Network HSM (PCIe / appliance)EAL 4+ with AVA_VAN.5, against the HSM PP or a vendor STFIPS 140-3 Level 3, occasionally Level 4 for root-key use cases
Cloud HSM service backendEAL 4+ on the underlying module (inherited)FIPS 140-3 Level 3 on the underlying module (inherited)
Secure element / eSIMEAL 4+ to EAL 5+ against eUICC or SE PPsFIPS 140-3 Level 3 (less common at Level 4)
High-assurance separation kernelEAL 6+ or EAL 7Not applicable (no crypto module boundary inside the kernel)
Defense / TS-grade cryptographic moduleEAL 6+ where required by national schemeFIPS 140-3 Level 4 where US federal mandates apply
Typical certification pairings at the high end. Specific products vary; always check the actual certificate set.

A few patterns are worth calling out.

HSMs cluster at EAL 4+ and FIPS Level 3. Even though HSMs are the obvious candidate for high assurance on both axes, the commercial reality is that most procurement specs settle for EAL 4+ with AVA_VAN.5 and FIPS 140-3 Level 3. The jump to EAL 5+ or EAL 6+ on the CC side, or to Level 4 on the FIPS side, is reserved for a narrower set of programmes (root certificate authorities, sovereign key escrow, defense).

Smart cards skew higher on EAL than HSMs. Smart card ICs and OSes at EAL 5+ or EAL 6+ are common, because the smart card market historically anchored to SOG-IS High assurance and that pattern persists in EUCC. They typically pair with FIPS 140-3 Level 3 on the cryptographic services, not Level 4, because the form factor and use case do not need Level 4’s environmental failure protection.

EAL 7 products usually do not carry FIPS at all. EAL 7 TOEs are small, formally tractable cores like separation kernels. They do not have a cryptographic module boundary inside them in the FIPS sense, so they are not candidates for a FIPS 140-3 certificate. A larger product wrapping an EAL 7 kernel may have a separately FIPS-validated cryptographic module in another component.

Cost and timeline at the high end

Both certifications are expensive. The combination is more expensive than the sum.

A base EAL 6 evaluation typically runs into the low millions of USD and takes two to four years of calendar time. The cost drivers are the formal security policy model (which most vendors do not have in their existing development process and must build), the semiformal design verification work, the strengthened development security and life-cycle controls, and the AVA_VAN.5 vulnerability analysis. Adding ”+” augmentations such as ALC_FLR.3 increases scope modestly; the bulk of the cost is base EAL 6.

A FIPS 140-3 Level 4 validation typically costs USD 200K to USD 1M and takes 12 to 24 months. The cost driver is the physical security engineering (active tamper response, environmental failure protection) and the CMVP queue at NIST. Level 3 is cheaper because the physical security expectations are bounded.

Combined programmes at EAL 6+ and FIPS 140-3 Level 4 are usually multi-year, multi-million-dollar efforts. Most vendors who go this far have institutional customers who fund the certification cost via long-term contracts. This is why so few products reach this combined tier and why the ones that do tend to come from the same handful of vendors.

When you need which

A simplified decision frame, given a procurement question:

  • Need cryptographic algorithm and physical assurance only? FIPS 140-3 is sufficient. Pick Level 3 for typical commercial HSM use; pick Level 4 for root key storage, certificate authorities, or anything where environmental failure protection is required.
  • Need whole-product assurance only? Common Criteria is sufficient. Pick an EAL that matches the threat model and any applicable Protection Profile. EAL 4+ with AVA_VAN.5 is the practical ceiling for general-purpose IT; EAL 5+ to EAL 6+ for smart card and embedded high-assurance products.
  • Need both? You almost certainly need both certificates, not a single “highest tier” certificate. A CC certificate at EAL 5+ or higher and a FIPS 140-3 validation at Level 3 or higher is the typical pairing.

If procurement asks for “EAL 6+ or FIPS 140-3 Level 4” as alternatives, the spec is malformed. They are not alternatives. Ask the procurement team to pick which of the two underlying questions they are trying to answer: do they want whole-product security architecture assurance, or do they want cryptographic module assurance? Most of the time the honest answer is both, with the right level on each axis.

Tracking

NenkinTracker tracks Common Criteria certifications across all CCRA member schemes, including the EAL 5+, EAL 6, EAL 6+, and EAL 7 long tail. You can filter by EAL, by scheme, by product category, and watch for new certificates, maintenance reports, and expirations.

For FIPS 140-3, the authoritative source remains the CMVP validated modules list maintained by NIST. NenkinTracker does not ingest CMVP today.

To monitor the Common Criteria side across BSI, ANSSI, NIAP, and the wider scheme landscape, you can start tracking for free.

See also

Frequently asked questions

Is EAL 6+ equivalent to FIPS 140-3 Level 4?
No. The two evaluate different things. EAL 6+ assures the design of a whole product against a Security Target, using semiformal verification and High attack potential analysis. FIPS 140-3 Level 4 assures a cryptographic module against NIST-defined requirements, including environmental failure protection and the highest physical security. There is no one-to-one mapping between the two ladders.
What does the + in EAL 6+ mean?
EAL 6+ is a Common Criteria evaluation at base EAL 6 with one or more augmented assurance components. EAL 6 already includes AVA_VAN.5 (High attack potential), so common augmentations are flaw remediation (ALC_FLR.2 or ALC_FLR.3) or stronger development security (ALC_DVS.2 if not already required). Always check the Security Target for the exact augmentations, because two products labelled EAL 6+ can differ.
Why do high-end HSMs and smart cards usually carry both certifications?
A high-assurance HSM or smart card has two distinct things that need evaluating. Common Criteria at EAL 5+ or EAL 6+ assures the whole product's security architecture: access control, role separation, audit, key lifecycle, and so on. FIPS 140-3 (often Level 3, sometimes Level 4) assures the cryptographic module itself: algorithms, key management, and physical tamper resistance. The two certifications cover different surfaces, so most procurement specs ask for both.
How much does an EAL 6+ evaluation cost?
EAL 6+ evaluations are typically in the multi-million USD range and take two to four years of calendar time. The cost driver is the formal security policy model, semiformal design verification, and hardened development process required by EAL 6 assurance components. FIPS 140-3 Level 3 or Level 4 validations are usually cheaper in isolation, often USD 200K to USD 1M, but combine to a substantial multi-million-dollar programme when paired.
Is EAL 7 better than EAL 6+ for cryptographic products?
For most cryptographic products, no. EAL 7 requires complete formal mathematical verification of the design, which scales poorly with complexity. Cryptographic products tend to be large enough that the EAL 7 TOE would have to be scoped down to a small inner core, with the rest of the product outside the certificate boundary. EAL 6+ keeps a more useful TOE scope while still resisting High attack potential.
Does FIPS 140-3 Level 4 require Common Criteria certification?
No. FIPS 140-3 and Common Criteria are independent programmes. A module can be FIPS 140-3 Level 4 validated without any CC certificate, and a product can be CC EAL 6+ certified without any FIPS validation. In practice, high-end HSMs almost always carry both because their procurement markets (US federal, financial services, government) demand both, but neither programme references the other as a prerequisite.