Skip to content
Nenkin

From SOG-IS to CCRA and EUCC: The New Landscape of Common Criteria Recognition

Common Criteria certifications originate from many different schemes and regulatory ecosystems around the world.

Historically, developers, procurement authorities and integrators often treated “Common Criteria certified” as a relatively unified concept. In reality, the ecosystem has always consisted of multiple national schemes, overlapping recognition arrangements, different assurance philosophies and varying political objectives.

At Nenkin, one of our goals is to make this landscape easier to understand. Nenkin tracks cybersecurity certifications across multiple schemes and sources globally, helping users follow certifications, vulnerabilities, assurance claims, document changes and scheme activity in one place.

To understand the current transition from the Senior Officials Group Information Systems Security Mutual Recognition Agreement (SOG-IS MRA) to the EUCC, it is important to understand that the roots of European mutual recognition predate Common Criteria itself.

Before Common Criteria

Long before online certification portals, harmonised international standards and modern cybersecurity regulation, several European governments operated national IT security evaluation schemes using their own national criteria.

This was an era before email became routine workplace infrastructure. Certified product lists and evaluation information were exchanged physically between governments, often on paper. The ecosystem was small, government-centric and built largely around bilateral trust relationships between national security authorities.

The original Senior Officials Group Information Systems Security (SOG-IS) emerged from this environment as a European governmental cooperation forum focused on information assurance and security evaluation.

Over time, these nations recognised that duplicating expensive government evaluations across Europe created unnecessary inefficiencies. This led to early forms of mutual recognition built around the now-discontinued ITSEC criteria framework.

Although the ITSEC ecosystem never became globally dominant, it introduced many of the concepts that later became central to Common Criteria:

  • assurance levels,
  • harmonised methodologies,
  • evaluator cooperation,
  • technical peer confidence,
  • and cross-border recognition of evaluation results.

When the Common Criteria Recognition Arrangement (CCRA) was established in 1999, many of these ideas were effectively internationalised. In many ways, the CCRA can be viewed as a global evolution of concepts first explored through European SOG-IS and ITSEC cooperation. For the detailed origin of the MRAs, read The Origin of Mutual Recognition: From SOG-IS to CCRA and EUCC.

For a period during the late 1990s and early 2000s, there was genuine optimism that Common Criteria could become a globally unified assurance language for commercial IT products.

Reality turned out to be more complicated.

Two Recognition Systems, One Increasingly Complex Ecosystem

For many years, Europe operated under two overlapping recognition arrangements:

  • the global CCRA,
  • and the European SOG-IS MRA.

Although they shared historical roots, they evolved in different directions.

The Global CCRA

The CCRA was designed as a global framework open to any participating nation willing to meet the required peer confidence obligations.

Its original ambition was broad mutual recognition of certificates up to EAL4.

That changed significantly with the 2014 revision of the arrangement:

  • traditional Security Target-based evaluations effectively retained mutual recognition only up to EAL2,
  • while broader recognition shifted toward collaborative Protection Profiles (cPPs),
  • with ALC_FLR security patching assurance continuing to receive wider recognition.

The revised CCRA moved away from the earlier “recognise everything up to EAL4” philosophy and toward a more profile-centric assurance model.

The European SOG-IS MRA

At the same time, SOG-IS maintained a parallel European recognition structure.

Outside technical domains, SOG-IS recognised evaluations up to EAL4. Within technical domains such as smart cards and hardware security devices, recognition could extend to EAL7.

This created a layered recognition landscape:

  • global recognition through CCRA,
  • and deeper regional recognition through SOG-IS.

In practice, this became difficult for vendors, procurement authorities and even experienced practitioners to interpret consistently.

A product certified at EAL5 by a SOG-IS scheme might:

  • carry only EAL2 recognition under CCRA,
  • retain higher recognition only inside specific SOG-IS technical domains,
  • and still lack mutual recognition of ALC_FLR security patching under SOG-IS itself.

The result was a recognition matrix that became increasingly difficult to understand.

The practical outcome was often that highly rigorous evaluations achieved little additional internationally recognised assurance value compared to substantially simpler evaluations.

At the same time, neither CCRA nor SOG-IS ever created automatic obligations for governments to accept products in procurement simply because they were mutually recognised.

That misunderstanding has persisted for years.

Mutual recognition did not automatically mean procurement acceptance, deployment approval or operational accreditation. Governments retained broad discretion based on procurement policy, national security considerations and sector-specific regulation.

The Hidden Complexity of the SOG-IS Era

The SOG-IS system also developed operational characteristics that increasingly frustrated both vendors and some participating schemes.

Technical domains became highly specialised communities with significant internal expertise, particularly around smart cards and hardware evaluations. While this improved technical depth, it also created barriers to transparency and market accessibility.

Admission into technical domains was slow, politically sensitive and heavily unanimous-driven. In practice, new entrants faced a difficult path toward full participation.

The ecosystem also relied on closed technical interpretation documents and evaluator guidance papers, including methodologies maintained within groups such as JHAS for smart card evaluations.

These documents were often unavailable not only to the public, but also to the end customers whose risks the evaluations were intended to address.

Over time, this contributed to a perception that parts of the recognition ecosystem had become increasingly opaque and difficult for outsiders to navigate.

At the same time, national interpretations of Common Criteria requirements gradually diverged between schemes. This weakened the predictability that mutual recognition was originally intended to provide.

Enter the EUCC

The EU Cybersecurity Act fundamentally changed the direction of European cybersecurity certification.

It mandated the European Union Agency for Cybersecurity to develop EU-wide cybersecurity certification schemes. The first major result was EUCC, adopted by the European Commission in 2024 and entering into force in 2025.

Structurally, EUCC is the successor to the SOG-IS era, but it differs in several important ways. For a deeper introduction to the scheme, see our earlier post on the EU Cybersecurity Certification Scheme.

Unlike SOG-IS, which was always a voluntary intergovernmental arrangement, EUCC is an EU implementing regulation.

This is an important distinction.

EU member states are legally bound by it, and national certification schemes must transition into the EUCC framework. This represents a major governance shift, from voluntary recognition cooperation toward formal regulatory harmonisation.

EUCC Introduces Commercial Certification Bodies

Under SOG-IS, certification was mostly government-centric with only a few commercial CBs. The most known were set up in the United States, the Netherlands and Italy, while additional variants also exist.

Under EUCC, accredited commercial conformity assessment bodies can operate as ITSEFs (evaluation laboratories) and Certification Bodies (CBs).

These bodies operate under:

  • ISO/IEC 17025 accreditation for laboratories,
  • ISO/IEC 17065 accreditation for certification bodies,
  • with supervision by national cybersecurity certification authorities (NCCAs).

For the High assurance level, additional NCCA authorisation is required.

This introduces significantly greater scalability into the European certification ecosystem if implemented effectively. We have written more about how this separation works in CAB and Lab Independence in Common Criteria.

EUCC Simplifies Recognition

Rather than using the traditional EAL1 to EAL7 recognition structure directly, EUCC introduces the assurance levels:

  • Substantial
  • High

The fragmented recognition matrix that characterised the CCRA and SOG-IS overlap is largely replaced with a single EU-wide recognition model.

The old questions:

“Which arrangement recognises this level?”

“Does this apply inside or outside technical domains?”

“Is ALC_FLR recognised?”

become far less central under EUCC.

The New Complication: EUCC and CCRA Coexistence

The transition, however, is not entirely seamless.

The CCRA and EUCC are built on somewhat different trust models.

Historically, CCRA recognition depended on certification schemes designed and set up by the individual member state, peer assessments and direct intergovernmental trust relationships developed over decades.

EUCC introduces commercial certification bodies operating under accreditation and regulatory supervision rather than direct government issuance of certificates.

From the CCRA perspective, this introduces a perceived structural trust gap.

This issue is formally acknowledged in the CCRA Management Committee document concerning CCRA and EUCC coexistence published in 2025.

The solution proposed is pragmatic, but follows already established CCRA practices used by several CCRA members. EUCC certificates may optionally carry the CCRA mark if additional government oversight is applied by the NCCA on a per-certificate basis.

Under this model the NCCA reviews the Security Target and assessment scope, reviews technical reporting before approval and ultimately authorises use of the CCRA recognition mark.

Importantly, the EUCC certificate itself remains valid even if the CCRA mark is withheld.

This creates a layered coexistence model rather than a direct merger between the two systems. We unpack more of this overlap in our Common Criteria vs EUCC migration guide.

What This Means for Vendors and Procurement Authorities

For developers and vendors, EUCC offers a significantly clearer path to EU-wide recognition than the old SOG-IS patchwork.

The replacement of closed interpretation communities with published state-of-the-art documents improves transparency, even if the resulting framework remains highly technical.

The introduction of commercial CBs should also gradually improve evaluation capacity and reduce bottlenecks.

Whether to additionally pursue CCRA recognition becomes a strategic decision:

  • products targeting primarily EU regulatory environments may rely solely on EUCC,
  • while products targeting broader international markets may still benefit from CCRA recognition.

For procurement authorities, the situation is improved, but not fully simplified.

An EUCC High certificate supervised by an NCCA represents a substantially different assurance proposition than the fragmented recognition arrangements of the past.

At the same time, the old reality still applies: mutual recognition does not automatically create procurement obligations.

That remains a matter of policy, regulation and operational risk acceptance outside the certification schemes themselves.

A More Mature View of Mutual Recognition

Earlier debates around Common Criteria recognition often became polarised: either mutual recognition was portrayed as highly effective, or as fundamentally broken.

Reality has always been more nuanced.

Mutual recognition operates simultaneously on several levels:

LayerWhat it actually enables
PoliticalConfidence building between governments
TechnicalRe-use of assurance evidence
CommercialReduced duplication for vendors
RegulatorySupport for market access
ProcurementSometimes relevant, but never automatic

The core issue historically was not that mutual recognition accomplished nothing.

Rather, the expectations surrounding recognition often exceeded what the arrangements themselves were ever designed to guarantee.

The Road Ahead

The transition from SOG-IS to EUCC represents more than an administrative change.

It reflects a broader evolution in how cybersecurity assurance is governed: from relatively informal intergovernmental cooperation toward formal regulatory ecosystems tied directly to digital market regulation.

At the same time, the CCRA continues serving an important role as a global interoperability and coordination framework. Neither system fully replaces the other.

The long-term trajectory now appears to be either gradual convergence or long-term structured coexistence between:

  • the EU regulatory certification ecosystem,
  • and the broader global CCRA framework.

Whether that eventually evolves into a fully unified international recognition model remains uncertain.

What is already clear, however, is that understanding the governance structure behind a certificate is becoming just as important as understanding the technical evaluation itself.

And that is exactly the kind of complexity Nenkin is built to help navigate.