The Origin of Mutual Recognition: From SOG-IS to CCRA and EUCC
To understand mutual recognition in IT security evaluations, it helps to go back to the very beginning. This entry is the historical companion to From SOG-IS to CCRA and EUCC: The New Landscape of Common Criteria Recognition, which focuses on where the ecosystem stands today.
Long before the term SOG-IS became widely used, European nations were already cooperating on the problem of evaluating and recognising trusted IT systems across borders. What later became the Senior Officials Group on Information Systems Security (SOG-IS) emerged during an era that predates Common Criteria, predates the internet as a workplace tool, and even predates email as a routine means of workplace communication by over a decade. Established as an advisory body to the European Commission, SOG-IS brought together security officials from European nations who were developing their own national IT security evaluation criteria for government use.
In those early years, countries such as the UK, France, Norway, Germany and the Netherlands (and others) had each built their own national frameworks for assessing the security of IT products. This led to an expensive and inconsistent situation that made cross-border procurement difficult. The practical solution was low-tech yet effective: member nations would certify products against their national criteria and circulate lists of certified products on paper.
As the group matured, the need for more harmonised criteria became apparent. This led to the development of ITSEC (Information Technology Security Evaluation Criteria), a European standard published in 1991 that attempted to unify the national frameworks. SOG-IS created a Mutual Recognition Agreement around ITSEC, which allowed certificates issued by one member scheme to be recognised by others. Today only version 2.0 of the SOG-IS MRA is available on the official website. The original SOG-IS MRA was practically identical, but only mentioned recognition based on ITSEC.
Although ITSEC never gained significant traction outside Europe, it established several foundational concepts that would later become central to Common Criteria: cross-border recognition, harmonised evaluation methodologies, evaluator cooperation, assurance levels, and trust relationships between national schemes. These ideas were carried forward into the Common Criteria Recognition Arrangement (CCRA), which was created in the late 1990s.
The CCRA marked a significant shift towards internationalisation, attempting to create a global recognition ecosystem spanning North America, Europe, and Asia-Pacific markets. This aligned well with the rapid internationalisation of the commercial IT industry during the late 1990s and early 2000s.
SOG-IS did not dissolve when the CCRA was created. Instead it continued as a parallel agreement maintained by its European members. The SOG-IS group eventually implemented an explicit technical domain structure that allowed mutual recognition up to EAL7 for certain product categories in 2010.
The modern EUCC framework represents the next major evolutionary step in this lineage: from national criteria, to European intergovernmental recognition, to global voluntary recognition, and now towards formalised regional cybersecurity regulation under EU law. The legacy of SOG-IS and ITSEC can be seen in the ongoing efforts to harmonise evaluation methodologies, promote cross-border recognition and establish trust relationships between national certification schemes.
This narrative arc highlights the evolution of mutual recognition from its humble beginnings in what became SOG-IS to the current global frameworks that govern IT security evaluations. By understanding the background for these agreements we can better appreciate the complexities and challenges involved in creating a unified system for evaluating the security of IT products.
It is still quite difficult.