Skip to content
Nenkin

Procurement Planning Before the Certificate Exists

Common Criteria certification is slow. From the moment a vendor files an evaluation with a certification body to the day the certificate is published on the scheme registry, twelve to eighteen months is a routine elapsed time, and more is normal for higher EAL targets. For most of that period the work is happening in plain sight on the certification body’s public pages, but invisible to anyone who is only reading the certificate registries.

The cost of that gap shows up wherever someone has to plan ahead with certified products. Procurement teams are the clearest case, but they are not the only one.

The gap in plain numbers

A registry of certificates tells you what is already certified. It tells you nothing about what will be available three quarters from now. For short purchasing cycles that may be fine. For anyone running a multi-year compliance programme or specifying a product against a regulation that calls for a particular EAL level, the lag is significant.

A simple way to picture it: the certified inventory is a stock, and the evaluation pipeline is a flow. The stock at any moment is the catalogue. The flow that will become next year’s stock is the set of products currently in evaluation. If you only see the stock, you are planning against today’s supply without any signal about what tomorrow’s supply will look like.

Most certification bodies publish their evaluation pipelines on their public sites. BSI publishes a list under “Products in Evaluation”. NIAP shows “Products in Evaluation” under the CCEVS programme. CCCS, JISEC, CSEC Sweden, TrustCB, and Brightsight all publish equivalent lists. The data is there. Until now there has not been a single place to read it, follow it, or be notified when something new appears.

What changes for procurement

The procurement use case is the most direct. A team writing a requirement that calls for, say, “an EAL4+ smart card with a Java Card protection profile” has historically been planning against the existing catalogue. The product they pick is often a product that was certified two or three years ago, because that is what shows on the registry today.

With a pipeline view in hand, the same team can:

  • See which vendors are currently putting new platforms through evaluation at which labs, against which profiles. That tells the team what they will be choosing from in twelve to eighteen months, not in three years.
  • Notice when a vendor’s newer-generation chip enters evaluation, signalling that the older generation in today’s catalogue is heading towards end of life as an actively certified product.
  • Identify gaps. If no vendor has anything under evaluation in a category the team’s roadmap depends on, that is information the team needs before it commits to a procurement specification.
  • Plan timing. A product entering evaluation in May at a lab whose average evaluation cycle is twelve months is unlikely to be certified before next May. A requirement issued now that can only be met by that product needs an alternative path or a waiver.

The single biggest practical effect is to extend the visible procurement horizon by roughly a year. That is the difference between “we will work with what is on the registry today” and “we will work with what we know is coming”. The regulated procurement use case walks through this for buyers whose specifications are bound by NIS2, automotive, or payments regulation.

What changes for compliance and CISOs

Compliance programmes pinned to certified components carry the same shape of risk as procurement specs, with longer feedback loops. NIS2 controls that call for certified cryptographic modules, PCI DSS requirements that point at PTS-approved devices, and automotive supplier programmes that require ISO/SAE 21434 evidence all live in this space.

The pipeline view lets a compliance lead:

  • Anticipate when a deprecated certified product will have a successor on the registry, instead of discovering it the week the old certificate expires.
  • Map the compliance roadmap to the actual supply pipeline, so the documentation team is not promising customers a certified migration path that does not exist in any evaluation queue.
  • Spot scheme-level shifts. If the EUCC pipeline starts filling up with classes of product that previously evaluated under national CCRA schemes, that is a useful signal about where the centre of gravity is moving for European compliance.

CISOs sitting one layer above the compliance programme get a useful side benefit: an objective answer to the question “what is actually happening in our certified supply chain”. The pipeline list is not anyone’s marketing material. It is what the certification body has accepted into evaluation.

What changes for vendors

Vendor strategy is the use case most people do not bring up first, but it is real. The pipeline lists are public; the picture they paint is competitive intelligence.

A vendor working on a new secure element can see which competitor entered which lab with which profile, at roughly what time. That informs:

  • Roadmap timing. If a direct competitor entered evaluation eight months ago at a lab with an average twelve-month cycle, an announcement is likely soon. Internal release decisions can factor that in.
  • Lab capacity. If a target lab is currently working on several large evaluations, an early conversation about a planned engagement is more informative than the lab’s marketing-side responsiveness suggests.
  • Cross-scheme positioning. A vendor that has so far evaluated under one scheme can read the pipeline at the other scheme to understand whether competitors are quietly broadening their certification footprint there.

This is not new information in any deep sense. Sales teams have always known the rough shape of competitor activity. The difference is having it in one place, dated, and queryable, rather than reconstructed from rumour.

What changes for analysts and auditors

Industry analysts publishing market overviews of certified products in a sector (smart card platforms, automotive secure elements, PSA chips) routinely face the question “is this list representative of where the market is going, or only of where it has been?” The answer has historically required calling individual vendors. The pipeline view turns it into a query against the public catalogue.

Auditors checking a vendor’s certification roadmap for a customer or for due diligence get a parallel benefit. A vendor that claims its next-generation product is “in evaluation” can be checked against the public pipeline list of the relevant certification body. Either the claim is in the list, or it is not.

What this is not

A few things worth being clear about.

A product appearing on a certification body’s evaluation list is not a guarantee that a certificate will issue. Evaluations are abandoned for many reasons, from a failed assurance argument to a commercial decision. The pipeline view tells you what is being attempted, not what will succeed.

The information is published by the certification body and reflects what the body has accepted into evaluation. It does not include what is being prepared internally but not yet formally entered. Vendor-side roadmaps remain private.

The fields published vary by scheme. BSI publishes a sponsor, a developer, and a registered title. NIAP publishes the product name, vendor, and a target assurance package. The level of detail is not uniform across sources, and the new view simply surfaces what each source actually publishes.

Where to start

For NenkinTracker users, the new view is live. Search now returns products that are only under evaluation, with an “Under Eval” badge and a filter chip to restrict the catalogue to that subset. Opening a product shows an “Under Evaluation” card with the source-published fields. Two new notification routes are available: subscribe to a certification body to be alerted whenever a new product enters evaluation there, or follow a specific product under evaluation to be alerted when it is registered and again when the certificate eventually issues.

The longer-term effect is the same in every case: the procurement, compliance, and vendor-strategy horizon shifts forward by something close to the length of an evaluation cycle. That is the part that has been quietly missing from the certified-product picture until now.

See also

Frequently asked questions

What does it mean for a product to be 'under evaluation' at a certification body?
A product is under evaluation when a certification body has formally accepted it into the evaluation queue and an accredited lab has begun the assurance work. The body typically publishes the sponsor, the developer, a registered title, and the targeted assurance package. The evaluation runs until the body issues a certificate or the work is withdrawn.
How long does a Common Criteria evaluation take?
Twelve to eighteen months is a routine elapsed time from acceptance into evaluation to certificate issuance. Higher EAL targets and Protection Profile evaluations can take longer. Maintenance updates and assurance continuity paths are usually faster than a fresh evaluation.
Where do certification bodies publish the list of products under evaluation?
Each body publishes its own list. BSI publishes "Products in Evaluation" on its certification site. NIAP publishes "Products in Evaluation" under the CCEVS programme. CCCS, JISEC, CSEC Sweden, TrustCB, and Brightsight publish equivalent lists on their own sites. The fields published vary by body.
Does an entry on a 'products in evaluation' list guarantee a certificate will issue?
No. Evaluations are sometimes abandoned, for reasons that range from a failed assurance argument to a commercial decision by the sponsor. A pipeline entry is a statement that a body has accepted a product into evaluation, not a promise of certification.
Why does early visibility into the evaluation pipeline matter for procurement?
Procurement specifications that call for a certified product have historically been written against the existing catalogue, which reflects evaluations that completed one to three years ago. A pipeline view extends the planning horizon by roughly the length of an evaluation cycle, so a buyer can plan against what will be certified next year, not only what was certified last year.
Can vendors use the evaluation pipeline lists as competitive intelligence?
Yes. The pipeline lists are public records published by the certification bodies. A vendor can read them to see which competitors entered which labs against which assurance packages, and combine that with the typical evaluation cycle of each lab to estimate when competing certificates are likely to land.