Procurement Planning Before the Certificate Exists
Common Criteria certification is slow. From the moment a vendor files an evaluation with a certification body to the day the certificate is published on the scheme registry, twelve to eighteen months is a routine elapsed time, and more is normal for higher EAL targets. For most of that period the work is happening in plain sight on the certification body’s public pages, but invisible to anyone who is only reading the certificate registries.
The cost of that gap shows up wherever someone has to plan ahead with certified products. Procurement teams are the clearest case, but they are not the only one.
The gap in plain numbers
A registry of certificates tells you what is already certified. It tells you nothing about what will be available three quarters from now. For short purchasing cycles that may be fine. For anyone running a multi-year compliance programme or specifying a product against a regulation that calls for a particular EAL level, the lag is significant.
A simple way to picture it: the certified inventory is a stock, and the evaluation pipeline is a flow. The stock at any moment is the catalogue. The flow that will become next year’s stock is the set of products currently in evaluation. If you only see the stock, you are planning against today’s supply without any signal about what tomorrow’s supply will look like.
Most certification bodies publish their evaluation pipelines on their public sites. BSI publishes a list under “Products in Evaluation”. NIAP shows “Products in Evaluation” under the CCEVS programme. CCCS, JISEC, CSEC Sweden, TrustCB, and Brightsight all publish equivalent lists. The data is there. Until now there has not been a single place to read it, follow it, or be notified when something new appears.
What changes for procurement
The procurement use case is the most direct. A team writing a requirement that calls for, say, “an EAL4+ smart card with a Java Card protection profile” has historically been planning against the existing catalogue. The product they pick is often a product that was certified two or three years ago, because that is what shows on the registry today.
With a pipeline view in hand, the same team can:
- See which vendors are currently putting new platforms through evaluation at which labs, against which profiles. That tells the team what they will be choosing from in twelve to eighteen months, not in three years.
- Notice when a vendor’s newer-generation chip enters evaluation, signalling that the older generation in today’s catalogue is heading towards end of life as an actively certified product.
- Identify gaps. If no vendor has anything under evaluation in a category the team’s roadmap depends on, that is information the team needs before it commits to a procurement specification.
- Plan timing. A product entering evaluation in May at a lab whose average evaluation cycle is twelve months is unlikely to be certified before next May. A requirement issued now that can only be met by that product needs an alternative path or a waiver.
The single biggest practical effect is to extend the visible procurement horizon by roughly a year. That is the difference between “we will work with what is on the registry today” and “we will work with what we know is coming”. The regulated procurement use case walks through this for buyers whose specifications are bound by NIS2, automotive, or payments regulation.
What changes for compliance and CISOs
Compliance programmes pinned to certified components carry the same shape of risk as procurement specs, with longer feedback loops. NIS2 controls that call for certified cryptographic modules, PCI DSS requirements that point at PTS-approved devices, and automotive supplier programmes that require ISO/SAE 21434 evidence all live in this space.
The pipeline view lets a compliance lead:
- Anticipate when a deprecated certified product will have a successor on the registry, instead of discovering it the week the old certificate expires.
- Map the compliance roadmap to the actual supply pipeline, so the documentation team is not promising customers a certified migration path that does not exist in any evaluation queue.
- Spot scheme-level shifts. If the EUCC pipeline starts filling up with classes of product that previously evaluated under national CCRA schemes, that is a useful signal about where the centre of gravity is moving for European compliance.
CISOs sitting one layer above the compliance programme get a useful side benefit: an objective answer to the question “what is actually happening in our certified supply chain”. The pipeline list is not anyone’s marketing material. It is what the certification body has accepted into evaluation.
What changes for vendors
Vendor strategy is the use case most people do not bring up first, but it is real. The pipeline lists are public; the picture they paint is competitive intelligence.
A vendor working on a new secure element can see which competitor entered which lab with which profile, at roughly what time. That informs:
- Roadmap timing. If a direct competitor entered evaluation eight months ago at a lab with an average twelve-month cycle, an announcement is likely soon. Internal release decisions can factor that in.
- Lab capacity. If a target lab is currently working on several large evaluations, an early conversation about a planned engagement is more informative than the lab’s marketing-side responsiveness suggests.
- Cross-scheme positioning. A vendor that has so far evaluated under one scheme can read the pipeline at the other scheme to understand whether competitors are quietly broadening their certification footprint there.
This is not new information in any deep sense. Sales teams have always known the rough shape of competitor activity. The difference is having it in one place, dated, and queryable, rather than reconstructed from rumour.
What changes for analysts and auditors
Industry analysts publishing market overviews of certified products in a sector (smart card platforms, automotive secure elements, PSA chips) routinely face the question “is this list representative of where the market is going, or only of where it has been?” The answer has historically required calling individual vendors. The pipeline view turns it into a query against the public catalogue.
Auditors checking a vendor’s certification roadmap for a customer or for due diligence get a parallel benefit. A vendor that claims its next-generation product is “in evaluation” can be checked against the public pipeline list of the relevant certification body. Either the claim is in the list, or it is not.
What this is not
A few things worth being clear about.
A product appearing on a certification body’s evaluation list is not a guarantee that a certificate will issue. Evaluations are abandoned for many reasons, from a failed assurance argument to a commercial decision. The pipeline view tells you what is being attempted, not what will succeed.
The information is published by the certification body and reflects what the body has accepted into evaluation. It does not include what is being prepared internally but not yet formally entered. Vendor-side roadmaps remain private.
The fields published vary by scheme. BSI publishes a sponsor, a developer, and a registered title. NIAP publishes the product name, vendor, and a target assurance package. The level of detail is not uniform across sources, and the new view simply surfaces what each source actually publishes.
Where to start
For NenkinTracker users, the new view is live. Search now returns products that are only under evaluation, with an “Under Eval” badge and a filter chip to restrict the catalogue to that subset. Opening a product shows an “Under Evaluation” card with the source-published fields. Two new notification routes are available: subscribe to a certification body to be alerted whenever a new product enters evaluation there, or follow a specific product under evaluation to be alerted when it is registered and again when the certificate eventually issues.
The longer-term effect is the same in every case: the procurement, compliance, and vendor-strategy horizon shifts forward by something close to the length of an evaluation cycle. That is the part that has been quietly missing from the certified-product picture until now.
See also
- Common Criteria Procurement: how to write a procurement specification that points at certified products
- Regulated procurement: NenkinTracker for buyers in regulated industries
- The Common Criteria certification process: each step from kickoff to certificate, and where the time goes