The Least-Used Protection Profiles: a Procurement Caution Tale
A few weeks ago we walked through the most-used Protection Profiles in our catalogue. The story there was concentration: a small number of PPs cover the bulk of certified products. This post is the other side. Of the 267 PPs we track, half are referenced by exactly one certified product. The long tail has procurement consequences worth thinking about before anyone writes a PP requirement into a tender.
How the 267 PPs split out
| Conforming products | Number of PPs | Share |
|---|---|---|
| 1 | 133 | 49.8% |
| 2 | 51 | 19.1% |
| 3 to 5 | 34 | 12.7% |
| 6 to 10 | 28 | 10.5% |
| 11 or more | 21 | 7.9% |
Just under 70% of the catalogue’s PPs have one or two conforming products. The 21 PPs with 11 or more products account for roughly two-thirds of all PP-product associations, while the 133 singletons account for 9% of them. This is a very long tail.
Why so many PPs get used once
Four patterns explain almost all 133 singletons.
Superseded versions. Many are older revisions of profiles whose newer version is widely used. PP_OS_V4.2.1 has one product; PP_OS_V4.3 carries the rest. PP_MD_V3.1 has one; PP_MDF_V3.3 carries the modern Mobile Device Family certifications. These are stragglers, certified just before the PP was revised and never re-certified.
Composite PP claims. A large share of singletons are claim strings that combine a base PP with PP-Modules and PP-Packages from the NIAP collaborative ecosystem. A string like CPP_ND_V3.0E,MOD_VPNGW_V1.3,MOD_MACSEC_V1.0,PKG_SSH_V1.0 describes a module mix only one product has claimed. The base components are common; the exact combination is unique. Treat these as variations of the popular PPs.
National PPs. Several singletons originate in a single national scheme and never crossed over. KECS-PP-1232-2023 DB ENCRYPTION V3.0 (Korean database encryption) and KECS-PP-1348-2025 SSO V3.1 (Korean single sign-on) each have two Korean products. PP_DCSSI_MASS_STORAGE_ENCRYPT_APP_V1.4 is a French ANSSI mass-storage encryption profile with one French product. These PPs serve a regulated domestic market and were not really intended to attract international conformance.
Niche and one-off categories. A few singletons describe genuinely narrow product categories. RECOBS_V1.0 is a remote-controlled-browser-system PP (m-privacy’s TightGate-Pro). HIS PP is a Turkish Health Information System PP (TMYPACS). FSDPP_OSP_V1.7 is a fingerprint sensor PP (a Dermalog reader). BAROC_SC_PP_V1.0 is the Bankers Association of the Republic of China smart-card PP (an Infineon SLM10TLD). Real PPs, just for very specific use cases.
A few rare PPs worth naming
A handful are worth naming, because a procurement team writing requirements for an unusual product class may stumble onto one of these and not realise how thin the conforming population is.
PP_PSS_V3.0. Peripheral Sharing Switch PP. One product (a Belkin Secure KVM family). If you want a CC-certified KVM, this is the PP.TEE PROTECTION PROFILE. GlobalPlatform TEE PP, generic form. One product (Qualcomm’s TEE on Snapdragon 865). Modern TEE certifications mostly use scheme-specific composite claims.CALYPSO BASIC. Calypso transit ticketing PP. One product (Infineon SLM10TLD with Calypso Move).PP_COS_G2. German eHealth Card OS Generation 2 PP. One product (G+D STARCOS for the German GKV).IEEE 2600.2-2009. Older Hardcopy Device PP. Two products (one Kyocera, one HP).PP_HCD_V1.0andCPP_HCD_V1.0Ecarry the rest of the printer ecosystem.PDCP_V1.3. Java Card platform PP. One composite product (a Gemalto/Thales JavaCard MultiApp on Infineon M7892).PP_DCSSI_MASS_STORAGE_ENCRYPT_APP_V1.4. French mass-storage encryption PP. One product (PrimX Cryhod).
Why this matters for procurement
If you are writing a tender that names a Protection Profile, look up the conforming product count first. The most-used PPs give you a real market. The long tail does not.
Specifying a singleton PP is effectively specifying one vendor. “Conformant to RECOBS_V1.0” picks one product. “Conformant to BAROC_SC_PP_V1.0” picks one chip. If that is the intent, write it down honestly. If not, broaden the requirement.
Evaluator and lab familiarity matters. Labs that have run dozens of NDcPP or SECURITY_IC_AUGP evaluations are fast and predictable. A PP that has been used once means the lab is starting from scratch on the threat model, the assurance activities, and the conformance argument. Cost and schedule risk both go up.
No comparator products means no comparator pricing. With one certified vendor you have no second source and no negotiating leverage. Re-certifying a competitor against the same PP is a project measured in months and six figures.
Older PPs may be on the way out. A singleton against an older revision (PP_OS_V4.2.1, PP_MD_V3.1, MRTD_ICAO_EAC_V1.1) often signals a PP whose successor is now standard. Specifying the old one locks procurement to a narrow and shrinking pool.
A reasonable default
Pick PPs from the head of the distribution, not the tail. If your product category does not have a widely-used PP, that is itself useful information: write the requirement around EAL plus specific functional and assurance components, or use a Security Target with no PP claim. Both are normal, and both compete more easily than a singleton-PP requirement.
Before locking a PP into a tender, review the conformance claims in candidate products’ certification records. Explore NenkinTracker to start comparing products.
See also
- The Most-Used Protection Profiles in Common Criteria, by Product Count: The head of the distribution, and the direct counterpart to this post
- Protection Profiles (PP): What a PP is and how conformance works in CC evaluations
- Which EAL Do I Need? A Procurement Decision Guide: Companion piece on assurance levels in procurement
- Smart Card Chip Vendor Comparison: Sibling post on the head of the chip-IC market