Skip to content
Nenkin

The Least-Used Protection Profiles: a Procurement Caution Tale

A few weeks ago we walked through the most-used Protection Profiles in our catalogue. The story there was concentration: a small number of PPs cover the bulk of certified products. This post is the other side. Of the 267 PPs we track, half are referenced by exactly one certified product. The long tail has procurement consequences worth thinking about before anyone writes a PP requirement into a tender.

How the 267 PPs split out

Conforming productsNumber of PPsShare
113349.8%
25119.1%
3 to 53412.7%
6 to 102810.5%
11 or more217.9%

Just under 70% of the catalogue’s PPs have one or two conforming products. The 21 PPs with 11 or more products account for roughly two-thirds of all PP-product associations, while the 133 singletons account for 9% of them. This is a very long tail.

Why so many PPs get used once

Four patterns explain almost all 133 singletons.

Superseded versions. Many are older revisions of profiles whose newer version is widely used. PP_OS_V4.2.1 has one product; PP_OS_V4.3 carries the rest. PP_MD_V3.1 has one; PP_MDF_V3.3 carries the modern Mobile Device Family certifications. These are stragglers, certified just before the PP was revised and never re-certified.

Composite PP claims. A large share of singletons are claim strings that combine a base PP with PP-Modules and PP-Packages from the NIAP collaborative ecosystem. A string like CPP_ND_V3.0E,MOD_VPNGW_V1.3,MOD_MACSEC_V1.0,PKG_SSH_V1.0 describes a module mix only one product has claimed. The base components are common; the exact combination is unique. Treat these as variations of the popular PPs.

National PPs. Several singletons originate in a single national scheme and never crossed over. KECS-PP-1232-2023 DB ENCRYPTION V3.0 (Korean database encryption) and KECS-PP-1348-2025 SSO V3.1 (Korean single sign-on) each have two Korean products. PP_DCSSI_MASS_STORAGE_ENCRYPT_APP_V1.4 is a French ANSSI mass-storage encryption profile with one French product. These PPs serve a regulated domestic market and were not really intended to attract international conformance.

Niche and one-off categories. A few singletons describe genuinely narrow product categories. RECOBS_V1.0 is a remote-controlled-browser-system PP (m-privacy’s TightGate-Pro). HIS PP is a Turkish Health Information System PP (TMYPACS). FSDPP_OSP_V1.7 is a fingerprint sensor PP (a Dermalog reader). BAROC_SC_PP_V1.0 is the Bankers Association of the Republic of China smart-card PP (an Infineon SLM10TLD). Real PPs, just for very specific use cases.

A few rare PPs worth naming

A handful are worth naming, because a procurement team writing requirements for an unusual product class may stumble onto one of these and not realise how thin the conforming population is.

  • PP_PSS_V3.0. Peripheral Sharing Switch PP. One product (a Belkin Secure KVM family). If you want a CC-certified KVM, this is the PP.
  • TEE PROTECTION PROFILE. GlobalPlatform TEE PP, generic form. One product (Qualcomm’s TEE on Snapdragon 865). Modern TEE certifications mostly use scheme-specific composite claims.
  • CALYPSO BASIC. Calypso transit ticketing PP. One product (Infineon SLM10TLD with Calypso Move).
  • PP_COS_G2. German eHealth Card OS Generation 2 PP. One product (G+D STARCOS for the German GKV).
  • IEEE 2600.2-2009. Older Hardcopy Device PP. Two products (one Kyocera, one HP). PP_HCD_V1.0 and CPP_HCD_V1.0E carry the rest of the printer ecosystem.
  • PDCP_V1.3. Java Card platform PP. One composite product (a Gemalto/Thales JavaCard MultiApp on Infineon M7892).
  • PP_DCSSI_MASS_STORAGE_ENCRYPT_APP_V1.4. French mass-storage encryption PP. One product (PrimX Cryhod).

Why this matters for procurement

If you are writing a tender that names a Protection Profile, look up the conforming product count first. The most-used PPs give you a real market. The long tail does not.

Specifying a singleton PP is effectively specifying one vendor. “Conformant to RECOBS_V1.0” picks one product. “Conformant to BAROC_SC_PP_V1.0” picks one chip. If that is the intent, write it down honestly. If not, broaden the requirement.

Evaluator and lab familiarity matters. Labs that have run dozens of NDcPP or SECURITY_IC_AUGP evaluations are fast and predictable. A PP that has been used once means the lab is starting from scratch on the threat model, the assurance activities, and the conformance argument. Cost and schedule risk both go up.

No comparator products means no comparator pricing. With one certified vendor you have no second source and no negotiating leverage. Re-certifying a competitor against the same PP is a project measured in months and six figures.

Older PPs may be on the way out. A singleton against an older revision (PP_OS_V4.2.1, PP_MD_V3.1, MRTD_ICAO_EAC_V1.1) often signals a PP whose successor is now standard. Specifying the old one locks procurement to a narrow and shrinking pool.

A reasonable default

Pick PPs from the head of the distribution, not the tail. If your product category does not have a widely-used PP, that is itself useful information: write the requirement around EAL plus specific functional and assurance components, or use a Security Target with no PP claim. Both are normal, and both compete more easily than a singleton-PP requirement.

Before locking a PP into a tender, review the conformance claims in candidate products’ certification records. Explore NenkinTracker to start comparing products.

See also

Frequently asked questions

How many Protection Profiles are used by only one product?
Of the 267 Protection Profiles in the NenkinTracker catalog, 133 (49.8 percent) are referenced by exactly one certified product. Another 51 PPs have just two. Roughly 70 percent of the catalog's PPs have one or two conforming products. The 21 PPs with 11 or more products account for roughly two-thirds of all PP-product associations; the singletons account for 9 percent.
Why are so many Protection Profiles used only once?
Four patterns explain almost all singletons. Superseded versions are older PP revisions whose newer version is widely used. Composite PP claims are unique combinations of base PPs with PP-Modules and PP-Packages. National PPs originate in a single national scheme and never crossed over. Niche and one-off categories describe genuinely narrow product classes (specific KVM, fingerprint sensor, or transit-ticketing PPs).
Should procurement specify a rare Protection Profile in a tender?
Generally no. Specifying a singleton PP is effectively specifying one vendor. Evaluator and lab familiarity matters: PPs that have been used dozens of times mean predictable cost and schedule, while a once-used PP means the lab starts from scratch on threat model and assurance activities. No comparator products means no comparator pricing and no second-source leverage.
What if my product category has no widely-used Protection Profile?
Either write the requirement around EAL plus specific functional and assurance components, or use a Security Target with no PP claim. Both are normal in Common Criteria evaluations, and both compete more easily than a singleton-PP requirement. The full PP distribution with conforming product counts is searchable; check it before locking a PP into a tender.
Why should I avoid older Protection Profile revisions in procurement?
A singleton against an older revision (for example PP_OS_V4.2.1 when PP_OS_V4.3 is current, or PP_MD_V3.1 versus PP_MDF_V3.3) often signals a PP whose successor is now standard. Specifying the old one locks procurement to a narrow and shrinking pool. Stragglers exist because they were certified just before the PP was revised and never re-certified.
Are there singleton Protection Profiles for legitimate niche product categories?
Yes. Some narrow PPs serve real but small markets: PP_PSS_V3.0 (Peripheral Sharing Switch / KVM, one Belkin product), TEE PROTECTION PROFILE (one Qualcomm Snapdragon TEE), CALYPSO BASIC (transit ticketing, one Infineon product), PP_COS_G2 (German eHealth Card OS, one G+D STARCOS), and PP_DCSSI_MASS_STORAGE_ENCRYPT_APP_V1.4 (French mass-storage encryption, one product).