Skip to content
Nenkin

What to watch at ICCC26: a curtain-raiser for Common Criteria in Rome

The Common Criteria community holds one annual gathering where the schemes, the labs, the vendors, and the policy bodies all sit in one room. This year it is in Rome, from 28 September to 1 October 2026, at Cardo Roma. The conference is the 25th edition of ICCC, and the program looks more consequential than the average year. The published theme, “Managing Compliance Across an Expanding Certification Landscape,” is doing some work.

EUCC has crossed 30 published certificates since the previous edition. The EU Cyber Resilience Act is rewriting what conformity assessment means for connected products, with the operational details (which products, which assurance levels, which assessment routes) still being worked out. The host country, Italy, has just retired its national Common Criteria scheme in favour of the EU framework. Plenty of conversations that have been held bilaterally over the past twelve months will become public in late September.

This is a curtain-raiser. We have not been to every session yet (no one has, the program is still being finalised), but the shape of the week, the named tracks, and the sponsor list are enough to call out what is worth watching.

The shape of the week

ICCC26 runs over four days, with the first one optional. The full schedule of events is published on the conference site; the headline structure is:

  • Monday 28 September: CC Action Plan Day. A pre-conference day framed around turning Common Criteria from a bottleneck into a competitive advantage for ICT developers. Included in the 4-day pass, optional otherwise.
  • Tuesday 29 September: opening plenary keynote (09:00 to 10:15), morning plenary session (11:00 to 13:00), three concurrent tracks in the afternoon, welcome reception in the exhibits (17:30), evening dinner (19:30).
  • Wednesday 30 September: four concurrent track blocks across the day. Exhibits close at end of day.
  • Thursday 1 October: morning track sessions including the dedicated Assurance track, closing plenary 13:00 to 14:00, conference adjourns.

Expected attendance is over 400 delegates from 28 countries, which is the upper end of the typical ICCC range and consistent with a host city that draws well.

Why this edition matters more than the average year

Three regulatory currents collide in 2026, and ICCC26 is the first venue where the people who have to operationalise them will be in the same room since the picture took shape.

EUCC moved from draft framework to real publishing surface. When the community last met in Korea in October 2025, EUCC certificates were being issued but the registry was sparse and the operational details (CAB onboarding, ENISA portal behaviour, assurance continuity rules) were still being shaken down. Fifteen months on, the scheme has 30 published certificates, multiple active CABs across Member States, and an identifier format that has already been quietly reformatted once. Plenty to talk about.

The Cyber Resilience Act is now in scope for the same audience. CRA conformity assessment will lean on horizontal cybersecurity standards and, where appropriate, on EUCC. Which products land in which assurance route, what the gap between CRA self-assessment and a third-party EUCC certification will mean for vendors, and how labs will be resourced for the expected demand surge are all live questions.

The CC standard itself is in revision. “New CC ISO Revision Update” is a named track for the first time. The CC:2022 baseline is now embedded in EUCC, and the next revision will determine what schemes, labs, and vendors code against for the back half of the decade.

Layer on top of that the structural conversation about continuous assurance (what to do about vulnerabilities discovered after certification, how to handle patch management for certified products, how AVA_VAN guidance should evolve), and there is enough material to fill the four days twice over.

What we are watching, track by track

ICCC26 publishes six tracks. Based on the call for speakers and the precedent set by ICCC25’s agenda in Korea, here is what we expect from each.

Advances in the Use of Common Criteria. The A-track is where continuous assurance, vulnerability management beyond certification maintenance, attack potential and CVSS scoring, and post-quantum cryptography readiness will land. This is also typically where AI assurance, cloud, OT, and other emerging-domain topics appear, framed as “how does CC methodology apply here.” A useful track for anyone trying to certify something that does not look like a smart card.

Assurance. The dedicated Assurance track is new on the named-track list this year. We expect deeper sessions on AVA_VAN evolution, CEM:2022 in practice, evaluator-side methodology questions, and the supporting documents (the SOG-IS-era documents now being absorbed into the EUCC framework). This is the track for the labs.

Cybersecurity Certification Schemes Landscape. The L-track is where the regulatory comparisons happen. EUCC, CRA, candidate EUCS for cloud services, EU Digital Identity Wallet certification, and the relationship between the EU framework and the CCRA. Expect at least one panel on what each scheme is for and where the overlaps are starting to bite.

Meeting Customer Requirements. The M-track is the procurement and deployment side. What buyers actually want to read on a certificate, how to express security requirements in a contract, the gap between EAL packages (still how the procurement community thinks) and the EUCC Substantial / High labels (how the regulator thinks). Useful for anyone on the buying side of certified products.

New CC ISO Revision Update. The first time this has been a named track. The CC standard revision cycle is slow-moving but high-stakes plumbing. The schemes, the labs, and the vendors all want a quiet runway with no surprises. Worth watching for any early signals on what the next revision will and will not contain.

Updates from Schemes and iTCs. The U-track is the regular reports from CCRA national schemes (BSI, ANSSI, NIAP, OCSI, NSCIB, CCCS, JISEC, KECS, and others) and from the international Technical Communities. Mostly status reports, occasionally newsworthy when a scheme announces a process change or a new product category coming into scope.

The split between A, L, M, and U has been stable for years. The Assurance and CC ISO Revision tracks being named separately this year is the structural change worth noticing.

The host scheme is its own case study

OCSI (Organismo di Certificazione della Sicurezza Informatica) is Italy’s national CC body, transferred to the Italian Cybersecurity Agency (ACN) in July 2022. On 27 February 2026, OCSI wound down its national CC scheme and now functions as Italy’s EUCC NCCA, per ACN’s own statement on the OCSI page. Italian CC evaluations now route through the EUCC framework rather than through a parallel national scheme.

That makes Rome a slightly unusual host city. ICCC is normally hosted by a country whose national scheme is still actively issuing under CCRA. Italy is one of the first CCRA Authorising members to have completed the transition the rest of the EU is in the middle of. Whatever lessons OCSI and ACN have learned from running the transition end to end (CAB readiness, vendor communication, the practical mechanics of redirecting in-flight evaluations) will be one of the more useful informal threads of the week. Rome also hosted ICCC7 in 2007, so this is Italy’s second turn at the conference.

The exhibit floor reads as a map of the lab market

The published sponsor list for ICCC26 is a useful snapshot of the active CC evaluation and consulting market.

  • Title sponsors: Securus Consulting Group (Platinum), UL Solutions (Gold), Brightsight, Intertek Acumen Security with EWA-Canada, LGAI Technological Center, and TUV Informationstechnik (TUViT, all Silver).
  • Leading sponsors: CCLab (hosting the opening reception), DEKRA (track sponsor), konfidas, Teron Labs (badges and lanyards), Zhejiang Wonsec (WiFi).
  • Exhibitors: eShard, Red Alert Labs.
  • Supporting associations: CCUF, EUCC ISAC, Eurosmart, Global Platform, OASIS, Trusted Connectivity Alliance, Biometric Update.

That roster spans BSI-licensed labs, ANSSI-licensed labs, NIAP CCTLs, and EUCC-accredited CABs. It also covers the consulting tier (Securus, konfidas) and the policy and standards bodies (Eurosmart, OASIS, Trusted Connectivity Alliance). For procurement and integration teams trying to map who can evaluate what under which scheme, walking the exhibit floor at ICCC26 is probably the highest-bandwidth way to do that in person.

Practical notes for delegates

  • Early-bird registration (via the official ICCC26 site) closes 18 August 2026. Saves EUR 380 on the 3-day pass (EUR 1,150 vs EUR 1,530) or EUR 490 on the 4-day pass that includes Action Plan Day (EUR 1,460 vs EUR 1,950).
  • Refund window closes 8 September 2026; cancellations after that date are non-refundable.
  • Speaker slides are due to the organisers on 8 September. Speakers receive complimentary full conference registration.
  • Session format is 30-minute talks (including Q&A) and 60-minute panels.
  • Venue is Cardo Roma, in the southern EUR business district. Allow more travel time from the historic centre than the map suggests.
  • Side meetings typically cluster around the welcome reception (Tuesday evening) and the lunches; the schedule does not formally allocate working-group time, so most bilateral conversations happen at the margins.

How NenkinTracker helps you see this

The schemes, labs, CABs, and vendors heading to Rome are the bodies generating the records we ingest every day. NenkinTracker indexes certificates across seven schemes (CCRA, EUCC, SESIP, PSA, ESA, EMVCo, MIFARE). Explore the tracker to follow products across these schemes.

If you are heading to ICCC26, useful pre-conference reading is a quick refresher on where each scheme stands now: the EUCC corpus, your home national scheme, and any vendor portfolios you follow. Those are the views the tracker is built around.

We will publish a follow-up after the conference with the program details that turned out to matter, the announcements that landed, and any structural changes to scheme practice worth flagging.

See also

Frequently asked questions

When and where is ICCC26?
ICCC26 runs from Monday 28 September to Thursday 1 October 2026 at Cardo Roma in Rome, Italy. Monday is the optional CC Action Plan Day; the main conference runs Tuesday through Thursday. The conference is produced by Cnxtd Event Media Corp. with the support of the Common Criteria Users' Forum (CCUF), and is expected to draw over 400 delegates from 28 countries.
What is the International Common Criteria Conference?
ICCC is the annual gathering for the international Common Criteria community: national certification schemes, conformity assessment bodies, evaluation laboratories, product vendors, procurement and integration teams, and policy makers. It rotates internationally; recent editions were Washington DC (2023), Doha (2024), Korea (2025), and Rome (2026). It is the one venue each year where the entire CC ecosystem sits in one room.
What are the main themes at ICCC26?
The 2026 theme is "Managing Compliance Across an Expanding Certification Landscape." Expect heavy coverage of EUCC rollout, the EU Cyber Resilience Act's conformity assessment routes, continuous assurance and vulnerability management for certified products, post-quantum cryptography readiness, and the upcoming CC standard revision. Six tracks run across the three main days, including a dedicated Assurance track and the first named "New CC ISO Revision Update" track.
What is the CC Action Plan Day at ICCC26?
Monday 28 September is the CC Action Plan Day, an optional pre-conference day framed around turning Common Criteria from a bottleneck into a competitive advantage for ICT developers. It is included in the 4-day pass and adds roughly EUR 310 over the 3-day pass. The agenda focuses on practical certification strategy rather than scheme updates or technical sessions.
Why is Rome a notable host for ICCC26?
Italy's national CC scheme OCSI ceased its national activity on 27 February 2026 and now operates as Italy's EUCC certification authority, so the host country is itself a live case study of the national-to-EU transition the conference will discuss. Rome also last hosted ICCC in 2007 (ICCC7), making this Italy's second turn. The Italian Cybersecurity Agency (ACN) is the parent body for OCSI and a visible presence in EU certification policy.
Who attends ICCC26?
Over 400 delegates from 28 countries are expected. Attendance typically spans CCRA national schemes, accredited evaluation labs (ITSEFs, CCTLs, LVS), conformity assessment bodies operating under EUCC, product vendors (silicon, smart cards, network devices, software, IoT), procurement and integration teams, and policy bodies from the EU, national governments, and international standards organisations.