What to watch at ICCC26: a curtain-raiser for Common Criteria in Rome
The Common Criteria community holds one annual gathering where the schemes, the labs, the vendors, and the policy bodies all sit in one room. This year it is in Rome, from 28 September to 1 October 2026, at Cardo Roma. The conference is the 25th edition of ICCC, and the program looks more consequential than the average year. The published theme, “Managing Compliance Across an Expanding Certification Landscape,” is doing some work.
EUCC has crossed 30 published certificates since the previous edition. The EU Cyber Resilience Act is rewriting what conformity assessment means for connected products, with the operational details (which products, which assurance levels, which assessment routes) still being worked out. The host country, Italy, has just retired its national Common Criteria scheme in favour of the EU framework. Plenty of conversations that have been held bilaterally over the past twelve months will become public in late September.
This is a curtain-raiser. We have not been to every session yet (no one has, the program is still being finalised), but the shape of the week, the named tracks, and the sponsor list are enough to call out what is worth watching.
The shape of the week
ICCC26 runs over four days, with the first one optional. The full schedule of events is published on the conference site; the headline structure is:
- Monday 28 September: CC Action Plan Day. A pre-conference day framed around turning Common Criteria from a bottleneck into a competitive advantage for ICT developers. Included in the 4-day pass, optional otherwise.
- Tuesday 29 September: opening plenary keynote (09:00 to 10:15), morning plenary session (11:00 to 13:00), three concurrent tracks in the afternoon, welcome reception in the exhibits (17:30), evening dinner (19:30).
- Wednesday 30 September: four concurrent track blocks across the day. Exhibits close at end of day.
- Thursday 1 October: morning track sessions including the dedicated Assurance track, closing plenary 13:00 to 14:00, conference adjourns.
Expected attendance is over 400 delegates from 28 countries, which is the upper end of the typical ICCC range and consistent with a host city that draws well.
Why this edition matters more than the average year
Three regulatory currents collide in 2026, and ICCC26 is the first venue where the people who have to operationalise them will be in the same room since the picture took shape.
EUCC moved from draft framework to real publishing surface. When the community last met in Korea in October 2025, EUCC certificates were being issued but the registry was sparse and the operational details (CAB onboarding, ENISA portal behaviour, assurance continuity rules) were still being shaken down. Fifteen months on, the scheme has 30 published certificates, multiple active CABs across Member States, and an identifier format that has already been quietly reformatted once. Plenty to talk about.
The Cyber Resilience Act is now in scope for the same audience. CRA conformity assessment will lean on horizontal cybersecurity standards and, where appropriate, on EUCC. Which products land in which assurance route, what the gap between CRA self-assessment and a third-party EUCC certification will mean for vendors, and how labs will be resourced for the expected demand surge are all live questions.
The CC standard itself is in revision. “New CC ISO Revision Update” is a named track for the first time. The CC:2022 baseline is now embedded in EUCC, and the next revision will determine what schemes, labs, and vendors code against for the back half of the decade.
Layer on top of that the structural conversation about continuous assurance (what to do about vulnerabilities discovered after certification, how to handle patch management for certified products, how AVA_VAN guidance should evolve), and there is enough material to fill the four days twice over.
What we are watching, track by track
ICCC26 publishes six tracks. Based on the call for speakers and the precedent set by ICCC25’s agenda in Korea, here is what we expect from each.
Advances in the Use of Common Criteria. The A-track is where continuous assurance, vulnerability management beyond certification maintenance, attack potential and CVSS scoring, and post-quantum cryptography readiness will land. This is also typically where AI assurance, cloud, OT, and other emerging-domain topics appear, framed as “how does CC methodology apply here.” A useful track for anyone trying to certify something that does not look like a smart card.
Assurance. The dedicated Assurance track is new on the named-track list this year. We expect deeper sessions on AVA_VAN evolution, CEM:2022 in practice, evaluator-side methodology questions, and the supporting documents (the SOG-IS-era documents now being absorbed into the EUCC framework). This is the track for the labs.
Cybersecurity Certification Schemes Landscape. The L-track is where the regulatory comparisons happen. EUCC, CRA, candidate EUCS for cloud services, EU Digital Identity Wallet certification, and the relationship between the EU framework and the CCRA. Expect at least one panel on what each scheme is for and where the overlaps are starting to bite.
Meeting Customer Requirements. The M-track is the procurement and deployment side. What buyers actually want to read on a certificate, how to express security requirements in a contract, the gap between EAL packages (still how the procurement community thinks) and the EUCC Substantial / High labels (how the regulator thinks). Useful for anyone on the buying side of certified products.
New CC ISO Revision Update. The first time this has been a named track. The CC standard revision cycle is slow-moving but high-stakes plumbing. The schemes, the labs, and the vendors all want a quiet runway with no surprises. Worth watching for any early signals on what the next revision will and will not contain.
Updates from Schemes and iTCs. The U-track is the regular reports from CCRA national schemes (BSI, ANSSI, NIAP, OCSI, NSCIB, CCCS, JISEC, KECS, and others) and from the international Technical Communities. Mostly status reports, occasionally newsworthy when a scheme announces a process change or a new product category coming into scope.
The split between A, L, M, and U has been stable for years. The Assurance and CC ISO Revision tracks being named separately this year is the structural change worth noticing.
The host scheme is its own case study
OCSI (Organismo di Certificazione della Sicurezza Informatica) is Italy’s national CC body, transferred to the Italian Cybersecurity Agency (ACN) in July 2022. On 27 February 2026, OCSI wound down its national CC scheme and now functions as Italy’s EUCC NCCA, per ACN’s own statement on the OCSI page. Italian CC evaluations now route through the EUCC framework rather than through a parallel national scheme.
That makes Rome a slightly unusual host city. ICCC is normally hosted by a country whose national scheme is still actively issuing under CCRA. Italy is one of the first CCRA Authorising members to have completed the transition the rest of the EU is in the middle of. Whatever lessons OCSI and ACN have learned from running the transition end to end (CAB readiness, vendor communication, the practical mechanics of redirecting in-flight evaluations) will be one of the more useful informal threads of the week. Rome also hosted ICCC7 in 2007, so this is Italy’s second turn at the conference.
The exhibit floor reads as a map of the lab market
The published sponsor list for ICCC26 is a useful snapshot of the active CC evaluation and consulting market.
- Title sponsors: Securus Consulting Group (Platinum), UL Solutions (Gold), Brightsight, Intertek Acumen Security with EWA-Canada, LGAI Technological Center, and TUV Informationstechnik (TUViT, all Silver).
- Leading sponsors: CCLab (hosting the opening reception), DEKRA (track sponsor), konfidas, Teron Labs (badges and lanyards), Zhejiang Wonsec (WiFi).
- Exhibitors: eShard, Red Alert Labs.
- Supporting associations: CCUF, EUCC ISAC, Eurosmart, Global Platform, OASIS, Trusted Connectivity Alliance, Biometric Update.
That roster spans BSI-licensed labs, ANSSI-licensed labs, NIAP CCTLs, and EUCC-accredited CABs. It also covers the consulting tier (Securus, konfidas) and the policy and standards bodies (Eurosmart, OASIS, Trusted Connectivity Alliance). For procurement and integration teams trying to map who can evaluate what under which scheme, walking the exhibit floor at ICCC26 is probably the highest-bandwidth way to do that in person.
Practical notes for delegates
- Early-bird registration (via the official ICCC26 site) closes 18 August 2026. Saves EUR 380 on the 3-day pass (EUR 1,150 vs EUR 1,530) or EUR 490 on the 4-day pass that includes Action Plan Day (EUR 1,460 vs EUR 1,950).
- Refund window closes 8 September 2026; cancellations after that date are non-refundable.
- Speaker slides are due to the organisers on 8 September. Speakers receive complimentary full conference registration.
- Session format is 30-minute talks (including Q&A) and 60-minute panels.
- Venue is Cardo Roma, in the southern EUR business district. Allow more travel time from the historic centre than the map suggests.
- Side meetings typically cluster around the welcome reception (Tuesday evening) and the lunches; the schedule does not formally allocate working-group time, so most bilateral conversations happen at the margins.
How NenkinTracker helps you see this
The schemes, labs, CABs, and vendors heading to Rome are the bodies generating the records we ingest every day. NenkinTracker indexes certificates across seven schemes (CCRA, EUCC, SESIP, PSA, ESA, EMVCo, MIFARE). Explore the tracker to follow products across these schemes.
If you are heading to ICCC26, useful pre-conference reading is a quick refresher on where each scheme stands now: the EUCC corpus, your home national scheme, and any vendor portfolios you follow. Those are the views the tracker is built around.
We will publish a follow-up after the conference with the program details that turned out to matter, the announcements that landed, and any structural changes to scheme practice worth flagging.
See also
- EUCC: What the EU Cybersecurity Certification Scheme Means for Common Criteria: background on the scheme that dominates the 2026 program
- EUCC at 30 certifications: where the EU scheme sits heading into the conference
- Common Criteria vs EUCC: A Migration Guide: the practical migration questions delegates are working through
- EUCC vs CCRA: how the two frameworks compare on governance and recognition
- OCSI: Italy's Common Criteria scheme: the host country scheme, now an EUCC NCCA
- What is Common Criteria?: background on the standard that anchors the conference