Skip to content
Nenkin

Nenkin expertise / Certification consulting

A clear path to certification.

Plan the evaluation, prepare the evidence, and coordinate the work. Nenkin supports vendors from scheme selection and Security Target authoring through certification and maintenance.

Where we can help.

Start with one question or a complete programme. We agree the scope and deliverables around your product and decision.

01

Strategy & advisory

Decide whether to certify, which scheme to target, and at what assurance level, before you commit budget or schedule.

Typical work
  • Scheme selection across CCRA, EUCC, SESIP, EMVCo, PSA, MIFARE, ESA
  • Assurance level scoping (EAL, SESIP, PSA Levels)
  • Composition strategy for products built on certified components
  • Reuse and maintenance planning for existing certificates
02

Security Target authoring

We write the Security Target, supporting design rationale, and required architectural artifacts in formats labs and certifiers expect.

Typical work
  • ST scoping, security problem definition, and SFR derivation
  • Conformance to relevant Protection Profiles where applicable
  • Aligning ST scope with product reality, not aspirational claims
  • CC:2022 and legacy CC v3.1r5 documentation
03

Lab selection & coordination

Match the right evaluation lab to your product, scheme, and timeline. We manage the lab relationship through evaluation.

Typical work
  • Lab shortlisting based on scheme, technology, and capacity
  • Quote review and engagement scoping
  • Evaluator-question (OR) handling and response coordination
  • Single point of contact between vendor, lab, and certifier
04

End-to-end program management

We run the certification program from kickoff to certificate issuance so your engineering team can stay focused on the product.

Typical work
  • Project plan, milestones, and risk register tailored to the scheme
  • Documentation deliverables tracked against the lab work programme
  • Stakeholder management across vendor, lab, and certifier
  • Maintenance and surveillance planning post-certification

A practical outcome

Work you can act on.

Your engagement has a defined scope, named advisors, and written deliverables.

  • An agreed certification strategy and scope.
  • A Security Target and supporting evaluation evidence.
  • A programme plan with milestones and responsibilities.
  • Coordinated responses to evaluator questions.

Practitioner experience

Talk to people who read the evidence.

Nenkin brings Common Criteria evaluation experience together with security architecture in banking and defence.

Meet the team ↗
Which schemes do you work with?

We work across CCRA national schemes, EUCC, SESIP, PSA Certified, EMVCo, MIFARE, and eSA. Scheme selection and multi-scheme programmes are part of the initial scoping work.

Can you join an evaluation already in progress?

Yes. We can review the current Security Target, open evaluator questions, and programme status before agreeing how to help.

How do you scope and price the work?

We offer fixed-fee work for defined deliverables and time-and-materials support for ongoing programmes. We agree the engagement model, milestones, and responsibilities before work begins.

Tell us about your next decision.

A short description of the product, scope, and timing is enough to begin.

Contact our team