Skip to content
Nenkin

How long does a Common Criteria certificate last?

Most CC certificates are issued for 5 years and may be extended via maintenance updates. The histogram below shows the actual distribution from 268 expired and archived certificates. Median validity period: 5 years.

  • 1-3 years 46
  • 4-5 years 184
  • 6-7 years 32
  • 8+ years 6

Expired certificates by scheme

Total expired or archived certificates per scheme.

  • CCRA 212
  • MIFARE 39
  • SESIP 17

Expired certificates by EAL

Distribution of expired certificates across Evaluation Assurance Levels.

  • EAL1 2
  • EAL2 40
  • EAL3 18
  • EAL4 29
  • EAL5 36
  • EAL6 8
  • EAL7 1

Expiry year trend

Number of certificates expiring (or already expired) per year.

  • 2023 2
  • 2024 20
  • 2025 21
  • 2026 225

Get notified before a supplier's certificate lapses

Set up watches on the products and vendors you depend on, and NenkinTracker emails you the moment a certificate moves toward expiry, gets archived, or has a new maintenance update posted. No more discovering at audit time that the certificate you relied on lapsed six months ago.

  • Per-product follows: notification on every status change, maintenance update, and new document version
  • Per-vendor follows: catch a vendor letting their entire catalog lapse before your renewal cycle does
  • Expiry forecasting on your shortlist, with the date the certificate's validity period ends
  • Audit-ready evidence export for every certificate you track, with version history and source-document hashes
Register now

30-day free trial. No credit card required.

About Common Criteria certificate expiry

Common Criteria (ISO/IEC 15408) certificates are issued with an explicit validity period, typically 5 years from the certificate's date of issue, though the period varies by scheme and Protection Profile. After expiry, the certificate is no longer valid for procurement claims unless the vendor has obtained a maintenance update or a fresh re-evaluation. Some schemes archive expired certificates rather than delisting them entirely; archived certificates remain in the public record but cannot be cited as active evidence.

Many procurement frameworks accept maintenance updates (also called assurance continuity) as proof that a previously certified product still meets its Security Target. NenkinTracker tracks maintenance update events alongside the original certification, so a product whose base certificate is expired but whose maintenance updates are current still surfaces correctly.