Foundational questions about the Common Criteria standard itself: what it is, who maintains it, and how it differs from other security frameworks.
ISO/IEC 15408 is the formal name for the Common Criteria for Information Technology Security Evaluation. The CC:2022 edition is a five-part international standard (Part 1: Introduction and general model, Part 2: Security functional components, Part 3: Security assurance components, Part 4: Framework for evaluation methods and activities, Part 5: Pre-defined packages of security requirements, where the EAL packages now live) that defines a common framework for specifying and evaluating the security of IT products. See our Common Criteria overview for more.
Common Criteria is maintained by the Common Criteria Management Board (CCMB) and the Common Criteria Development Board (CCDB), with participation from national scheme bodies such as BSI, ANSSI, NIAP, and CCCS. The official specifications and methodology documents are published on the Common Criteria Portal at commoncriteriaportal.org.
Common Criteria evaluates the security of a specific IT product (a piece of hardware, firmware, or software), while ISO 27001 certifies an organization's information security management system. A vendor might hold ISO 27001 for its internal processes and separately certify individual products under Common Criteria. The two are complementary rather than substitutes.
A Target of Evaluation (TOE) is the specific product, subsystem, or configuration that is being evaluated under Common Criteria. The TOE boundary is defined in the Security Target and determines what is covered by the certificate and what lies outside its scope. Anything outside the TOE boundary is not guaranteed by the certification.
A Security Target (ST) is the central document in a Common Criteria evaluation. It describes the TOE, the threats it is designed to counter, the security objectives, and the Security Functional Requirements (SFRs) the product claims to implement. Every certified product has a published Security Target that defines the scope of its certificate.
The Common Evaluation Methodology (CEM), formally ISO/IEC 18045, is the companion standard to Common Criteria. It specifies how evaluators should perform assurance activities, what evidence they must gather, and how they should document findings. Together, CC and CEM ensure that evaluations are reproducible and comparable across labs and schemes.
The current release is Common Criteria version 2022 (CC:2022), which aligns with ISO/IEC 15408:2022. It replaces the long-running CC v3.1 release series but schemes and vendors are transitioning gradually, so both versions remain in active use for new evaluations and existing certificates.
In Common Criteria, certification is the act of issuing a certificate for a specific product evaluation, performed by a national scheme body. Accreditation is a separate process in which an authority confirms that an evaluation laboratory (ITSEF) is competent to carry out CC evaluations. A certified product has been evaluated by an accredited lab and certified by an authorizing scheme.
Yes. Common Criteria continues to be the dominant international standard for IT security product evaluation. It now also underpins the EU Cybersecurity Certification scheme (EUCC), which adds EU regulatory weight on top of the CCRA mutual-recognition arrangement. New evaluations are issued daily across CCRA member nations and EUCC; see the certification database for the active corpus.
A CC certificate is a one or two page issuance document from the certifying scheme. It identifies the certificate by ID, names the Target of Evaluation, lists the EAL and any Protection Profile conformance, gives the date of issue and validity period, and identifies the vendor. The detailed evaluation evidence lives in the accompanying Security Target and Certification Report. See How to read a Common Criteria certificate.
No. SESIP is GlobalPlatform's separate evaluation methodology for IoT platforms and components. It reuses Common Criteria vocabulary and structure but defines its own assurance ladder (SESIP 1 through SESIP 5) calibrated to typical IoT deployment contexts. SESIP and Common Criteria can complement each other in stacked evaluations. See SESIP vs Common Criteria: When to choose each.