Skip to content
Nenkin

Nenkin expertise / Procurement advisory

Read the evidence before you buy.

Understand what a certificate covers, where the limitations sit, and whether the evidence matches the product you need. Nenkin gives buyers an independent technical assessment.

Where we can help.

Start with one question or a complete programme. We agree the scope and deliverables around your product and decision.

01

Requirements scoping

Translate operational and regulatory needs into a procurement specification a vendor can actually bid against.

Typical work
  • Map use case, threat model, and deployment environment to assurance level
  • Identify which schemes a candidate certificate must come from
  • Define minimum Protection Profile or SESIP profile conformance
  • Capture lifecycle constraints (maintenance, end of support, surveillance)
02

Market survey and shortlisting

Build the candidate vendor list from the live certified product landscape, not from sales decks.

Typical work
  • Search the Common Criteria, EUCC, SESIP, EMVCo, PSA and MIFARE registries
  • Cross check certificate validity, scope, and surveillance status
  • Flag products whose certificates are expired, archived, or have a narrowed scope
  • Surface known CVEs and notable advisories against the candidates
03

Bid evaluation and due diligence

Independent technical review of vendor responses, certificates, and Security Targets so the comparison is apples to apples.

Typical work
  • Read the Security Target against the actual procurement requirement
  • Verify the certified TOE matches the product being sold
  • Spot scope narrowing, optional features, and assumptions that change risk
  • Compare assurance level claims across CC, EUCC, SESIP, PSA
04

Negotiation and contracting support

Get the security relevant commitments into the contract before signature, not after the first incident.

Typical work
  • Patching SLAs and vulnerability disclosure obligations
  • Maintenance and assurance continuity commitments
  • End of life, replacement, and certificate renewal expectations
  • Right to audit and re-evaluation triggers

A practical outcome

Work you can act on.

Your engagement has a defined scope, named advisors, and written deliverables.

  • A requirements and assurance-level brief.
  • A candidate shortlist with supporting certification evidence.
  • A review of scope, validity, dependencies, and known vulnerabilities.
  • A written recommendation and questions to resolve with the vendor.

Practitioner experience

Talk to people who read the evidence.

Nenkin brings Common Criteria evaluation experience together with security architecture in banking and defence.

Meet the team ↗
How does this differ from certification consulting?

Procurement advisory supports buyers choosing between products. Certification consulting supports vendors preparing a product for evaluation. We do not represent both sides of a single transaction.

What kinds of products can you assess?

Our experience spans smart cards, secure ICs and SoCs, network and telecom infrastructure, IoT platforms, mobile and payment security, Trusted Execution Environments, and eIDAS signature devices. We agree the scope and identify where specialist input is needed.

What does an engagement look like?

We can review a single candidate or support a broader market survey and bid evaluation. Defined reviews can use a fixed fee; longer engagements can use time and materials. Deliverables and milestones are agreed in advance.

Tell us about your next decision.

A short description of the product, scope, and timing is enough to begin.

Contact our team