Services

Common Criteria consultancy from people who ship certifications.

Nenkin Technologies AS runs Common Criteria certification programs end to end - from "should we certify?" through Security Target authoring, lab selection, and shepherding the evaluation to certificate issuance. Founder-led, Norwegian, scheme-agnostic.

What we do

Four service lines covering the full certification lifecycle. We engage on any single line, or run the entire program as a single accountable owner.

Strategy & advisory

Decide whether to certify, which scheme to target, and at what assurance level - before you commit budget or schedule.

  • Scheme selection across CCRA, EUCC, SESIP, EMVCo, PSA, MIFARE, ESA
  • Assurance level scoping (EAL, SESIP, PSA Levels)
  • Composition strategy for products built on certified components
  • Reuse and maintenance planning for existing certificates

Security Target authoring

We write the Security Target, supporting design rationale, and required architectural artifacts in formats labs and certifiers expect.

  • ST scoping, security problem definition, and SFR derivation
  • Conformance to relevant Protection Profiles where applicable
  • Aligning ST scope with product reality - not aspirational claims
  • CC:2022 and legacy CC v3.1r5 documentation

Lab selection & coordination

Match the right evaluation lab to your product, scheme, and timeline. We manage the lab relationship through evaluation.

  • Lab shortlisting based on scheme, technology, and capacity
  • Quote review and engagement scoping
  • Evaluator-question (OR) handling and response coordination
  • Single point of contact between vendor, lab, and certifier

End-to-end program management

We run the certification program from kickoff to certificate issuance so your engineering team can stay focused on the product.

  • Project plan, milestones, and risk register tailored to the scheme
  • Documentation deliverables tracked against the lab work programme
  • Stakeholder management across vendor, lab, and certifier
  • Maintenance and surveillance planning post-certification

Why us

Founder-led, no handoffs

The person scoping your engagement is the person doing the work. No junior bench, no offshore drop-off, no margin gap between the pitch and the delivery.

Independent of any lab

We are not owned by, nor exclusive to, any evaluation lab. That means we can match the right lab to your product on merit - capacity, scheme, technology fit - rather than steering you toward a captive partner.

Norwegian AS

Nenkin Technologies AS is incorporated in Norway. EU-aligned for EUCC engagements, with the contractual and data-handling posture European procurement teams expect.

Schemes we work in

From CCRA national schemes through to the newer European and industry frameworks. New to a scheme? Each name links to our wiki entry on it.

Engagement model

The honest answers to the questions every procurement team asks before they sign.

Talk to us about your certification.

Tell us where the product is today and what you need certified. We will come back with an honest scoping read, including whether we are the right fit.