Use case: Regulated procurement
Check if a Common Criteria certificate is current, real, and matches the SKU you are buying.
Common Criteria certifications turn up in RFPs as a procurement requirement, but the official portals do not make verification easy. CCRA's commoncriteriaportal.org is a static list. EUCC certificates live on a different registry. SESIP, PSA Certified, EMVCo, ESA and MIFARE each have their own. NenkinTracker indexes all of them in one searchable database, so you can answer "is this certificate real and current?" in seconds rather than tabs.
How to verify a Common Criteria certificate
- Open the NenkinTracker certifications database. Open NenkinTracker at tracker.nenkin.io to search certifications. It covers every CCRA national scheme, plus EUCC, SESIP, PSA Certified, EMVCo, MIFARE, and ESA: one query, one result list, no scheme-by-scheme tab juggling.
- Match the certificate to the SKU. Confirm the product name, version, and vendor on the certificate match the SKU on your quote exactly. Vendors sometimes ship a v1.2.4 of a product whose certificate was issued for v1.2.3, where the certificate may still be valid for the older version only.
- Read the status and dates honestly. A certificate's status (active, in maintenance, archived, withdrawn) and its issue/expiry/maintenance dates tell you what an auditor will accept. The wiki entry on what 'current' actually means under CC walks through the six combinations that matter.
- Set up monitoring for the shortlist. For the products you are actually buying, follow them in NenkinTracker so any future change (status flip, archived flag, new CVE on the TOE) lands in your inbox before your audit.
New to what "current" means in CC? The wiki entry on Common Criteria certificate validity walks through every status combination an auditor will look at and what each one actually allows the buyer to claim.
Plan beyond today's catalogue
The certificate registry tells you what is already certified. It tells you nothing about what will be certified next year. For a multi-year compliance programme, or a specification that calls for a particular EAL level, that lag is the difference between planning against today's supply and planning against what is coming.
Every major certification body publishes a public "Products in Evaluation" list (BSI, NIAP, CCCS, JISEC, CSEC Sweden, TrustCB, Brightsight, and the equivalents). NenkinTracker ingests every one of them. Search returns under-evaluation products with an "Under Eval" badge, a filter chip restricts the catalogue to that subset, and you can subscribe to a scheme to receive a notification each time a new product enters evaluation there. The pattern is written up in full in Procurement Planning Before the Certificate Exists.
RFP clause: certificate validity and notification
A clause you can drop into supplier contracts. It binds the vendor to hold a current certificate for the supplied version and to notify the buyer of any change. Use, edit, and redistribute freely. No attribution required.
The Supplier shall, at the time of contract award and throughout the term, hold a valid Common Criteria certificate (or equivalent EUCC, SESIP, or scheme-recognised certification) for the offered product at the version supplied, issued by a CCRA-recognised national scheme or by an EUCC-accredited Conformity Assessment Body. The Supplier shall notify the Buyer in writing within ten (10) business days of any change to certificate status (including but not limited to: entry into maintenance, archival, withdrawal, or expiry without renewal), publication of a new Maintenance Report, republication of the Security Target, or linkage of any CVE to the certified product. For continuous monitoring of the suppliers covered by this clause, follow each product in NenkinTracker. Any status flip, new Maintenance Report, or CVE linked to the TOE triggers a notification you can forward to the supplier under the notification clause above.
Verify and monitor in NenkinTracker.
Search certifications and monitor your shortlist in the NenkinTracker application. Professional at €99/month covers up to 100 followed products across 10 lists, with certification, document, and CVE notifications. Team at €299/month adds unlimited lists and products, developer following, and evaluation tracking. Prices exclude VAT and additional users. The 30-day free trial includes Enterprise features, no credit card required.
Frequently asked questions
- How do I verify that a Common Criteria certificate is current?
- Search certifications in the application at tracker.nenkin.io. Look up the product, vendor, or certificate ID and read off the status and dates. Every entry links back to the source document on the issuing scheme so you can confirm against the authoritative registry. For continuous verification (so a status flip after the quote is signed reaches you) follow the certificate in NenkinTracker.
- What schemes does the certifications database cover?
- Every CCRA national scheme (BSI, ANSSI, NIAP, CCCS, SERTIT, JISEC, KCMVP, OCSI, CCN), the EUCC scheme under the EU Cybersecurity Act, SESIP, PSA Certified, EMVCo, MIFARE, and ESA. Coverage is documented at nenkin.io/data.
- Can NenkinTracker email me when a certificate I am about to buy gets archived?
- Yes. Sign in and follow the product to receive email and in-app notifications about certification and document changes. Professional costs €99/month excluding VAT and covers up to 100 followed products across 10 lists. Team costs €299/month excluding VAT and adds unlimited lists and products, developer following, and evaluation tracking. The 30-day free trial includes Enterprise features.
- Is NenkinTracker authoritative on certificate status?
- NenkinTracker mirrors the public data published by each issuing scheme and refreshes daily. For legally authoritative confirmation, the issuing scheme's own registry (linked from every result) remains the source of truth. NenkinTracker's role is to make that data searchable, comparable across schemes, and pushable to your inbox when it changes.
- How can we see what will be certified next year, not just what was certified last year?
- Most certification bodies publish a public 'Products in Evaluation' list (BSI, NIAP, CCCS, JISEC, CSEC Sweden, TrustCB, Brightsight, and the equivalents). NenkinTracker ingests every one of them, so search returns under-evaluation products with an 'Under Eval' badge and a filter chip restricts the catalogue to that subset. Follow a scheme to be notified when a new product enters evaluation there, or follow a specific under-evaluation product to be alerted when its certificate eventually issues. The pipeline view extends a procurement planning horizon by roughly the length of an evaluation cycle, typically twelve to eighteen months.
Verify the certificate. Then keep verifying it.
Explore the tracker to verify certifications and follow the products on your shortlist. Start with a 30-day free trial.