Your own certificate
Status changes (active, in maintenance, archived, withdrawn), Security Target republications, Maintenance Reports, and Certification Report updates on every certificate where your product is the TOE.
Use case: Vendor certification program
Common Criteria certificates do not sit still. Schemes republish Security Targets, issue Maintenance Reports, and flip statuses without sending an email. If your product is in the field under an EAL4+ certification today, the document set on commoncriteriaportal.org or your national scheme portal will change a handful of times before it expires, and almost every vendor finds out at the next surveillance audit, not the day it happens.
NenkinTracker watches your certificate and the components you reused every day, and emails you the moment BSI, ANSSI, NIAP, EUCC, SESIP, or any scheme republishes a document or changes a status. From €99/month on the Professional plan, excluding VAT, with a 30-day free trial.
Status changes (active, in maintenance, archived, withdrawn), Security Target republications, Maintenance Reports, and Certification Report updates on every certificate where your product is the TOE.
If your product builds on a certified platform (smart card OS, secure element, HSM, TPM) we watch those underlying certs too. A status flip on a dependency lands in your inbox, not in next year's audit.
NVD entries linked to your certified product, as they publish. CVSS, affected versions, and remediation status, attached to the certificate they impact.
Five categories of change cover almost every signal a vendor cert-program manager needs to act on. NenkinTracker emits one notification per change, attributed to the document and scheme that produced it.
Certification bodies publish their "Products in Evaluation" lists in plain sight. The list shows which vendor filed at which lab, against which assurance package, at roughly what time. NenkinTracker ingests every one of these lists across BSI, NIAP, CCCS, JISEC, CSEC Sweden, TrustCB, Brightsight, and the equivalents, so a cert-program manager can read what was previously reconstructed from rumour.
Three uses come up routinely. Roadmap timing: a direct competitor that entered evaluation eight months ago at a lab with a twelve-month average cycle is probably four months from an announcement, which is a useful input to your own release decisions. Lab capacity: a target lab currently running several large evaluations is unlikely to start a new engagement quickly, regardless of what the lab's marketing-side responsiveness suggests. Cross-scheme positioning: a competitor that quietly enters a second scheme is signalling a regional or sector expansion before it shows up in the certified catalogue. The pattern is written up in Procurement Planning Before the Certificate Exists.
The Professional plan at €99/month covers up to 100 followed products across 10 lists. Team at €299/month adds unlimited lists and products, evaluation tracking, and following up to 3 developers. Enterprise at €499/month adds unlimited developer following, certification-source feeds, and custom notifications. Prices exclude VAT and additional users.
The 30-day free trial includes Enterprise features with no credit card required, so you can prove the workflow on your own certificates before you commit.
NenkinTracker is built by Nenkin Technologies AS, a Norwegian Common Criteria company. Our co-founder Kjartan Kvassness Jæger spent six years as Technical Manager at the Norwegian national security authority and has represented Norway on the Common Criteria Development Board, the SOG-IS Joint Interpretation Working Group, and ISO/IEC JTC1 SC 27 / WG3 for more than twenty years. Co-founder Lauritz Prag Sømme led the threat-modelling framework at DNB Bank as security architect and consults on secure systems for the Norwegian Defence Materiel Agency. The "silent revisions" problem this page is about is one we lived firsthand chasing document churn across scheme portals.
Start the 30-day free trial and follow your own products in five minutes. Or book 30 minutes with a founder if you would rather walk through the workflow with us first.