Common Criteria Knowledge Base
A practical reference for Common Criteria (ISO/IEC 15408), evaluation assurance levels, Protection Profiles, and the certification scheme landscape.
- Articles
- 35
- Categories
- 4
- Standard
- ISO/IEC 15408
Common Criteria Overview: ISO/IEC 15408 Explained
Complete overview of Common Criteria (ISO/IEC 15408): the international standard for IT security evaluation, EAL levels, Protection Profiles, and the CCRA mutual-recognition framework.
Read the overview →Contents
- Fundamentals (4)
- Reference (7)
- EAL Levels (7)
- Schemes (17)
Fundamentals
- Common Criteria Overview: ISO/IEC 15408 Explained
Complete overview of Common Criteria (ISO/IEC 15408): the international standard for IT security evaluation, EAL levels, Protection Profiles, and the CCRA mutual-recognition framework.
- Certification Schemes Overview
An overview of the major Common Criteria certification schemes worldwide, including BSI, ANSSI, NIAP, and the emerging EUCC.
- Evaluation Assurance Levels (EAL)
Reference guide to EAL1 through EAL7: what each Evaluation Assurance Level requires, what it measures, and how it affects procurement decisions.
- Protection Profiles (PP)
What Protection Profiles are, how they work in Common Criteria evaluations, and why they matter for procurement and compliance.
Reference
- Common Criteria Glossary
Definitions of Common Criteria (ISO/IEC 15408) terms: EAL, PP, ST, TOE, SFR, SAR, TSF, CCRA, EUCC, SESIP, cPP, and more.
- Security Target (ST): Common Criteria Document Type
What a Security Target is, how it differs from a Protection Profile, and what each section of an ST contains under Common Criteria (ISO/IEC 15408).
- Common Criteria Certificate Validity and Expiry
How long Common Criteria certificates last, what happens when they expire, and how schemes handle archived, withdrawn, and re-evaluated certificates.
- Common Criteria Procurement Guide: Buying Security-Sensitive Products
A reference guide for procurement teams sourcing Common Criteria, EUCC, SESIP, PSA, and EMVCo certified products. How to read certificates, Security Targets, and assurance claims at procurement time.
- Security Target Review for Buyers: A Procurement Checklist
How a procurement reviewer should read a Common Criteria Security Target: section by section, with the gotchas, mismatch patterns, and a worked example.
- EAL Augmentations Explained: AVA_VAN, ALC_DVS, ALC_FLR, and Beyond
Reference guide to Common Criteria EAL augmentations: what AVA_VAN, ALC_DVS, ALC_FLR, ATE, and AGD components mean, how they change an EAL claim, and how to write them into a procurement spec.
- Composite Certifications: Smart Cards, Applets, and Platform Stacks
Reference on composite Common Criteria evaluations: how chip, platform, and applet certificates layer, what the Composite Evaluation Methodology requires, and how procurement teams verify the chain.
EAL Levels
- EAL1: Functionally Tested
EAL1 is the lowest Common Criteria assurance level: independent confirmation that a product behaves as documented. Suitable when threats are low and trust in the vendor is adequate.
- EAL2: Structurally Tested
EAL2 is the workhorse Common Criteria assurance level: a high-level design review with independent vulnerability analysis, and the CCRA mutual-recognition cap for non-cPP evaluations.
- EAL3: Methodically Tested and Checked
EAL3 extends EAL2 with development environment security controls, systematic life-cycle definition, and deeper test coverage. Less common than EAL2 or EAL4 in practice.
- EAL4: Methodically Designed, Tested, and Reviewed
EAL4 is the highest assurance level generally achievable on commercial products without re-engineering for assurance. Standard for smart cards, HSMs, and many government-used products.
- EAL5: Semiformally Designed and Tested
EAL5 introduces semiformal design notation, well-structured internals, and modular-design test depth. Typical for smart card ICs and high-assurance OS kernels.
- EAL6: Semiformally Verified Design and Tested
EAL6 requires semiformal verification of design correspondence and layered internals, paired with High attack potential vulnerability analysis. Rare, reserved for high-risk TOEs.
- EAL7: Formally Verified Design and Tested
EAL7 is the highest Common Criteria assurance level: formal verification that the TOE design implements the security policy, for TOEs small enough to be amenable to mathematical proof.
Schemes
- BSI: Germany's Common Criteria Scheme
BSI (Bundesamt für Sicherheit in der Informationstechnik) is Germany's Common Criteria certification body and one of the largest authorizing schemes under the CCRA.
- ANSSI: France's Common Criteria Scheme
ANSSI (Agence nationale de la sécurité des systèmes d'information) operates France's national CC scheme and is a major issuer of high-assurance smart card and embedded certificates.
- NIAP: The U.S. Common Criteria Scheme
NIAP (National Information Assurance Partnership) runs the U.S. Common Criteria scheme and mandates exact-conformance evaluations against approved Protection Profiles.
- CCCS: Canada's Common Criteria Scheme
The Canadian Centre for Cyber Security (CCCS) operates Canada's CC scheme, emphasising collaborative Protection Profile evaluations and Technical Community participation.
- JISEC: Japan's Common Criteria Scheme
JISEC is Japan's Common Criteria certification scheme, operated under IPA, covering copiers and MFPs, network products, and a range of IT security products.
- SERTIT: Norway's Common Criteria Scheme
SERTIT is Norway's Common Criteria certification body, operated under NSM, issuing CC certificates recognized across CCRA member nations.
- KCMVP: Korea's Cryptographic Module Validation Programme
KCMVP is South Korea's national validation programme for cryptographic modules used by Korean public institutions, run by the NSR under the National Intelligence Service.
- EUCC Overview: EU Common Criteria Certification Scheme
EUCC overview: the European Union's Common Criteria-based cybersecurity certification scheme, adopted under the EU Cybersecurity Act and replacing SOG-IS for member states. Updates, structure, and how it relates to CCRA.
- SESIP Overview: Security Evaluation Standard for IoT Platforms
SESIP overview: GlobalPlatform's Common Criteria-aligned security evaluation methodology for IoT platforms and components, defining the lighter-weight SESIP 1-5 assurance levels and how they map to CC.
- EUCC vs CCRA: How the Two Common Criteria Frameworks Relate
EUCC is the EU's regulatory Common Criteria scheme; CCRA is the international mutual-recognition arrangement. They share the same standard but differ on scope, governance, and recognition.
- EMVCo: Payment Product Security Evaluation
EMVCo runs independent security evaluation programmes for payment terminals, smart cards, and mobile payment components on behalf of the major payment networks.
- Beyond Common Criteria: SESIP, PSA, ESA, EMVCo, and MIFARE
The non-CC certification schemes that matter for IoT, payment, and chip-platform security, and how they relate to Common Criteria.
- PSA Certified: IoT Security Certification Maintained by GlobalPlatform
PSA Certified is a tiered IoT security certification programme originally developed by Arm and six partners, donated to GlobalPlatform in September 2025. TrustCB issues certificates at Levels 1 through 4.
- MIFARE: Contactless Smart Card Certifications
MIFARE is NXP's family of contactless smart card ICs for transit, access, and loyalty. Individual MIFARE products are evaluated under Common Criteria at high EALs.
- ESA: GSMA eUICC Security Assurance Scheme
ESA is GSMA's eUICC Security Assurance (eSA) scheme, the industry security certification programme for embedded UICC (eUICC) products. Operated by TrustCB under GSMA governance, evaluations use Common Criteria with eUICC-specific optimisations from SGP.06 and SGP.07.
- OCSI: Italy's Common Criteria Scheme
OCSI (Organismo di Certificazione della Sicurezza Informatica) is Italy's designated EUCC certification authority under the Italian Cybersecurity Agency (ACN). It previously operated Italy's national Common Criteria scheme, which retired on 27 February 2026.
- CCN: Spain's Common Criteria Scheme
CCN (Centro Criptológico Nacional) is Spain's national Common Criteria certification body, operated under the Spanish National Intelligence Centre (CNI).