<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss-style.xsl" type="text/xsl"?><rss version="2.0"><channel><title>Nenkin Wiki - Common Criteria Knowledge Base Updates</title><description>Updates to the Nenkin Wiki: Common Criteria, EAL levels, Protection Profiles, and the certification scheme landscape.</description><link>https://nenkin.io/</link><item><title>Beyond Common Criteria: SESIP, PSA, ESA, EMVCo, and MIFARE</title><link>https://nenkin.io/wiki/non-cc-certification-schemes/</link><guid isPermaLink="true">https://nenkin.io/wiki/non-cc-certification-schemes/</guid><description>The non-CC certification schemes that matter for IoT, payment, and chip-platform security - and how they relate to Common Criteria.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>Security Target (ST) - Common Criteria Document Type</title><link>https://nenkin.io/wiki/security-target/</link><guid isPermaLink="true">https://nenkin.io/wiki/security-target/</guid><description>What a Security Target is, how it differs from a Protection Profile, and what each section of an ST contains under Common Criteria (ISO/IEC 15408).</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Common Criteria Certificate Validity and Expiry</title><link>https://nenkin.io/wiki/cc-certificate-validity/</link><guid isPermaLink="true">https://nenkin.io/wiki/cc-certificate-validity/</guid><description>How long Common Criteria certificates last, what happens when they expire, and how schemes handle archived, withdrawn, and re-evaluated certificates.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>EUCC vs CCRA - How the Two Common Criteria Frameworks Relate</title><link>https://nenkin.io/wiki/eucc-vs-ccra/</link><guid isPermaLink="true">https://nenkin.io/wiki/eucc-vs-ccra/</guid><description>EUCC is the EU&apos;s regulatory Common Criteria scheme; CCRA is the international mutual-recognition arrangement. They share the same standard but differ on scope, governance, and recognition.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>OCSI - Italy&apos;s Common Criteria Scheme</title><link>https://nenkin.io/wiki/schemes/ocsi/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/ocsi/</guid><description>OCSI (Organismo di Certificazione della Sicurezza Informatica) is Italy&apos;s national Common Criteria certification body, operating under the Italian Cybersecurity Agency (ACN).</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>CCN - Spain&apos;s Common Criteria Scheme</title><link>https://nenkin.io/wiki/schemes/ccn/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/ccn/</guid><description>CCN (Centro Criptológico Nacional) is Spain&apos;s national Common Criteria certification body, operated under the Spanish National Intelligence Centre (CNI).</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>EAL1 - Functionally Tested</title><link>https://nenkin.io/wiki/eal/eal1/</link><guid isPermaLink="true">https://nenkin.io/wiki/eal/eal1/</guid><description>EAL1 is the lowest Common Criteria assurance level: independent confirmation that a product behaves as documented. Suitable when threats are low and trust in the vendor is adequate.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Common Criteria Glossary</title><link>https://nenkin.io/wiki/glossary/</link><guid isPermaLink="true">https://nenkin.io/wiki/glossary/</guid><description>Definitions of Common Criteria (ISO/IEC 15408) terms: EAL, PP, ST, TOE, SFR, SAR, TSF, CCRA, EUCC, SESIP, cPP, and more.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>BSI - Germany&apos;s Common Criteria Scheme</title><link>https://nenkin.io/wiki/schemes/bsi/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/bsi/</guid><description>BSI (Bundesamt für Sicherheit in der Informationstechnik) is Germany&apos;s Common Criteria certification body and one of the largest authorizing schemes under the CCRA.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>EAL2 - Structurally Tested</title><link>https://nenkin.io/wiki/eal/eal2/</link><guid isPermaLink="true">https://nenkin.io/wiki/eal/eal2/</guid><description>EAL2 is the workhorse Common Criteria assurance level: a high-level design review with independent vulnerability analysis, and the CCRA mutual-recognition cap for non-cPP evaluations.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>ANSSI - France&apos;s Common Criteria Scheme</title><link>https://nenkin.io/wiki/schemes/anssi/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/anssi/</guid><description>ANSSI (Agence nationale de la sécurité des systèmes d&apos;information) operates France&apos;s national CC scheme and is a major issuer of high-assurance smart card and embedded certificates.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>EAL3 - Methodically Tested and Checked</title><link>https://nenkin.io/wiki/eal/eal3/</link><guid isPermaLink="true">https://nenkin.io/wiki/eal/eal3/</guid><description>EAL3 extends EAL2 with development environment security controls, systematic life-cycle definition, and deeper test coverage. Less common than EAL2 or EAL4 in practice.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>NIAP - The U.S. Common Criteria Scheme</title><link>https://nenkin.io/wiki/schemes/niap/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/niap/</guid><description>NIAP (National Information Assurance Partnership) runs the U.S. Common Criteria scheme and mandates exact-conformance evaluations against approved Protection Profiles.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>EAL4 - Methodically Designed, Tested, and Reviewed</title><link>https://nenkin.io/wiki/eal/eal4/</link><guid isPermaLink="true">https://nenkin.io/wiki/eal/eal4/</guid><description>EAL4 is the highest assurance level generally achievable on commercial products without re-engineering for assurance. Standard for smart cards, HSMs, and many government-used products.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>CCCS - Canada&apos;s Common Criteria Scheme</title><link>https://nenkin.io/wiki/schemes/cccs/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/cccs/</guid><description>The Canadian Centre for Cyber Security (CCCS) operates Canada&apos;s CC scheme, emphasising collaborative Protection Profile evaluations and Technical Community participation.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>EAL5 - Semiformally Designed and Tested</title><link>https://nenkin.io/wiki/eal/eal5/</link><guid isPermaLink="true">https://nenkin.io/wiki/eal/eal5/</guid><description>EAL5 introduces semiformal design notation, full implementation representation, and covert channel analysis. Typical for smart card ICs and high-assurance OS kernels.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>JISEC - Japan&apos;s Common Criteria Scheme</title><link>https://nenkin.io/wiki/schemes/jisec/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/jisec/</guid><description>JISEC is Japan&apos;s Common Criteria certification scheme, operated under IPA, covering copiers and MFPs, network products, and a range of IT security products.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>EAL6 - Semiformally Verified Design and Tested</title><link>https://nenkin.io/wiki/eal/eal6/</link><guid isPermaLink="true">https://nenkin.io/wiki/eal/eal6/</guid><description>EAL6 requires semiformal verification of design correspondence and layered internals, paired with High attack potential vulnerability analysis. Rare, reserved for high-risk TOEs.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SERTIT - Norway&apos;s Common Criteria Scheme</title><link>https://nenkin.io/wiki/schemes/sertit/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/sertit/</guid><description>SERTIT is Norway&apos;s Common Criteria certification body, operated under NSM, issuing CC certificates recognized across CCRA member nations.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>EAL7 - Formally Verified Design and Tested</title><link>https://nenkin.io/wiki/eal/eal7/</link><guid isPermaLink="true">https://nenkin.io/wiki/eal/eal7/</guid><description>EAL7 is the highest Common Criteria assurance level: formal verification that the TOE design implements the security policy, for TOEs small enough to be amenable to mathematical proof.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>KCMVP - Korea&apos;s Cryptographic Module Validation Programme</title><link>https://nenkin.io/wiki/schemes/kcmvp/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/kcmvp/</guid><description>KCMVP is South Korea&apos;s national validation programme for cryptographic modules used by Korean public institutions, run by the NSR under the National Intelligence Service.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>EUCC Overview - EU Common Criteria Certification Scheme</title><link>https://nenkin.io/wiki/schemes/eucc-scheme/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/eucc-scheme/</guid><description>EUCC overview: the European Union&apos;s Common Criteria-based cybersecurity certification scheme, adopted under the EU Cybersecurity Act and replacing SOG-IS for member states. Updates, structure, and how it relates to CCRA.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>SESIP Overview - Security Evaluation Standard for IoT Platforms</title><link>https://nenkin.io/wiki/schemes/sesip-scheme/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/sesip-scheme/</guid><description>SESIP overview: GlobalPlatform&apos;s Common Criteria-aligned security evaluation methodology for IoT platforms and components, defining the lighter-weight SESIP 1-5 assurance levels and how they map to CC.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>EMVCo - Payment Product Security Evaluation</title><link>https://nenkin.io/wiki/schemes/emvco/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/emvco/</guid><description>EMVCo runs independent security evaluation programmes for payment terminals, smart cards, and mobile payment components on behalf of the major payment networks.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>PSA Certified - IoT Security Certification from Arm and Partners</title><link>https://nenkin.io/wiki/schemes/psa-certified/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/psa-certified/</guid><description>PSA Certified is a tiered IoT security certification programme co-authored by Arm, Brightsight, CAICT, Prove &amp; Run, Riscure, and UL (with TrustCB as certification body), offering laboratory evaluation at Levels 2 through 4.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>MIFARE - Contactless Smart Card Certifications</title><link>https://nenkin.io/wiki/schemes/mifare/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/mifare/</guid><description>MIFARE is NXP&apos;s family of contactless smart card ICs for transit, access, and loyalty. Individual MIFARE products are evaluated under Common Criteria at high EALs.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>ESA - European Space Agency Security Evaluations</title><link>https://nenkin.io/wiki/schemes/esa/</link><guid isPermaLink="true">https://nenkin.io/wiki/schemes/esa/</guid><description>Security evaluation activities associated with the European Space Agency, tracked alongside commercial Common Criteria certifications for components used in space systems.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Common Criteria Overview - ISO/IEC 15408 Explained</title><link>https://nenkin.io/wiki/common-criteria/</link><guid isPermaLink="true">https://nenkin.io/wiki/common-criteria/</guid><description>Complete overview of Common Criteria (ISO/IEC 15408): the international standard for IT security evaluation, EAL levels, Protection Profiles, and the CCRA mutual-recognition framework.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Certification Schemes Overview</title><link>https://nenkin.io/wiki/certification-schemes/</link><guid isPermaLink="true">https://nenkin.io/wiki/certification-schemes/</guid><description>An overview of the major Common Criteria certification schemes worldwide, including BSI, ANSSI, NIAP, and the emerging EUCC.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Evaluation Assurance Levels (EAL)</title><link>https://nenkin.io/wiki/eal-levels/</link><guid isPermaLink="true">https://nenkin.io/wiki/eal-levels/</guid><description>Reference guide to EAL1 through EAL7 - what each Evaluation Assurance Level requires, what it measures, and how it affects procurement decisions.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Protection Profiles (PP)</title><link>https://nenkin.io/wiki/protection-profiles/</link><guid isPermaLink="true">https://nenkin.io/wiki/protection-profiles/</guid><description>What Protection Profiles are, how they work in Common Criteria evaluations, and why they matter for procurement and compliance.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item></channel></rss>