Skip to content
Nenkin

Common Criteria Certificate Validity and Expiry

A Common Criteria (ISO/IEC 15408) certificate is not valid forever. Each certificate is issued with a defined validity period after which the certificate transitions to a non-active state. Procurement teams, auditors, and compliance reviewers need to understand what those states mean and how to act on them.

Summary: Most Common Criteria certificates are issued for around five years. After expiry the certificate is moved to an archived or withdrawn state and can no longer be cited as active evidence, though maintenance updates can extend assurance for minor changes during the validity window.

Typical validity period

There is no single global rule. Validity periods are set by the issuing national scheme and can also be constrained by the underlying Protection Profile. Common patterns include:

  • Five years is the most common nominal validity period across CCRA member schemes.
  • Two years is used by some schemes for specific Protection Profile families that are revised on a faster cadence.
  • Time-limited validity tied to a Protection Profile version: when the PP is superseded, certificates that conform to the old PP version may be moved to archive ahead of the nominal expiry.
  • EUCC and other regulatory schemes inherit similar validity windows from the wider Common Criteria framework, with additional rules around scheme-specific maintenance procedures.

Lifecycle states

A typical Common Criteria certificate moves through the following states:

  1. Active: the certificate is in force, the product can be cited as certified, and any vendor or procurement claim against the certificate is supported.
  2. Maintenance: a Maintenance Report has been issued for a minor change to the product or its environment. The base certificate remains active; the maintenance report extends the assurance scope to the changed version.
  3. Archived: the certificate has reached its nominal expiry date or has been superseded by a newer evaluation. The certificate remains in the public record but cannot be cited as active.
  4. Withdrawn or suspended: the certificate has been removed from the active list at the request of the vendor or by action of the issuing scheme. Reasons can include discovery of a vulnerability that materially affects the assurance, end-of-life of the product, or vendor-side changes that move the product out of scope.

The exact terminology varies by scheme. Some schemes use “expired” rather than “archived”; others distinguish between archive and withdrawal more strictly than the table above implies. The Common Criteria Portal and each national scheme’s registry are the authoritative sources for the current state of any individual certificate.

Maintenance and assurance continuity

Common Criteria includes formal procedures for keeping a certificate current as the underlying product evolves. The relevant document family is assurance continuity, set out in the CCRA’s “Assurance Continuity: CCRA Requirements” document (most recently version 2.1, June 2012) alongside the Common Criteria standard (ISO/IEC 15408) and the Common Evaluation Methodology (CEM, ISO/IEC 18045).

  • Minor changes to a certified product can be handled through a Maintenance Report, sometimes called an Assurance Continuity Maintenance Report (ACMR). The vendor describes the change, the lab reviews the impact, and the scheme issues an updated report. The base certificate remains valid.
  • Major changes require a re-evaluation that produces a new certificate with its own validity period.

The line between minor and major is a judgement call made by the lab and the scheme. Schemes publish their own assurance-continuity guidance with examples; vendors should consult the scheme early when planning a release that touches certified components.

What expiry means in practice

For procurement and compliance purposes the practical question is whether the cited certificate is still in an actionable state.

  • An active certificate, with current maintenance reports if applicable, is normal evidence.
  • An archived or expired certificate is generally not acceptable as active evidence. Some procurement frameworks accept archived certificates for a defined transition window, but this is the exception rather than the rule.
  • A withdrawn or suspended certificate should be treated as evidence of a problem and investigated before the product is accepted.

When a certificate is approaching expiry, vendors are expected to either initiate a re-evaluation, issue a maintenance report covering the most recent product version, or notify their customer base that the product is moving to end-of-life under that certification.

How NenkinTracker exposes validity state

NenkinTracker records the issue date, expiry date, and current status of every certificate it indexes. Users can filter the catalog by status, follow products to receive notifications when a certificate moves between states, and surface aggregate validity statistics across schemes from the expired certificates statistics page.

See also

Frequently asked questions

How long is a Common Criteria certificate valid?
There is no single global rule. Validity is set by the issuing national scheme and can also be constrained by the underlying Protection Profile. Five years is the most common nominal validity period across CCRA member schemes. Some schemes use two years for specific Protection Profile families revised on a faster cadence, and EUCC inherits similar windows with additional EU-specific maintenance rules.
What happens when a Common Criteria certificate expires?
The certificate moves to an archived (or expired) state. It remains in the public record as historical evidence but cannot be cited as active certification. Some procurement frameworks accept archived certificates for a defined transition window, but this is the exception rather than the rule. Vendors are expected to either re-evaluate, issue a maintenance report, or notify customers that the product is reaching end-of-life under that certification.
What is a maintenance report in Common Criteria?
A Maintenance Report (sometimes called an Assurance Continuity Maintenance Report or ACMR) extends a certificate's assurance to a minor change in the product or its environment without a full re-evaluation. The vendor describes the change, the lab reviews its impact, and the scheme issues an updated report. The base certificate remains active. Major changes require a re-evaluation that produces a new certificate with its own validity period.
What is the difference between archived and withdrawn?
An archived certificate has reached its nominal expiry date or been superseded by a newer evaluation; it is no longer active but the lifecycle ended normally. A withdrawn (or suspended) certificate has been removed from the active list early, at the vendor's request or by scheme action. Reasons for withdrawal include a discovered vulnerability that materially affects assurance, end-of-life of the product, or scope changes from the vendor.
Can an expired Common Criteria certificate be renewed?
Common Criteria does not have a simple renewal: the certificate either receives a maintenance report (for minor changes during the validity window) or the product is re-evaluated, which produces a new certificate with its own validity period. The line between minor and major is a judgement call by the lab and the scheme, so vendors planning a release that touches certified components should consult the scheme early.
How do I check if a Common Criteria certificate is still active?
Check the issuing scheme's registry or the Common Criteria Portal, which list the current state (active, maintenance, archived, withdrawn) for each certificate. Look for the issue date, expiry date, and any maintenance reports. An active certificate with current maintenance reports is normal evidence; an archived or withdrawn certificate generally is not. NenkinTracker also tracks status changes and can notify users when a followed certificate transitions between states.