Skip to content
Nenkin

Certification Schemes Overview

Common Criteria certifications are issued by national scheme bodies around the world. Each scheme operates its own accredited evaluation labs and issues certificates, but through the CCRA mutual recognition arrangement, these certificates are accepted internationally.

Summary: CC certificates are issued by national scheme bodies such as BSI, ANSSI, NIAP, and CCCS and recognised internationally through the CCRA.

Key facts

  • Governing arrangement: Common Criteria Recognition Arrangement (CCRA)
  • Member roles: Certificate Authorizing Participants (issue) and Certificate Consuming Participants (accept)
  • Major certificate-issuing schemes: BSI (Germany), ANSSI (France), NIAP (USA), CCCS (Canada), NSCIB (Netherlands), OCSI (Italy), CCN (Spain), JISEC (Japan), KECS (South Korea)
  • European regional arrangement: SOG-IS MRA for higher-assurance recognition; being transitioned into the EUCC
  • EU framework: EUCC under the EU Cybersecurity Act (Regulation 2019/881, Implementing Regulation (EU) 2024/482)
  • Evaluators: Accredited IT Security Evaluation Facilities (ITSEFs) / Conformity Assessment Bodies (CABs)

Major certification schemes

BSI (Germany)

The Bundesamt für Sicherheit in der Informationstechnik is one of the largest and most active CC certification bodies globally. BSI certifies a wide range of products including smart cards, hardware security modules, and operating systems. Germany is both a certificate-authorizing and certificate-consuming member of the CCRA.

ANSSI (France)

The Agence nationale de la sécurité des systèmes d’information operates France’s national CC scheme. ANSSI is particularly active in certifying products for European government and defense use. France has a strong tradition in formal methods and higher EAL evaluations.

NIAP (USA)

The National Information Assurance Partnership manages the U.S. CC scheme. NIAP has shifted toward Protection Profile-based evaluations, requiring products to conform to specific PPs rather than arbitrary EAL targets. This approach focuses evaluations on threat-relevant security requirements for each product category.

CCCS (Canada)

The Canadian Centre for Cyber Security operates Canada’s CC scheme. Like NIAP, CCCS emphasizes PP-conformance evaluations and participates actively in international PP development.

Other schemes

Additional CC schemes include:

  • OCSI (Italy)
  • CCN (Spain)
  • NSCIB (Netherlands)
  • JISEC (Japan)
  • ASD (Australia)
  • KECS (South Korea)

EUCC: The EU Cybersecurity Certification Scheme

The European Common Criteria-based Cybersecurity Certification Scheme (EUCC) is a voluntary EU-wide scheme adopted under the EU Cybersecurity Act (Regulation (EU) 2019/881) via Commission Implementing Regulation (EU) 2024/482 (31 January 2024), with subsequent amendments including Regulation (EU) 2024/3144. It builds on Common Criteria and aims to create a unified European certification process, reducing fragmentation across national schemes within the EU.

EUCC defines two assurance levels: substantial (corresponding to AVA_VAN.1 or AVA_VAN.2) and high (corresponding to AVA_VAN.3, AVA_VAN.4, or AVA_VAN.5). It is administered by ENISA in cooperation with the European Cybersecurity Certification Group, with national cybersecurity certification authorities operating it within each EU member state.

Tracking certifications across schemes

With certifications issued by dozens of national bodies, keeping track of certificate status, new issuances, and expirations across schemes is a significant operational challenge. NenkinTracker aggregates data from these sources into a unified view, enabling teams to monitor the full CC certification landscape from one platform.

See also

Frequently asked questions

What is a Common Criteria certification scheme?
A certification scheme is the national body that operates Common Criteria evaluations within a country: it accredits evaluation laboratories, oversees the evaluation process, and issues the actual certificates. Examples include BSI in Germany, ANSSI in France, NIAP in the United States, and CCCS in Canada. Each scheme runs independently but evaluates against the same ISO/IEC 15408 standard.
Which countries have a Common Criteria scheme?
Major certificate-issuing schemes include BSI (Germany), ANSSI (France), NIAP (USA), CCCS (Canada), NSCIB (Netherlands), OCSI (Italy), CCN (Spain), JISEC (Japan), KECS (South Korea), and ASD (Australia). The CCRA has 36 member nations in total: 18 Certificate Authorizing Participants that issue certificates and 18 Certificate Consuming Participants that recognise them.
What is the difference between authorizing and consuming members?
Certificate Authorizing Participants (CAPs) operate their own scheme, accredit evaluation laboratories, and issue Common Criteria certificates. Certificate Consuming Participants (CCPs) do not issue their own certificates but formally recognise certificates issued by authorising members. The distinction matters in procurement: only authorising-member schemes can produce a CC certificate, but consuming members accept those certificates without re-evaluation.
Does NIAP do EAL-based evaluations?
No. Since 2014, NIAP has required every evaluation to conform to an approved Protection Profile rather than targeting an arbitrary EAL. The PP determines the assurance activities, so a NIAP certificate cites the relevant PP rather than an EAL number. This is a deliberate move to focus evaluations on threat-relevant security requirements for each product category instead of a one-size-fits-all assurance ladder.
What is SOG-IS and how does it relate to EUCC?
SOG-IS (Senior Officials Group Information Systems Security) operated a European mutual-recognition arrangement for higher-assurance Common Criteria evaluations, particularly for smart cards and secure microcontrollers above the CCRA EAL2 baseline. It is being transitioned into the EUCC, the EU's voluntary cybersecurity certification scheme adopted under the EU Cybersecurity Act (Regulation (EU) 2019/881) via Implementing Regulation (EU) 2024/482. SOG-IS stops issuing certificates from 27 February 2026.
What is an ITSEF or CAB?
An ITSEF (IT Security Evaluation Facility) is the accredited laboratory that performs the technical evaluation of a product under a Common Criteria scheme. Under EUCC the equivalent term is CAB (Conformity Assessment Body). The ITSEF or CAB does the testing, document review, and vulnerability analysis; the national scheme then reviews the lab's evaluation technical report and issues the certificate.