Skip to content
Nenkin

Common Criteria Overview: ISO/IEC 15408 Explained

Common Criteria (CC) is the international standard for evaluating the security of IT products, formally published as ISO/IEC 15408. It provides a framework for specifying security requirements and evaluating whether products meet those requirements through independent testing by accredited laboratories.

Summary: Common Criteria (ISO/IEC 15408) is the international standard for IT security evaluation, with certificates mutually recognised across 36 CCRA nations.

Key facts

  • Formal name: Common Criteria for Information Technology Security Evaluation (ISO/IEC 15408)
  • Standard parts (CC:2022): Part 1 (introduction and model), Part 2 (functional components), Part 3 (assurance components), Part 4 (framework for evaluation methods and activities), Part 5 (pre-defined packages of security requirements)
  • Companion methodology: Common Evaluation Methodology (ISO/IEC 18045, CEM)
  • Assurance scale: EAL1 (functionally tested) through EAL7 (formally verified)
  • Mutual recognition: Common Criteria Recognition Arrangement (CCRA), 36 member nations (18 Authorizing, 18 Consuming)
  • Key artefacts: Security Target (ST), Protection Profile (PP), Target of Evaluation (TOE), Certification Report

How Common Criteria works

Under CC, products are tested by accredited evaluation labs against defined security requirements called Security Targets. These Security Targets optionally conform to Protection Profiles, which are standardized sets of requirements for a product category (e.g., smart cards, firewalls, operating systems).

Evaluations are performed at one of seven Evaluation Assurance Levels (EAL1 through EAL7), and successful products receive certificates from national scheme bodies.

Key concepts

  • Security Target (ST): A document describing the security properties and requirements of the product being evaluated
  • Protection Profile (PP): A template of security requirements for a category of products, independent of any specific implementation
  • Evaluation Assurance Level (EAL): A numerical grade (1-7) indicating the depth and rigor of the evaluation
  • Target of Evaluation (TOE): The product or system being evaluated

National certification schemes

CC evaluations are conducted by accredited labs (called ITSEFs, IT Security Evaluation Facilities) and certificates are issued by national scheme bodies, including:

  • BSI (Germany): Bundesamt für Sicherheit in der Informationstechnik
  • ANSSI (France): Agence nationale de la sécurité des systèmes d’information
  • NIAP (USA): National Information Assurance Partnership
  • CCCS (Canada): Canadian Centre for Cyber Security
  • OCSI (Italy): Organismo di Certificazione della Sicurezza Informatica

Mutual recognition (CCRA)

Through the Common Criteria Recognition Arrangement (CCRA), certificates are mutually recognized across 36 member nations (18 Certificate Authorizing and 18 Certificate Consuming as of the most recent CCRA membership list). This means a product certified by an authorizing member is accepted by other CCRA members within the recognition limits set by the 2014 CCRA revision, avoiding the need for duplicate evaluations.

Why CC matters

Common Criteria certification is often required for products used in government, defense, and regulated industries. It provides an independent, standardized assessment of a product’s security claims, giving procurement teams and compliance officers a basis for trust.

See also

Frequently asked questions

What is Common Criteria?
Common Criteria is the international standard for evaluating the security of IT products, formally published as ISO/IEC 15408. Accredited evaluation laboratories test products against defined security requirements documented in a Security Target, and national scheme bodies issue certificates for products that pass. The standard covers hardware, software, and combined products across categories such as smart cards, firewalls, and operating systems.
What does ISO/IEC 15408 cover?
ISO/IEC 15408:2022 has five parts. Part 1 introduces the model and core concepts. Part 2 catalogues security functional components used to write Security Functional Requirements. Part 3 catalogues security assurance components. Part 4 specifies a framework for defining evaluation methods and activities. Part 5 contains pre-defined packages of security requirements, including the Evaluation Assurance Levels EAL1 through EAL7. The companion methodology, ISO/IEC 18045 (Common Evaluation Methodology), tells evaluators how to apply the assurance components in practice.
Who issues Common Criteria certificates?
Common Criteria certificates are issued by national scheme bodies, not a single global authority. The largest issuers include BSI in Germany, ANSSI in France, NIAP in the United States, CCCS in Canada, OCSI in Italy, NSCIB in the Netherlands, CCN in Spain, JISEC in Japan, and KECS in South Korea. Each scheme accredits its own evaluation laboratories (ITSEFs) that perform the technical testing.
Is a Common Criteria certificate recognised internationally?
Yes, within limits. The Common Criteria Recognition Arrangement (CCRA) has 36 member nations (18 Certificate Authorizing and 18 Certificate Consuming) and makes certificates issued by one member acceptable in the others. Under the 2014 CCRA revision, recognition covers EAL1 to EAL2 (plus ALC_FLR) for general evaluations, with higher assurance levels recognised only when the evaluation conforms to a collaborative Protection Profile. Inside the EU, EUCC adds a parallel regulatory recognition path.
What does TOE mean in Common Criteria?
TOE stands for Target of Evaluation. It is the specific part of the product that the certificate covers, defined in the Security Target. The TOE is rarely the entire shipping product: it usually excludes operational environment components such as the host operating system, network infrastructure, or external authentication services. Anything outside the TOE boundary is not guaranteed by the certificate.
Why is Common Criteria certification important?
Common Criteria certification is often required for products sold to government, defence, and regulated industries. It provides an independent, standardised assessment of a product's security claims, evaluated by accredited third parties against ISO/IEC 15408. For procurement teams and compliance officers, a CC certificate is a documented basis for trust that the product behaves as the vendor claims under the stated assumptions.