EAL2: Structurally Tested
EAL2 is the most common Common Criteria assurance level globally. It adds a high-level design review and independent vulnerability analysis beyond the surface-level checks of EAL1, and it is the cap for CCRA mutual recognition of non-cPP evaluations.
Explore NenkinTracker to find certified products and compare their assurance levels, including EAL2.
Key facts
- Assurance families covered: ADV_ARC.1, ADV_FSP.2, ADV_TDS.1, AGD_OPE.1 / AGD_PRE.1, ALC_CMC.2 / ALC_CMS.2, ALC_DEL.1, ATE_COV.1, ATE_FUN.1, ATE_IND.2, AVA_VAN.2.
- Typical product categories: commercial software, enterprise hardware, products sold to CCRA-member governments under mutual recognition.
- Relative cost/time: moderate; typical timelines are several months of evaluation effort plus developer preparation.
- Attack potential resisted: Basic attacker.
What this level tests
Evaluators review a security architecture description, a functional specification, and a basic TOE design. Developer testing must document coverage and pass independent reproduction (ATE_IND.2). AVA_VAN.2 requires evaluators to perform their own penetration testing against identified vulnerabilities, not merely survey public reports.
Configuration management now requires authorization controls over the TOE (ALC_CMC.2) and coverage of the TOE itself plus parts of the development environment (ALC_CMS.2). A documented delivery procedure (ALC_DEL.1) is required.
Typical product categories
EAL2 is the de-facto baseline for commercial CC certifications: network management software, enterprise applications, database components, identity products, mobile applications, and many virtualization and hypervisor products. It is the common target for vendors who need a CCRA-recognized certificate without committing to a cPP-based evaluation.
Common misconceptions
EAL is an assurance level, not a security-strength rating. An EAL2 certificate means the evaluator reviewed a high-level design and performed Basic-potential vulnerability analysis. It does not mean the product is “twice as secure” as EAL1 or “half as secure” as EAL4. The product’s real security depends on its design, its operational environment, and how precisely its Security Target captures the deployment’s threats.
Comparison to adjacent levels
- vs. EAL1: EAL2 adds architecture and basic design review (ADV_ARC.1, ADV_TDS.1), stronger CM and delivery requirements, and AVA_VAN.2 evaluator-driven vulnerability analysis.
- vs. EAL3: EAL3 adds development environment security (ALC_DVS.1) and a documented life-cycle model (ALC_LCD.1), upgrades the design (ADV_TDS.2 architectural design, ADV_FSP.3) and CM (ALC_CMC.3, ALC_CMS.3), and introduces test-coverage analysis (ATE_COV.2) and design-level testing depth (ATE_DPT.1).
See the EAL Levels overview, Protection Profiles for PP-based alternatives, and the glossary for SAR vocabulary.
Frequently asked questions
What is EAL2?
EAL2 is a Common Criteria Evaluation Assurance Level (ISO/IEC 15408-3) that adds a high-level design review and evaluator-driven vulnerability analysis on top of EAL1's functional testing. Evaluators examine a security architecture description, basic TOE design, configuration management, and delivery procedures. AVA_VAN.2 requires the lab to perform its own penetration testing against identified vulnerabilities. Attack potential resisted is Basic.
Why is EAL2 the most common assurance level?
EAL2 is the practical sweet spot for commercial products. It is the cap for automatic CCRA mutual recognition outside collaborative Protection Profiles, so an EAL2 certificate is recognised across all CCRA member states without additional negotiation. It also keeps cost and timeline moderate compared to EAL3 and above, making it the de-facto baseline for commercial software, enterprise hardware, and products sold into multiple government markets.
What product categories typically target EAL2?
Network management software, enterprise applications, database components, identity products, mobile applications, and many virtualization and hypervisor products. EAL2 is the common target for vendors who need a CCRA-recognized certificate without committing to a Protection Profile based evaluation. Smart cards and HSMs typically aim higher, but most general-purpose IT and network products that pursue CC certification stop at EAL2.
How does EAL2 differ from EAL3?
EAL3 adds development-environment security controls (ALC_DVS.1), a documented life-cycle model (ALC_LCD.1), broader configuration management coverage (ALC_CMC.3 and ALC_CMS.3), an architectural design description (ADV_TDS.2, up from ADV_TDS.1), a more detailed functional specification (ADV_FSP.3), test-coverage analysis (ATE_COV.2), and testing against the design rather than only external interfaces (ATE_DPT.1). The attacker model stays at Basic potential because vulnerability analysis remains AVA_VAN.2. Most of the EAL3 increment is about the developer's process and design visibility, not the product itself.
Is EAL2 recognised internationally under CCRA?
Yes. The 2014 CCRA revision provides automatic mutual recognition for evaluations up to and including EAL2 across all member states, regardless of whether the evaluation uses a Protection Profile. Above EAL2, mutual recognition requires conformance to a collaborative Protection Profile (cPP). This is the structural reason EAL2 is the workhorse level for vendors selling internationally.
Is EAL2 enough for commercial products?
For most commercial IT products handling non-classified data in low-to-moderate-risk environments, EAL2 provides meaningful third-party assurance and is the most frequently targeted level globally. Products with higher threat models, such as smart cards, HSMs, or government-grade OS kernels, typically need EAL4+ or evaluation against a specific Protection Profile. Always work back from threat model and regulatory requirements rather than defaulting to a number.