Skip to content
Nenkin

EAL4: Methodically Designed, Tested, and Reviewed

EAL4 is widely regarded as the highest Common Criteria assurance level that can be achieved on commercially engineered products without designing specifically for evaluation. It adds source-code-level review, life-cycle tool controls, and Enhanced-Basic vulnerability analysis with access to design.

Explore NenkinTracker to find certified products and compare their assurance levels, including EAL4.

Key facts

  • Assurance families covered: adds ADV_FSP.4 (complete functional specification), ADV_IMP.1 (implementation representation, a subset), ADV_TDS.3 (basic modular design), ALC_CMC.4 (production support, acceptance procedures, automation), ALC_CMS.4 (problem tracking CM coverage), ALC_TAT.1 (well-defined development tools), and AVA_VAN.3 (focused vulnerability analysis at Enhanced-Basic) over EAL3. ALC_DVS.1, ALC_LCD.1, ATE_DPT.1, ATE_FUN.1, and ATE_IND.2 carry over from EAL3.
  • Typical product categories: smart cards and secure ICs (often EAL4+ with AVA_VAN.5), HSMs, certified operating systems, virtualization platforms, payment and identity products.
  • Relative cost/time: substantial; source-code review and developer-tool discipline are significant investments.
  • Attack potential resisted: Enhanced-Basic (EAL4 baseline); Moderate or High in common augmentations (EAL4+ with AVA_VAN.4 or AVA_VAN.5).

What this level tests

Evaluators review a subset of the implementation representation (ADV_IMP.1), in practice, source code for security-relevant modules. The TOE design must be presented at a modular level (ADV_TDS.3). Life-cycle rigor includes tool and technique controls (ALC_TAT.1) and automated configuration management (ALC_CMC.4). AVA_VAN.3 allows the evaluator to use design knowledge when crafting attacks.

Typical product categories

EAL4 is the common target for high-assurance commercial products. Smart card ICs and embedded secure elements are typically evaluated at EAL4 augmented with AVA_VAN.5 (EAL4+) because their deployment threat model requires High attack potential resistance. HSMs, certified operating systems, and certain network and storage products are likewise frequently evaluated at EAL4+ with augmentations aligned to their Protection Profile.

Common misconceptions

EAL is an assurance level, not a security-strength rating. An EAL4 certificate describes how rigorously the evaluator examined the product. It does not declare that the product will resist every threat, only the threats defined in the Security Target, analyzed to the Enhanced-Basic attack potential that AVA_VAN.3 prescribes.

EAL4+ is not a single thing. “EAL4+” is shorthand for EAL4 augmented with one or more specific assurance components. The meaningful question is which components. An EAL4+ certificate augmented with ALC_FLR.2 is very different from one augmented with AVA_VAN.5: the former adds process for flaw handling; the latter increases vulnerability-analysis attacker potential from Enhanced-Basic to High. We unpack why this matters for procurement in EAL4 and EAL4+ Are Not the Same.

Comparison to adjacent levels

  • vs. EAL3: EAL4 introduces source-level review, more automated CM, and AVA_VAN.3 design-aware vulnerability analysis.
  • vs. EAL5: EAL5 requires semiformal design notation (ADV_FSP.5, ADV_TDS.4), well-structured internals (ADV_INT.2), and AVA_VAN.4 at Moderate attack potential, with substantially more evaluation effort. Implementation-representation review stays at ADV_IMP.1 (the EAL6 step is to ADV_IMP.2). Few products outside smart cards and high-assurance OS kernels reach EAL5.

See the EAL Levels overview and the glossary.

Frequently asked questions

What is EAL4?
EAL4 is a Common Criteria Evaluation Assurance Level (ISO/IEC 15408-3) widely regarded as the highest level generally achievable on commercially engineered products without re-engineering specifically for assurance. It adds source-code-level review (ADV_IMP.1), modular design documentation (ADV_TDS.3), automated configuration management (ALC_CMC.4), tool controls (ALC_TAT.1), and AVA_VAN.3 vulnerability analysis at Enhanced-Basic attack potential.
Does EAL4 require source-code review?
Yes. EAL4 is the first level at which evaluators must inspect the implementation representation, in practice meaning source code for security-relevant modules (ADV_IMP.1). Evaluators check that the source matches the modular TOE design, supports the security functional requirements, and is consistent with the architecture description. For hardware TOEs, the equivalent is review of design data such as RTL or schematics.
What does EAL4+ mean?
EAL4+ is shorthand for an EAL4 evaluation augmented with one or more specific assurance components. The plus sign hides which components were added, so two products both labelled EAL4+ can differ substantially. Common augmentations are AVA_VAN.5 (raises attack potential from Enhanced-Basic to High), ALC_DVS.2 (stronger development security), and ALC_FLR.2 or ALC_FLR.3 (flaw remediation procedures). Always check the Security Target for the exact components.
What product categories typically target EAL4?
Smart cards and secure ICs (usually as EAL4+ with AVA_VAN.5 to reach High attack potential), hardware security modules, certified operating systems, virtualization and separation platforms, and identity and payment products. Many national defence and government procurement programmes specify EAL4 or EAL4+ as the floor. It is the standard target for vendors building genuinely high-assurance commercial products.
How does EAL4 differ from EAL5?
EAL5 keeps the same implementation-representation component as EAL4 (ADV_IMP.1) but adds a semiformal functional specification (ADV_FSP.5), semiformal modular design (ADV_TDS.4), well-structured internals (ADV_INT.2), development-tools CM coverage (ALC_CMS.5), tighter implementation-standards compliance (ALC_TAT.2), deeper testing (ATE_DPT.3), and AVA_VAN.4 vulnerability analysis at Moderate attack potential. EAL5 also typically requires designing for assurance from the outset rather than retrofitting, which is why few products outside smart cards and high-assurance separation kernels reach it.
Is EAL4 recognised internationally under CCRA?
Only via collaborative Protection Profiles. CCRA mutual recognition for non-cPP evaluations caps at EAL2 plus ALC_FLR augmentation. EAL4 certificates issued under bilateral arrangements or individual schemes are valid within those schemes, and EU recognition for high-assurance products is now handled under EUCC. For automatic international recognition above EAL2, conformance to a collaborative Protection Profile is the established route.