EAL5: Semiformally Designed and Tested
EAL5 is a Common Criteria assurance level for products designed with assurance in mind from the outset. It introduces semiformal design notation, raises the test depth to the modular design, and mandates covert channel analysis for TOEs enforcing information-flow policies.
Explore NenkinTracker to find certified products and compare their assurance levels, including EAL5.
Key facts
- Assurance families covered: adds ADV_FSP.5 (complete semi-formal functional specification with additional error information), ADV_INT.2 (well-structured internals), ADV_TDS.4 (semiformal modular design), ALC_CMS.5 (development tools CM coverage), ALC_TAT.2 (compliance with implementation standards), ATE_DPT.3 (testing: modular design), and AVA_VAN.4 (methodical vulnerability analysis at Moderate) over EAL4. ADV_IMP.1, ALC_CMC.4, ALC_DVS.1, and ALC_LCD.1 carry over from EAL4. ADV_IMP.2 (complete mapping) is an EAL6 increment, not an EAL5 one.
- Typical product categories: smart card integrated circuits, smart card operating systems, high-assurance separation kernels, certain hypervisors.
- Relative cost/time: high; requires assurance-oriented design, semiformal specifications, and extensive documentation beyond commercial engineering norms.
- Attack potential resisted: Moderate (EAL5 baseline); High when augmented with AVA_VAN.5 (EAL5+).
What this level tests
Evaluators review a subset of the implementation representation (ADV_IMP.1, the same component that applies at EAL4); the step to complete mapping (ADV_IMP.2) does not occur until EAL6. The functional specification and TOE design must be presented in semiformal notation (ADV_FSP.5, ADV_TDS.4), with internal structure shown to be well-structured (ADV_INT.2). Testing depth reaches the modular description (ATE_DPT.3). AVA_VAN.4 raises vulnerability analysis to Moderate attack potential.
Covert channel analysis becomes relevant at EAL5 for TOEs that enforce information-flow policies, since evaluators expect the developer to identify and assess channels that could bypass the stated flow controls.
Typical product categories
EAL5 is strongly concentrated in smart card ICs and associated operating systems, where certification ecosystems under SOG-IS (and now EUCC) historically demanded high assurance combined with High attack potential (EAL5+ with AVA_VAN.5). High-assurance separation kernels used in defense and aerospace are another category where EAL5 or EAL5+ evaluations appear.
Common misconceptions
EAL is an assurance level, not a security-strength rating. EAL5 means the TOE was designed and documented in a way that makes deeper evaluator review tractable. It does not mean EAL5 products are invulnerable. Even at EAL5+/AVA_VAN.5, the evaluator analyzes against High attack potential, not unlimited resources.
“Semiformal” is not the same as formal. EAL5 requires a semiformal notation: structured and precise but not necessarily mathematically provable. Only EAL6 and EAL7 introduce formal verification components.
Comparison to adjacent levels
- vs. EAL4: EAL5 adds semiformal functional specification (ADV_FSP.5), semiformal modular design (ADV_TDS.4), well-structured internals (ADV_INT.2), broader CM coverage (ALC_CMS.5), tighter implementation-standards compliance (ALC_TAT.2), and AVA_VAN.4 at Moderate attack potential. ADV_IMP.1 is unchanged.
- vs. EAL6: EAL6 promotes implementation-representation review to ADV_IMP.2 (complete mapping), adds a formal security policy model (ADV_SPM.1), layered internals (ADV_INT.3), AVA_VAN.5 at High attack potential, and stronger development-environment controls (ALC_DVS.2, ALC_CMC.5, ALC_TAT.3).
See the EAL Levels overview and the glossary for SAR vocabulary.