Skip to content
Nenkin

Beyond Common Criteria: SESIP, PSA, ESA, EMVCo, and MIFARE

Common Criteria is the most widely-recognised security certification framework, but it is not the only one. Several adjacent or sector-specific schemes operate in parallel, particularly in IoT, payment, and chip-platform contexts. NenkinTracker monitors five of these alongside its CC coverage. This entry summarises each one, what it certifies, who runs it, and how it relates to the CC ecosystem.

Summary: SESIP, PSA Certified, ESA, EMVCo, and MIFARE are non-CC certification schemes covering IoT platforms, ARM-based devices, eUICCs and remote SIM provisioning components, payment terminals, and NXP smart card platforms. Some borrow CC methodology; others are independent.

Why the non-CC schemes matter

Common Criteria’s strengths (high-assurance, internationally recognised, formal methodology) are also its constraints. CC evaluations are expensive and slow, which makes them a poor fit for high-volume, fast-moving product categories like IoT sensors or microcontroller platforms. The schemes below filled that gap, in different ways:

  • SESIP is a CC-derived methodology adapted for IoT-scale economics
  • PSA Certified is a vendor-driven scheme aimed at Arm-based device platforms
  • ESA is GSMA’s eUICC Security Assurance scheme for eSIMs and remote SIM provisioning
  • EMVCo is the payment industry’s own certification regime
  • MIFARE certifications come from NXP’s smart card platform program

SESIP (Security Evaluation Standard for IoT Platforms)

What it is: A standardised evaluation methodology for IoT platform components such as microcontrollers, secure elements, and trusted execution environments. SESIP defines five assurance levels (SESIP1 through SESIP5), with SESIP3 broadly comparable to CC’s AVA_VAN.3 and SESIP5 to AVA_VAN.5.

Who runs it: Published by GlobalPlatform; evaluations are performed by accredited security labs, many of which also operate as CC evaluation facilities.

What it certifies: Connected-device platforms and components, with a focus on reusability: a SESIP-certified IoT platform can be re-used as the assurance basis for a higher-level product certification (SESIP-to-EUCC composition, for example).

Catalog scale: As of May 2026, NenkinTracker indexes 91 SESIP certifications covering 84 products from 30 distinct vendors.

Relation to CC: Methodologically derivative of CC, with simplified evaluator workload to support IoT economics. The European Union has formally recognised SESIP within the EUCC framework as a basis for certain composition scenarios.

PSA Certified

What it is: A security certification programme for connected-device silicon that evaluates the Root of Trust in IoT products. Originally developed by Arm with SGS Brightsight, CAICT, Riscure Keysight, UL, Prove & Run, and TrustCB, the scheme was donated to GlobalPlatform in September 2025 and is now maintained there.

Who runs it: GlobalPlatform (since September 2025). TrustCB acts as the independent certification body that issues the certificates; accredited evaluation laboratories perform Level 2 and above testing.

What it certifies: Hardware roots of trust, secure microcontroller platforms, and the firmware components that bind them. PSA Certified defines four assurance levels: Level 1 (questionnaire-based, vendor self-attestation), Level 2 (lab-evaluated, software-attack resistance of the PSA Root of Trust), Level 3 (lab-evaluated, substantial hardware and software attack resistance), and Level 4 iSE/SE (integrated or external Secure Element architecture, evaluated against SESIP). Levels 2 and 3 also have +Secure Element variants for additional physical protection of cryptographic keys.

Catalog scale: 267 certifications across 260 products and 112 vendors. The largest non-CC scheme NenkinTracker tracks.

Relation to CC: PSA Certified Level 4 explicitly adopts SESIP, which inherits Common Criteria methodology. The lower levels share threat-modelling and attack-potential concepts with CC. In practice many products certified under PSA Certified also pursue CC or EUCC certification at the platform level. The schemes are complementary rather than competing.

ESA

What it is: GSMA’s eUICC Security Assurance (eSA) scheme, the industry security certification programme for embedded UICC (eUICC) products. NenkinTracker carries it as “ESA” in the data model; GSMA and TrustCB write it as “eSA”.

Who runs it: Governed by GSMA (Global System for Mobile Communications Association); GSMA has selected TrustCB as the eSA Certification Body.

What it certifies: eUICC products (the embedded SIM chips and platforms in phones, watches, tablets, automotive units, and IoT devices). The scheme covers M2M eUICCs (against the SGP.05 Protection Profile, designed for the SGP.01 architecture) and Consumer or IoT-device eUICCs (against the SGP.25 Protection Profile, designed for the SGP.21 architecture). The methodology is Common Criteria plus CEM with eUICC-specific optimisations from GSMA SGP.07; scheme requirements are specified in GSMA SGP.06.

Catalog scale: 58 certifications across 48 products and 13 vendors.

Relation to CC: eSA is built on Common Criteria. The framework is CC plus CEM with eUICC-specific optimisations layered on through SGP.07, and the Protection Profiles (SGP.05 and SGP.25) are written in the standard CC format. The practical difference from a CCRA-issued certificate is governance: eSA is industry-governed by GSMA and is not part of the CCRA mutual-recognition arrangement.

EMVCo

What it is: The certification regime operated by EMVCo, the consortium that owns the EMV payment specifications. EMVCo certifications fall into two broad categories: functional (does the product implement the EMV protocols correctly?) and security (does it resist relevant attacks at the chip and terminal level?).

Who runs it: EMVCo is jointly owned by American Express, Discover, JCB, Mastercard, UnionPay, and Visa.

What it certifies: Payment cards (chip and contactless), payment terminals, mobile payment SDKs, and related components. Security evaluations rely on accredited laboratories and a documented attack methodology specific to the payment domain.

Catalog scale: NenkinTracker monitors EMVCo’s certificate registry but, as of May 2026, has zero indexed entries. The collector is in place; the data has not yet been ingested.

Relation to CC: Distinct framework with its own attack methodology, but the same underlying secure elements often hold CC certifications as well. A payment card might be issued under EMVCo (as a finished product) while its underlying chip holds a CCRA EAL5+ certification.

MIFARE

What it is: Certifications associated with NXP’s MIFARE smart card platform family. MIFARE is itself a product line (cards, tags, readers); the certifications cover specific products and platform variants under various assurance regimes.

Who issues them: NXP and the labs evaluating MIFARE-based products.

What it certifies: MIFARE Classic, MIFARE DESFire, MIFARE Plus, MIFARE Ultralight family products and related chips deployed in transit, access control, and identification applications.

Catalog scale: 111 certifications across 97 products from 6 distinct vendors.

Relation to CC: Many MIFARE products also hold CC certifications. The MIFARE designation is more of a product-platform identifier than a parallel certification scheme; it is included in NenkinTracker’s coverage because the MIFARE line is operationally significant in real procurement decisions.

How these schemes interact with CC

A single secure-element product can carry multiple certifications: a CCRA EAL5+ for the chip, a SESIP certification for the platform built on top, a PSA Level 3 for the platform’s role in an Arm device, and an EMVCo security certification if it ships in a payment card. These are layered, not competing.

For procurement and compliance teams, the practical implication is that CC alone is rarely a complete picture. Knowing which non-CC schemes also certify a given product class lets you ask sharper questions about what assurance you actually have.

Tracking the full landscape

NenkinTracker indexes all five schemes alongside CCRA and EUCC, presenting them in a unified product and vendor view. Where the same physical product holds certifications under multiple schemes, the catalogue links them via shared product or vendor records.

See also

Frequently asked questions

What is SESIP certification?
SESIP (Security Evaluation Standard for IoT Platforms) is a standardised evaluation methodology for IoT platform components such as microcontrollers, secure elements, and trusted execution environments. It defines five assurance levels, SESIP1 through SESIP5, with SESIP3 broadly comparable to Common Criteria AVA_VAN.3 and SESIP5 to AVA_VAN.5. SESIP is published by GlobalPlatform and is formally recognised within the EUCC framework.
What is PSA Certified?
PSA Certified is a security certification programme for connected-device silicon that evaluates the Root of Trust in Internet-of-Things products. Originally developed by Arm with SGS Brightsight, CAICT, Riscure Keysight, UL, Prove & Run, and TrustCB, the scheme was donated to GlobalPlatform in September 2025 and is now maintained there. It defines four assurance levels: Level 1 (questionnaire-based), Levels 2 and 3 (lab-evaluated against software and hardware attack potential), and Level 4 iSE/SE (Secure Element architecture, based on SESIP).
Is SESIP the same as Common Criteria?
No, but they are related. SESIP is methodologically derivative of Common Criteria, with simplified evaluator workload designed to support IoT economics where full CC evaluations would be too slow and expensive. SESIP assurance levels map roughly to CC AVA_VAN levels, and a SESIP-certified platform can be reused as the assurance basis for a higher-level certification, including SESIP-to- EUCC composition.
What does EMVCo certify?
EMVCo certifies products against the EMV payment specifications. Certifications fall into two categories: functional (does the product implement the EMV protocols correctly) and security (does it resist relevant attacks at the chip and terminal level). Covered products include payment cards (chip and contactless), payment terminals, mobile payment SDKs, and related components. EMVCo is jointly owned by American Express, Discover, JCB, Mastercard, UnionPay, and Visa.
Can a single product hold multiple certifications?
Yes, and many do. A single secure-element product can carry a CCRA EAL5+ certificate for the chip, a SESIP certification for the platform built on top, a PSA Level 3 for the platform's role in an Arm device, and an EMVCo security certification if it ships in a payment card. These certifications are layered rather than competing, each addressing a different assurance question for a different audience.
What is the ESA scheme?
ESA, written by GSMA as eSA, is GSMA's eUICC Security Assurance scheme: the industry certification programme for embedded UICC (eUICC) products. It is governed by GSMA and certificates are issued by TrustCB. The methodology is Common Criteria plus CEM with eUICC-specific optimisations defined in GSMA SGP.06 and SGP.07; Protection Profiles are SGP.05 (M2M) and SGP.25 (Consumer and IoT). eSA is not part of CCRA mutual recognition.