Skip to content
Nenkin

Protection Profiles (PP)

A Protection Profile (PP) is a standardized set of security requirements for a category of IT products. It defines what a product must do to be considered secure for a specific use case, independent of any particular vendor’s implementation.

Summary: A Protection Profile is a vendor-independent security requirements template for a product category; Security Targets claim conformance to it.

Key facts

  • Role: Vendor-independent security requirements for a product category
  • Relationship to ST: A Security Target may claim conformance to one or more PPs
  • Main types: Collaborative Protection Profiles (cPPs), national PPs, industry PPs
  • cPP governance: Developed by international Technical Communities (iTCs) under the CCRA
  • NIAP requirement: Since 2014, NIAP evaluations must conform to an approved PP
  • Typical categories: Network devices, operating systems, application software, full disk encryption, smart cards, HSMs

How Protection Profiles work

In a Common Criteria evaluation, the vendor writes a Security Target (ST) describing their product’s security claims. If a Protection Profile exists for the product category, the vendor can claim PP conformance: meaning their ST meets all the requirements defined in the PP.

This standardization is valuable because:

  • Procurement teams can require PP conformance instead of writing their own security requirements
  • Vendors know exactly what to build and test against
  • Evaluators have a consistent baseline for each product type
  • Comparisons between certified products in the same category become meaningful

Types of Protection Profiles

Collaborative Protection Profiles (cPP)

Developed by international Technical Communities (iTCs) under the CCRA. cPPs represent consensus requirements from multiple nations and are the preferred form for CCRA mutual recognition. Examples include cPPs for network devices, full disk encryption, and dedicated security components.

National Protection Profiles

Developed by individual national schemes for their specific requirements. NIAP maintains a large library of PPs for US government procurement. ANSSI publishes PPs for French government requirements.

Industry Protection Profiles

Developed by industry bodies for specific sectors. For example, payment industry PPs for point-of-sale terminals or smart card PPs developed by organizations like GlobalPlatform or EMVCo.

NIAP and PP-based evaluations

Since 2014, NIAP (the US CC scheme) requires all evaluations to conform to an approved Protection Profile. NIAP does not accept standalone EAL-based evaluations. This approach focuses evaluations on threat-relevant security requirements rather than arbitrary assurance levels.

NIAP’s PP library covers major product categories including:

  • Network devices (firewalls, VPN gateways, routers, switches)
  • Operating systems (general-purpose, mobile)
  • Application software
  • Virtualization and VDI
  • Full disk encryption
  • Multi-function devices (printers)
  • Enterprise mobility management

PP conformance in procurement

When writing procurement requirements, specifying PP conformance is more precise than specifying an EAL level alone:

  • A PP defines what security functions the product must implement
  • An EAL level defines how rigorously those functions were tested
  • Together, they provide both functional and assurance guarantees

For example, requiring “CC certification conformant to the NDcPP (Network Device collaborative Protection Profile) at EAL2” is more meaningful than simply “CC EAL2 certified” because the PP ensures the product was tested against specific network security requirements.

Tracking PP conformance

NenkinTracker tracks Protection Profile conformance alongside all other certification metadata. See which products conform to which PPs across all CCRA member schemes. Explore the tracker to review certification records and their Protection Profile claims.

See also

Frequently asked questions

What is a Protection Profile?
A Protection Profile (PP) is a standardised, vendor- independent set of security requirements for a category of IT products. It defines what a product must do to be considered secure for a specific use case, regardless of who builds it. Common categories with PPs include network devices, operating systems, application software, full disk encryption, smart cards, and hardware security modules.
How do Protection Profiles relate to Security Targets?
The Protection Profile is the template; the Security Target is the product-specific document. When a vendor evaluates a product, they write a Security Target that may claim conformance to one or more Protection Profiles. Claiming PP conformance means the ST meets every requirement defined in the PP, which lets evaluators and procurement teams compare products in the same category on a consistent baseline.
What is a collaborative Protection Profile (cPP)?
A collaborative Protection Profile is a PP developed by an international Technical Community (iTC) under the CCRA. cPPs represent consensus requirements from multiple nations and are the preferred form for CCRA mutual recognition: under the 2014 CCRA revision, recognition above EAL2 generally requires conformance to a cPP. Examples include cPPs for network devices, full disk encryption, and dedicated security components.
Are Protection Profiles required for NIAP certification?
Yes. Since 2014, NIAP requires every evaluation to conform to an approved Protection Profile. NIAP no longer accepts standalone EAL-based evaluations. The PP determines the assurance activities, so the EAL is effectively a consequence of the PP rather than a free vendor choice. NIAP maintains a large library of PPs covering network devices, operating systems, application software, virtualization, full disk encryption, and more.
Should procurement specify an EAL or PP conformance?
Specify PP conformance when one applies. A Protection Profile defines what security functions the product must implement; an EAL only defines how rigorously those functions were tested. Together they cover both functional and assurance dimensions. Requiring "CC certified conformant to NDcPP at EAL2" is far more meaningful than "CC EAL2 certified" because the PP ensures the product was tested against specific, threat-relevant requirements.
Who develops Protection Profiles?
PPs come from three sources. International Technical Communities under the CCRA develop collaborative PPs (cPPs) for cross-border recognition. National schemes develop their own PPs (NIAP maintains the largest national library; ANSSI publishes PPs for French government). Industry bodies develop sector PPs, including payment-industry profiles for point-of-sale terminals and smart card profiles from organisations such as GlobalPlatform or EMVCo.