Skip to content
Nenkin

BSI: Germany's Common Criteria Scheme

BSI, the Bundesamt für Sicherheit in der Informationstechnik, is Germany’s national cybersecurity agency and the certification body for Common Criteria evaluations carried out in Germany. It is one of the most active authorizing schemes under the CCRA and a central participant in European high-assurance ecosystems.

Key facts

Overview

BSI publishes Certification Reports and Security Targets for every completed evaluation, which means the scheme produces a large and detailed public record. German ITSEFs include long-standing labs specializing in smart card hardware, cryptographic modules, and payment systems. BSI coordinates with the Common Criteria Recognition Arrangement for international mutual recognition and is a primary driver of high-assurance evaluations in the EU.

How evaluations work under this scheme

An applicant engages an ITSEF accredited by BSI. The ITSEF performs work units defined in the CEM and any applicable Supporting Documents, then drafts an Evaluation Technical Report. BSI reviews the ETR, resolves any observations, and issues the Certification Report and certificate. For smart card products, evaluations typically follow BSI’s guidance on attack methods and interpretations (often referred to as the “JIL” documents co-published with SOG-IS partners).

BSI also operates a maintenance process based on assurance continuity: vendors submit impact analyses and maintenance reports to extend certificates after minor changes, without triggering a full re-evaluation.

Notable product categories

  • Smart card ICs and secure microcontrollers at EAL4+ through EAL6+ (with AVA_VAN.5)
  • Payment terminals and HSMs evaluated against relevant Protection Profiles
  • Digital tachographs for compliance with EU regulations
  • Signature-law products for qualified electronic signatures
  • Network devices and operating systems (periodic, less frequent than the embedded segment)

Relationship to CC baseline

BSI evaluations follow the Common Criteria baseline established by ISO/IEC 15408 and CC:2022, augmented by the smart card interpretations developed jointly with European partners. Under the transition to EUCC, BSI acts as a national cybersecurity certification authority, issuing EUCC certificates alongside its traditional CC certificates where applicable.

Where to find official records

See also: What is Common Criteria?, EAL Levels, Protection Profiles, Glossary.

Frequently asked questions

What is BSI?
BSI is the Bundesamt für Sicherheit in der Informationstechnik, Germany's federal cybersecurity agency. It was created in 1991 and operates Germany's Common Criteria scheme under the BSI-Gesetz. BSI is one of the most active CCRA Certificate Authorizing Members and a central participant in European high-assurance certification ecosystems.
What does BSI certify?
BSI is the home scheme for smart cards, integrated circuits, and secure microcontrollers, including products from Infineon and NXP. It also issues certificates for payment terminals, hardware security modules, digital tachographs, eID systems, signature-law components, and network products and operating systems. BSI is particularly strong at the high-assurance end (EAL4+ through EAL6+ with AVA_VAN.5).
How is a BSI certificate issued?
An applicant engages a BSI-accredited ITSEF. The lab runs the work units defined in the Common Evaluation Methodology and any applicable Supporting Documents, then drafts an Evaluation Technical Report. BSI reviews the ETR, resolves observations, and issues the Certification Report and certificate. For smart cards, evaluations follow joint interpretation documents (the JIL papers) co-published with SOG-IS partners.
Is BSI a CCRA member?
Yes. BSI is a CCRA Certificate Authorizing Member, so its certificates are recognised by all other CCRA member nations up to the standard cap. BSI was historically a SOG-IS authorizing member for smart cards and is now a designated EUCC certification authority under the EU Cybersecurity Act, issuing EUCC certificates alongside its traditional CC certificates.
Why is BSI considered the leading smart card scheme?
Germany hosts long-standing ITSEFs that specialise in smart card hardware, cryptographic modules, and payment systems, and BSI publishes Certification Reports and Security Targets for every completed evaluation, producing a detailed public record. The major European IC vendors run their evaluations through BSI, and the scheme drives much of the joint smart card attack methodology used across EU schemes.
Can a BSI certificate be extended without a full re-evaluation?
Yes. BSI operates a maintenance process based on assurance continuity. Vendors can submit an Impact Analysis Report and a maintenance report covering minor changes to the certified product. BSI reviews the documents and extends the certificate without triggering a full re-evaluation, provided the changes do not alter the security architecture or affect the evaluation evidence significantly.