Skip to content
Nenkin

CCCS: Canada's Common Criteria Scheme

CCCS, the Canadian Centre for Cyber Security, operates Canada’s Common Criteria scheme (CCS). Like NIAP, CCCS emphasises collaborative Protection Profile evaluations and is a leading participant in international Technical Communities that develop cPPs.

Key facts

  • Authorizing body: Canadian Centre for Cyber Security (CCCS), part of the Communications Security Establishment (CSE)
  • Country / region: Canada
  • Year established: Canada’s CC scheme has operated since the standard’s introduction; CCCS took over as the brand in 2018, consolidating earlier CSE-led activities
  • Product types: network devices, operating systems, mobile platforms, application software, and other cPP-aligned categories
  • CCRA status: Certificate Authorizing Member; Canada co-chairs or participates in multiple iTCs
  • Canonical portal: https://www.cyber.gc.ca/en/tools-services/canadian-common-criteria-program

Overview

CCCS oversees CCS evaluations carried out by Canadian CCTLs. The scheme’s output is dominated by evaluations against collaborative Protection Profiles, aligning closely with NIAP’s approach while remaining distinct in administration. Canada has long been a major contributor to CCRA Technical Communities, including those for network devices, dedicated security components, and endpoint products.

How evaluations work under this scheme

A vendor engages a CCS-accredited CCTL, which runs evaluation activities from the chosen cPP and its Supporting Document. CCCS reviews the Evaluation Technical Report and issues a Certification Report. Canadian certificates are posted to the CCS Certified Product List and mirrored in the CCRA portal for mutual recognition.

Notable product categories

  • Network devices (firewalls, VPN gateways, routers, switches) under NDcPP
  • Dedicated security components (HSMs, enterprise session controllers) under DSCcPP
  • Operating systems and application software
  • Full-disk encryption and cryptographic modules (as applicable)
  • Mobile platforms and management products

Relationship to CC baseline

CCS evaluations align with ISO/IEC 15408, the CEM, and cPP-driven evaluation activities. CCCS works within the CCRA mutual recognition framework and leverages Technical Community outputs, keeping evaluations methodologically consistent with NIAP, Swedish, and other cPP-focused schemes.

Where to find official records

See also: Protection Profiles, EAL Levels, Glossary.

Frequently asked questions

What is CCCS?
CCCS is the Canadian Centre for Cyber Security, part of the Communications Security Establishment (CSE). It operates Canada's Common Criteria Scheme (CCS). The CCCS brand was adopted in 2018, consolidating earlier CSE-led certification activity. CCCS is a CCRA Certificate Authorizing Member and a leading contributor to international Technical Communities that develop collaborative Protection Profiles.
What does CCCS certify?
CCCS issues Common Criteria certificates predominantly against collaborative Protection Profiles. Its output covers network devices (firewalls, VPN gateways, routers, switches), dedicated security components such as HSMs and enterprise session controllers, operating systems, application software, full-disk encryption, and mobile platforms and management products.
How is a CCCS certificate issued?
A vendor engages a CCS-accredited Common Criteria Testing Laboratory (CCTL). The CCTL runs the evaluation activities defined in the chosen collaborative Protection Profile and its Supporting Document. CCCS reviews the resulting Evaluation Technical Report, issues a Certification Report, and posts the certificate to the Canadian Certified Product List. The certificate is then mirrored on the CCRA portal for international recognition.
Is CCCS a CCRA member?
Yes. CCCS is a CCRA Certificate Authorizing Member, and Canada co-chairs or participates in multiple international Technical Communities (iTCs) that develop collaborative Protection Profiles. Certificates issued by CCCS are recognised by all other CCRA members up to the arrangement's standard cap, and at higher levels for products conforming to a recognised cPP.
How does CCCS compare to NIAP?
CCCS and NIAP take a similar approach: both emphasise evaluations against collaborative Protection Profiles rather than open-ended EAL targets, and both contribute heavily to international Technical Community work. They remain administratively distinct national schemes, but methodologies are closely aligned, which is why network device, OS, and mobile platform vendors often pursue certification under either scheme depending on procurement.
Does CCCS also run a cryptographic module programme?
The Cryptographic Module Validation Program (CMVP) is run jointly by the U.S. NIST and the Communications Security Establishment (CSE) of Canada, of which CCCS is a part. CMVP validates cryptographic modules under FIPS 140-3 and is separate from Common Criteria. Many products evaluated under the Canadian CC scheme for network or OS security also hold a CMVP certificate for the cryptographic engine they embed, particularly for U.S. and Canadian federal procurement.