Skip to content
Nenkin

JISEC: Japan's Common Criteria Scheme

JISEC, the Japan Information Technology Security Evaluation and Certification Scheme, is Japan’s national Common Criteria scheme. It is operated by the Information-technology Promotion Agency (IPA) and is a CCRA authorizing member with a distinctive emphasis on printing and imaging equipment.

Key facts

  • Authorizing body: Information-technology Promotion Agency (IPA)
  • Country / region: Japan
  • Year established: 2001 (Japan became CCRA authorizing participant in 2003)
  • Product types: multifunction devices and printers, hard-copy devices, network products, application software, smart cards
  • CCRA status: Certificate Authorizing Member
  • Canonical portal: https://www.ipa.go.jp/en/security/jisec/index.html

Overview

JISEC is the principal issuer of CC certificates for multifunction devices and hard-copy products globally, reflecting Japan’s manufacturing strengths in office imaging. Beyond that segment, JISEC evaluates network products, smart card operating systems, and a range of application software for domestic and international markets.

How evaluations work under this scheme

IPA accredits Japanese evaluation facilities as JISEC ITSEFs. A vendor contracts with an ITSEF, which produces the Evaluation Technical Report. IPA reviews the ETR, issues the Certification Report, and publishes the certificate on the JISEC list. JISEC evaluations can be PP-conformant (for example, the Hardcopy Device cPP is a common anchor for MFP certifications) or EAL-driven within CCRA-recognized bounds.

Notable product categories

  • Multifunction devices and hard-copy equipment
  • Network security products
  • Smart card operating systems and secure elements
  • Application software and middleware
  • Mobile and embedded security products

Relationship to CC baseline

JISEC follows ISO/IEC 15408 and the CEM, using the same SFR and SAR framework as other CCRA schemes. Japan participates in Technical Communities, particularly those relevant to its certified product base, and keeps JISEC’s evaluation methodology aligned with CCRA norms.

Where to find official records

See also: Certification Schemes Overview, EAL Levels, Glossary.

Frequently asked questions

What is JISEC?
JISEC is the Japan Information Technology Security Evaluation and Certification Scheme, Japan's national Common Criteria scheme. It is operated by the Information-technology Promotion Agency (IPA), an arm of the Japanese government. JISEC was established in 2001 and Japan became a CCRA Certificate Authorizing Member in 2003.
What does JISEC certify?
JISEC is the global anchor for Common Criteria certificates on multifunction devices and hard-copy products, reflecting Japan's manufacturing strengths in office imaging. Beyond MFDs, JISEC issues certificates for network security products, smart card operating systems and secure elements, application software and middleware, and mobile and embedded security products for domestic and international markets.
How is a JISEC certificate issued?
IPA accredits Japanese evaluation facilities as JISEC ITSEFs. A vendor contracts with an ITSEF, which performs the evaluation and produces the Evaluation Technical Report. IPA reviews the ETR, issues the Certification Report, and publishes the certificate on the JISEC certified product list. Evaluations can be PP-conformant (the Hardcopy Device cPP is a common anchor for MFP certifications) or EAL-driven within CCRA-recognised bounds.
Is JISEC a CCRA member?
Yes. JISEC is a CCRA Certificate Authorizing Member and has been since 2003. Certificates issued by JISEC are recognised by all other CCRA member nations up to the arrangement's standard cap, and at higher levels for products conforming to a recognised collaborative Protection Profile. Japan participates actively in Technical Communities relevant to its certified product base.
Why do most multifunction device certifications come from JISEC?
The major manufacturers of multifunction printers and hard-copy devices (Canon, Konica Minolta, Kyocera, Ricoh, Sharp, Toshiba, Brother, and others) are headquartered in Japan, and their CC evaluations naturally route through their domestic scheme. The Hardcopy Device collaborative Protection Profile is the standard target for these products, and JISEC's ITSEFs have deep experience evaluating MFD security functionality.
Does JISEC use EAL labels?
JISEC follows the CCRA model. It accepts evaluations against collaborative Protection Profiles (where assurance is expressed as PP conformance) and EAL-driven evaluations up to the CCRA recognition cap. Certificates show the EAL package or the conformant PP, depending on which path the vendor chose. JISEC participates in the same CC baseline, using the same SFRs and SARs as other CCRA schemes.