Skip to content
Nenkin

NIAP: The U.S. Common Criteria Scheme

NIAP, the National Information Assurance Partnership, operates the United States’ Common Criteria Evaluation and Validation Scheme (CCEVS). Since 2014 NIAP has required evaluations to conform strictly to an approved Protection Profile, departing from open-ended EAL targets.

Key facts

  • Authorizing body: National Information Assurance Partnership (NIAP), a collaboration between NSA and industry
  • Country / region: United States
  • Year established: NIAP was founded in 1997; the CCEVS operating model shifted to PP-based evaluations in 2014
  • Product types: network devices, mobile OSes and applications, virtualization, full-disk encryption, operating systems, application software, MFDs, enterprise mobility
  • CCRA status: Certificate Authorizing Member; does not accept standalone EAL claims but recognizes certificates issued under cPPs
  • Canonical portal: https://www.niap-ccevs.org/

Overview

NIAP validates evaluations against the U.S. Protection Profile library. Vendors can only pursue NIAP validation if a corresponding NIAP-Approved Protection Profile exists for their technology type. NIAP emphasizes exact conformance: the Security Target contains the PP’s SFRs with allowed selections and assignments, and no unauthorized additions.

How evaluations work under this scheme

A vendor engages a NIAP-accredited Common Criteria Testing Laboratory (CCTL). The CCTL performs evaluation activities defined in the PP and its Supporting Document, producing an Evaluation Technical Report and an Assurance Activities Report. NIAP validates the evaluation and publishes the Validation Report and certificate. Active NIAP certificates appear on the Product Compliant List (PCL); archived entries are maintained on the Archived Products list for historical reference.

Notable product categories

  • Network devices and VPN gateways (cPP Network Device, NDcPP)
  • General-purpose operating systems
  • Mobile device management and mobile OS platforms
  • Application software and web browsers
  • Full-disk and file encryption software
  • Multifunction devices and Hardcopy Device PP
  • Enterprise session controllers and dedicated security components

Relationship to CC baseline

NIAP-approved PPs are built on ISO/IEC 15408 and the CEM, with evaluation activities tailored for PP-driven evaluation. NIAP participates in CCRA Technical Communities (iTCs) that develop collaborative Protection Profiles recognized internationally. NIAP does not use EAL labels in certificates; assurance is expressed as conformance to the PP and its SD.

Where to find official records

See also: Protection Profiles, EAL Levels, Glossary.

Frequently asked questions

What is NIAP?
NIAP is the National Information Assurance Partnership, a collaboration between the National Security Agency (NSA) and industry. It operates the United States' Common Criteria Evaluation and Validation Scheme (CCEVS). NIAP was founded in 1997. Since 2014 it has required all evaluations to conform strictly to an approved Protection Profile, departing from open-ended EAL targets.
Does NIAP require Protection Profiles?
Yes. Since 2014, NIAP only validates evaluations that claim exact conformance to a NIAP-Approved Protection Profile. A vendor can pursue NIAP validation only if a corresponding PP exists for the technology type. The Security Target contains the PP's SFRs with allowed selections and assignments and no unauthorised additions. Standalone vendor-defined EAL claims are not accepted.
What is the NIAP Product Compliant List?
The Product Compliant List (PCL) is NIAP's public catalogue of currently validated products. It is the canonical reference used by U.S. federal procurement teams to verify that a product holds an active NIAP certificate. Products whose certificates have expired or been superseded are moved from the PCL to the Archived Products list, which is maintained for historical reference but does not represent active assurance.
What does NIAP certify?
NIAP issues certificates for product categories with an approved Protection Profile. The main categories are network devices and VPN gateways (NDcPP), general-purpose operating systems, mobile device management and mobile OS platforms, application software and web browsers, full-disk and file encryption software, multifunction devices under the Hardcopy Device PP, virtualisation, and dedicated security components.
Is NIAP certification required for U.S. federal procurement?
For many product categories, yes. CNSSP-11 requires that commercial off-the-shelf IT products used to protect national security systems have a NIAP certificate where an approved PP exists, and federal civilian agencies follow similar guidance under FISMA and NIST SP 800-53. Network devices, mobile platforms, and operating systems are the categories where NIAP validation is most consistently required.
Does NIAP use EAL labels?
No. NIAP certificates do not carry EAL labels. Assurance is expressed as conformance to an approved Protection Profile and its Supporting Document. NIAP participates in CCRA Technical Communities (iTCs) that develop collaborative Protection Profiles recognised internationally; the cPPs themselves embed the assurance activities, replacing EAL packages as the unit of assurance NIAP recognises.