Skip to content
Nenkin

OCSI: Italy's Common Criteria Scheme

OCSI, the Organismo di Certificazione della Sicurezza Informatica, is Italy’s designated EUCC certification authority. It operates under the Italian Cybersecurity Agency, Agenzia per la Cybersicurezza Nazionale (ACN), and was transferred to ACN in July 2022. OCSI previously operated Italy’s national CC scheme, which retired on 27 February 2026.

Key facts

  • Authorizing body: Agenzia per la Cybersicurezza Nazionale (ACN)
  • Country / region: Italy
  • Year established: OCSI was established in October 2003 by DPCM to operate Italy’s national CC scheme; transferred to ACN in July 2022
  • Product types: smart cards and ICs, network devices, software security products, payment-related TOEs
  • CCRA status: Certificate Authorizing Member (still listed on the CC Portal); historically a SOG-IS authorizing member; now Italy’s designated EUCC certification authority. National scheme retired 27 February 2026; new certifications issued only under EUCC
  • Canonical portal: https://www.ocsi.gov.it/

Overview

OCSI publishes Italy’s CC certifications and the supporting evaluation reports. Italy was a long-standing participant in SOG-IS, the European mutual recognition arrangement that preceded EUCC, and OCSI is one of the national schemes folded into the EUCC framework under the EU Cybersecurity Act. The national scheme retired on 27 February 2026, after which OCSI issues new certifications exclusively under EUCC; certificates issued before that date remain valid.

How evaluations work under this scheme

Evaluations are carried out by accredited Laboratori per la Valutazione della Sicurezza (LVS), Italy’s designation for an ITSEF. The LVS produces an Evaluation Technical Report which OCSI reviews and uses to issue the final Certification Report.

Notable product categories

  • Smart cards and embedded secure elements
  • Network and communications products
  • Software security products
  • Payment-related TOEs

Relationship to CC baseline

OCSI evaluations follow ISO/IEC 15408 and CC:2022. Italy’s national CC scheme retired on 27 February 2026, and OCSI now issues certificates exclusively under EUCC. Previously issued national OCSI certificates remain valid and continue to be recognised under CCRA.

Where to find official records

See also: What is Common Criteria?, EAL Levels, Protection Profiles, Glossary.

Frequently asked questions

What is OCSI?
OCSI is the Organismo di Certificazione della Sicurezza Informatica, the certification body within the Agenzia per la Cybersicurezza Nazionale (ACN), the Italian Cybersecurity Agency. It was established in October 2003 by DPCM to operate Italy's national CC scheme, and was transferred to ACN in July 2022. The national scheme retired on 27 February 2026, and OCSI now operates as Italy's designated EUCC certification authority.
What does OCSI certify?
OCSI issues Common Criteria certificates for smart cards and integrated circuits, network and communications products, software security products, and payment-related TOEs. The scheme also covers components used in Italian eIDAS contexts, particularly for digital identity and electronic signature products that must comply with EU regulations on qualified trust services.
How is an OCSI certificate issued?
Evaluations are carried out by accredited Italian ITSEFs, known as Laboratori per la Valutazione della Sicurezza (LVS). The LVS produces an Evaluation Technical Report against the Security Target and the relevant Protection Profile or EAL package. OCSI reviews the ETR and issues the final Certification Report and certificate, which is then published on the OCSI portal and the CCRA portal.
Is OCSI a CCRA member?
Yes. OCSI is listed as a CCRA Certificate Authorizing Member on the Common Criteria Portal, and Italy was historically a SOG-IS authorizing member. With the retirement of Italy's national CC scheme on 27 February 2026, OCSI no longer issues new national CC certificates under that authorisation; new certifications are issued exclusively under the EU Cybersecurity Act's EUCC framework, where OCSI is Italy's designated certification authority. Previously issued OCSI national certificates remain valid and continue to be recognised across CCRA member nations.
Does OCSI cover digital identity and electronic signature?
Yes, this is one of OCSI's distinctive areas. Italy has a developed eIDAS ecosystem, and OCSI evaluates components used in qualified electronic signature, qualified electronic seal, and digital identity solutions. Certified smart cards and secure signature creation devices are typical TOEs, often relied on by Italian and pan-European trust service providers operating under the eIDAS Regulation.
How does OCSI relate to EUCC?
OCSI operates exclusively under EUCC for new certifications. Italy's national CC scheme retired on 27 February 2026, and OCSI now issues certificates only under the EU Cybersecurity Act's EUCC framework, at the substantial and high assurance levels. EUCC shares the same technical baseline as the national scheme, ISO/IEC 15408 and CC:2022, and SOG-IS Supporting Documents, particularly for smart cards, have transitioned into the EUCC framework.