Skip to content
Nenkin

SESIP Overview: Security Evaluation Standard for IoT Platforms

SESIP, the Security Evaluation Standard for IoT Platforms, is a security certification methodology published by GlobalPlatform. It reuses Common Criteria structure and vocabulary but defines a distinct, lighter-weight assurance scheme tailored to constrained and fast-moving IoT products.

Key facts

  • Authorizing body: GlobalPlatform publishes the SESIP specification and operates a central certificate registry; accredited certification bodies issue certificates
  • Country / region: Global (used internationally; aligned with EUCC for recognition in Europe)
  • Year established: Initial publication 2020; referenced by ETSI EN 303 645 and PSA Certified Level 4
  • Product types: IoT platforms, microcontrollers, connectivity modules, operating systems, integrated devices
  • CCRA status: Not a CCRA scheme; SESIP is recognized under EUCC as a state-of-the-art methodology for IoT
  • Canonical portal: https://globalplatform.org/sesip/

Overview

SESIP defines five assurance levels (SESIP 1 to SESIP 5) corresponding to increasing depth of evaluation. SESIP 1 is self-assessment with review; SESIP 2 through 5 involve third-party laboratory evaluation with escalating attacker-potential coverage. The methodology reuses Security Targets, TSF, and SFR concepts familiar from Common Criteria, but simplifies documentation and emphasises reusable platform evidence for composite certification.

How evaluations work under this scheme

A vendor authors an ST against the SESIP-defined security functions catalogue. An accredited laboratory performs the required evaluation activities for the chosen SESIP level and produces a report. An accredited certification body issues the certificate, which is then registered in the SESIP public registry managed by GlobalPlatform. Certified components can be reused as secure platforms in larger SESIP evaluations through a composition model.

Notable product categories

  • Secure IoT microcontrollers and system-on-chip products
  • Connectivity modules (cellular, Wi-Fi, LoRa)
  • IoT operating systems and secure element firmware
  • Integrated IoT devices (sensors, smart meters, industrial control endpoints)

Relationship to CC baseline

SESIP leverages ISO/IEC 15408 vocabulary and aligns evaluation activities conceptually with the CEM, but it is a separate methodology with its own levels and requirements. Products can be tracked alongside CC certifications because SESIP STs declare security functions comparable to SFRs. Under EUCC, SESIP evaluations for IoT platforms can contribute to higher-level compositional certificates.

Where to find official records

See also: SESIP vs Common Criteria: When to choose each, PSA Certified, EUCC, Glossary.

Frequently asked questions

What is SESIP?
SESIP is the Security Evaluation Standard for IoT Platforms, a security certification methodology published by GlobalPlatform. It was first published in 2020 and is now referenced by ETSI EN 303 645 and PSA Certified Level 4. SESIP reuses Common Criteria structure and vocabulary but defines a distinct, lighter-weight assurance scheme tailored to constrained and fast-moving IoT products.
Who runs SESIP?
GlobalPlatform publishes the SESIP specification and operates the central certificate registry. Accredited certification bodies issue the certificates, and accredited laboratories perform the evaluation activities for SESIP 2 and above. SESIP is not a CCRA scheme, but it is recognised under EUCC as a state-of-the-art methodology for IoT, which gives certificates a regulatory pathway inside the EU.
What are the SESIP levels?
SESIP defines five assurance levels, SESIP 1 through SESIP 5, corresponding to increasing depth of evaluation. SESIP 1 is self-assessment with review. SESIP 2 through 5 involve third-party laboratory evaluation with escalating attacker-potential coverage. Each level reuses Security Target, TSF, and SFR concepts from Common Criteria but simplifies documentation and emphasises reusable platform evidence.
What does SESIP certify?
SESIP certifies IoT platforms and components: secure IoT microcontrollers and system-on-chip products, connectivity modules (cellular, Wi-Fi, LoRa), IoT operating systems and secure element firmware, and integrated IoT devices such as sensors, smart meters, and industrial control endpoints. SESIP supports composition: a certified component can be reused as a secure platform inside a larger SESIP evaluation.
How does SESIP differ from Common Criteria?
SESIP is methodologically aligned with Common Criteria but separate. It uses ISO/IEC 15408 vocabulary and a CEM-style evaluation model, but its levels are not EALs and its documentation is significantly lighter. SESIP targets IoT products where full CC evaluation would be too slow or expensive, and where compositional reuse of platform evidence is valuable. EUCC formally recognises SESIP for IoT.
How is a SESIP certificate issued?
A vendor authors a Security Target against the SESIP-defined security functions catalogue. An accredited laboratory performs the evaluation activities for the chosen SESIP level and produces a report. An accredited certification body issues the certificate, which is then registered in the SESIP public registry managed by GlobalPlatform. Certified components can subsequently contribute to higher-level compositional evaluations.