Common Criteria Development and Maintenance in the ISO Framework

Author
Regulations

CRA

EUCC

Common Criteria has long been the benchmark for evaluating the security of IT products within national certification schemes. Many of those schemes belong to the Common Criteria Recognition Arrangement (CCRA), which supports mutual recognition of certificates across participating countries. To improve convergence between the CCRA framework and the ISO editions of Common Criteria, the standard is now developed and maintained within ISO/IEC JTC 1/SC 27 — the ISO/IEC subcommittee responsible for IT security techniques. The goal: produce new editions of the ISO/IEC 15408 series (the international standard defining Common Criteria evaluation criteria) and ISO/IEC 18045 (its companion evaluation methodology), incorporating Common Criteria version 3.1 Revision 5 and related material. These ISO editions are also the technical basis for Europe’s EUCC scheme — making this standardisation work directly relevant to EU-wide certification under the Cybersecurity Act.

Definition

What are ISO/IEC 15408 and ISO/IEC 18045?

ISO/IEC 15408 is the international standard series that defines Common Criteria — the framework used to specify and evaluate security requirements for IT products, from smart cards to network equipment. ISO/IEC 18045 is its companion methodology, detailing exactly how evaluators must assess a product against those requirements. Together they underpin certification schemes worldwide, including SOG-IS in Europe and its successor framework, EUCC, under the EU Cybersecurity Act.

Client / Project Need

Objectives & drivers

ANSSI needed active representation in ISO SC 27 Working Group 3, to keep the development of the Common Criteria standard aligned with French and European principles, operational constraints, and certification interests. It also needed to steer key technical decisions in the standard and adapt its scheme interpretations in a timely way — first under SOG-IS, and now within EUCC. Internet of Trust has supported ANSSI on this since 2018: as a member of the Common Criteria editing team within ISO SC 27 WG 3, it contributed to the publication of the fourth and fifth editions of the ISO/IEC 15408 series and ISO/IEC 18045, in 2022 and 2026 respectively.

Challenge

Key hurdles

The first technical challenge was keeping Common Criteria applicable across a broad range of digital products — requirements generic enough to cover everything from hardware security modules to consumer IoT devices, yet precise enough to support meaningful evaluation. The second was making concepts useful in practice for developers, evaluators, laboratories, and certification bodies, not just valid on paper. On top of that sat real editorial and organisational complexity: several interrelated standards had to stay aligned while a large group of international experts brought different national, technical, and scheme-level priorities to every decision.

Approach

What we did

01

As part of the Common Criteria editing team since 2018, actively contributed to the fourth and fifth editions of the standard.

02

Defined new concepts for complex products with heterogeneous security levels, including modularity and multi-assurance.

03

Contributed to the requirements and assessment criteria for the use of formal models.

04

Contributed to the definition of new Security Functional Requirements, including for the boot process.

05

Generalised best practices from different Common Criteria communities, such as composite evaluation.

06

Led the writing of the transition guide ISO/IEC TR 22216:2022, with the 2026 edition ongoing.

07

Contributed to ISO/IEC TS 9569 on patch management and the ISO/IEC 19896 series on competence requirements.

Key outcomes

Impact delivered

Lessons learned

What we took away

Standardisation is a long game. It rewards perseverance, impartiality, and technical precision — and the ability to align experts who arrive with different national, industrial, and certification priorities. This project confirms Internet of Trust’s capacity to sustain complex, multi-year standardisation work and translate technical assurance concepts into usable certification frameworks — expertise that carries directly into EUCC scheme development and future Cyber Resilience Act conformity assessment work.
FAQ

Frequently asked questions

What is the difference between Common Criteria and ISO/IEC 15408?

They are effectively the same framework — ISO/IEC 15408 is the international ISO edition of the Common Criteria standard, developed to align with the CCRA version maintained by national schemes.

EUCC, the EU’s Common Criteria-based certification scheme under the Cybersecurity Act, uses ISO/IEC 15408 and 18045 as its technical basis — so keeping these ISO editions current directly supports CRA and EUCC certification readiness.

ANSSI (Agence nationale de la sécurité des systèmes d’information) is the French National Cybersecurity Agency and a national Common Criteria certification scheme operator.

Related materials

Keep exploring

ODSI: A Building-Block Approach to Secure Isolation

Read case study →

2IdO: Securing the Industrial Internet of Things

Read case study →

SECREDAS

SECREDAS: Building Trustworthy Automated Systems Across Critical Industries

Read case study →

CRA Box Unified Standard for HWSB

Read case study →

O-RAN Security Test Plan and Assurance Program Development

Read case study →

Security Analysis of 5G Network Products

Read case study →

Contact us

Request this document

We’ll send you access by email.