Common Criteria has long been the benchmark for evaluating the security of IT products within national certification schemes. Many of those schemes belong to the Common Criteria Recognition Arrangement (CCRA), which supports mutual recognition of certificates across participating countries. To improve convergence between the CCRA framework and the ISO editions of Common Criteria, the standard is now developed and maintained within ISO/IEC JTC 1/SC 27 — the ISO/IEC subcommittee responsible for IT security techniques. The goal: produce new editions of the ISO/IEC 15408 series (the international standard defining Common Criteria evaluation criteria) and ISO/IEC 18045 (its companion evaluation methodology), incorporating Common Criteria version 3.1 Revision 5 and related material. These ISO editions are also the technical basis for Europe’s EUCC scheme — making this standardisation work directly relevant to EU-wide certification under the Cybersecurity Act.
ISO/IEC 15408 is the international standard series that defines Common Criteria — the framework used to specify and evaluate security requirements for IT products, from smart cards to network equipment. ISO/IEC 18045 is its companion methodology, detailing exactly how evaluators must assess a product against those requirements. Together they underpin certification schemes worldwide, including SOG-IS in Europe and its successor framework, EUCC, under the EU Cybersecurity Act.
ANSSI needed active representation in ISO SC 27 Working Group 3, to keep the development of the Common Criteria standard aligned with French and European principles, operational constraints, and certification interests. It also needed to steer key technical decisions in the standard and adapt its scheme interpretations in a timely way — first under SOG-IS, and now within EUCC. Internet of Trust has supported ANSSI on this since 2018: as a member of the Common Criteria editing team within ISO SC 27 WG 3, it contributed to the publication of the fourth and fifth editions of the ISO/IEC 15408 series and ISO/IEC 18045, in 2022 and 2026 respectively.
The first technical challenge was keeping Common Criteria applicable across a broad range of digital products — requirements generic enough to cover everything from hardware security modules to consumer IoT devices, yet precise enough to support meaningful evaluation. The second was making concepts useful in practice for developers, evaluators, laboratories, and certification bodies, not just valid on paper. On top of that sat real editorial and organisational complexity: several interrelated standards had to stay aligned while a large group of international experts brought different national, technical, and scheme-level priorities to every decision.
01
As part of the Common Criteria editing team since 2018, actively contributed to the fourth and fifth editions of the standard.
02
Defined new concepts for complex products with heterogeneous security levels, including modularity and multi-assurance.
03
Contributed to the requirements and assessment criteria for the use of formal models.
04
Contributed to the definition of new Security Functional Requirements, including for the boot process.
05
06
Led the writing of the transition guide ISO/IEC TR 22216:2022, with the 2026 edition ongoing.
07
Contributed to ISO/IEC TS 9569 on patch management and the ISO/IEC 19896 series on competence requirements.
They are effectively the same framework — ISO/IEC 15408 is the international ISO edition of the Common Criteria standard, developed to align with the CCRA version maintained by national schemes.
EUCC, the EU’s Common Criteria-based certification scheme under the Cybersecurity Act, uses ISO/IEC 15408 and 18045 as its technical basis — so keeping these ISO editions current directly supports CRA and EUCC certification readiness.
ANSSI (Agence nationale de la sécurité des systèmes d’information) is the French National Cybersecurity Agency and a national Common Criteria certification scheme operator.
We’ll send you access by email.