Microsoft TPM requirements
European cybersecurity regulations
Common Criteria
ANSSI certification
Trusted Platform Module security assurance
Nations Technologies manufactures Trusted Platform Modules — developing both the hardware and the integrated software for secure computing environments. A TPM is a critical security component: it handles secure key storage, platform integrity, cryptographic operations, and trust anchoring for the device. To meet a key Microsoft requirement and get ahead of tightening European cybersecurity expectations, Nations Technologies built a new, higher-assurance TPM and set out to certify it to Common Criteria EAL4+ in France, under ANSSI supervision. This was a strategic certification, not a product test — it meant aligning the product, the development process, the manufacturing chain, the documentation, the evaluation lab, and the certification authority.
Nations Technologies needed a high-assurance certification that would do several jobs at once: satisfy Microsoft’s TPM security requirement, demonstrate strong product assurance, build trust with demanding customers and partners, get ahead of European cybersecurity regulation, and position the TPM competitively in security-sensitive markets — all within a market-relevant timeline. The added constraint: the team had no prior experience with Common Criteria or high-assurance certification. Internet of Trust had to supply both the technical certification expertise and the operational guidance to run the full lifecycle.
Bringing a combined hardware/software security component to ANSSI’s EAL4+ level takes far more than documentation. It reaches into product architecture, vulnerability analysis, development methodology, configuration management, testing, manufacturing controls, lifecycle security, and audit preparation — several of which had to move in parallel. Because the product combined hardware and software, any design weakness could force remediation by the client’s R&D teams, with knock-on effects on schedule and scope. EAL4+ also demands deep evidence: the evaluator must be able to trace how the product is specified, designed, developed, tested, manufactured, delivered, and maintained. And it involved four parties who all had to stay in sync — Nations Technologies, Internet of Trust, ANSSI as certification body, and Thales/CESTI as evaluation laboratory. With client teams new to Common Criteria, every function from R&D to supply chain had to understand how its work fed the final result. This was a cross-functional project, not a purely technical one.
01
Baseline and gap analysis. Assessed the product against EAL4+ expectations to identify the main workstreams, documentation needs, likely weaknesses, and certification risks.
02
Structured action plan. Defined the route to the target assurance level, covering the product, the Security Target, documentation, evaluation interactions, internal training, audits, and remediation cycles.
03
Security Target. Prepared the ~100-page Security Target defining the product scope, security problem, objectives, functional requirements, and assurance requirements — the reference point shared by client, lab, and certification authority.
04
Cross-functional training. Trained 10 Nations Technologies staff across R&D, product development, product management, manufacturing, and supply chain, so every team understood the EAL4+ process, the evidence required, and its own responsibilities — because high-assurance certification can’t be carried by a certification manager alone.
05
Evaluation documentation package. Wrote the full kit: 25 documents, each typically 20–50 pages, covering development process, architecture, security functions, test plans, lifecycle, configuration management, manufacturing, delivery, and vulnerability handling — the basis for the evaluator’s analysis and ANSSI’s review.
06
Stakeholder coordination. Managed structured exchanges with ANSSI and Thales/CESTI, keeping questions, evidence requests, and evaluation issues moving.
07
Site audit preparation. Prepared the client’s R&D and manufacturing sites for security audits, aligning processes and operational practice with Common Criteria expectations.
08
Remediation support. When hardware and software vulnerabilities surfaced during evaluation, structured the certification impact analysis, evaluation follow-up, and evidence updates. The full process ran roughly two years, from preparation to certificate.
EAL4+ certification is a company-wide process, not an R&D task — it pulls in product management, development, testing, documentation, manufacturing, supply chain, delivery, and executive commitment. For teams new to Common Criteria, structured training isn’t optional: each department has to understand what evidence it owns and why it matters. Early engagement with the certification body and lab is just as critical for cutting ambiguity before issues become blockers. And on complex hardware/software products, remediation cycles should be planned for, not treated as surprises — the discipline is to catch issues early, assess their certification impact, and keep the evidence consistent. Success depends on a clear strategy, rigorous documentation, cross-functional training, tight coordination with evaluators, and the ability to absorb remediation without losing the timeline.
We’ll send you access by email.