Semi-conductors

Your silicon is now Europe's regulated trust anchor.

SOG-IS is gone — EUCC is the only game in town. CC:2022 is coming, and the CRA puts tamper-resistant silicon in its strictest classes. We get chips, secure elements and platforms through evaluation — and keep the certificates alive.

SECURE ELEMENT EVALUATION EUCC · AVA_VAN.5

The landscape

Where your product sits

The most mature certification ecosystem in cybersecurity just changed owners. Here is what that means for you.

You make secure elements, smartcard ICs or secure MCUs

SOG-IS certification ended with the transition period in February 2026. EUCC is now the single European route — same Common Criteria substance, new governance, new state-of-the-art documents. Certificates at assurance level “high” (AVA_VAN.4/5) require authorised ITSEFs and certification bodies. If your certificate portfolio still says SOG-IS, its renewal path has changed under you.

EUCC

SOG-IS CLOSED

You are mid-transition to CC:2022

EUCC certifies against CC:2022; certificates on CC 3.1 remain possible only until 31 December 2027. Protection profiles, composite evaluation state-of-the-art and evaluation methods are being reissued for the new version. Starting an evaluation today on the wrong CC version is an expensive way to do it twice.

CC:2022

CC 3.1 SUNSET 2027

You sell into products covered by the CRA

Tamper-resistant microprocessors and microcontrollers are CRA Class II — notified-body assessment, no self-declaration. Secure elements appear on the critical list, where the Commission can make European certification mandatory by delegated act. Your customers will ask for your CRA position in every design-in conversation from now on.

CRA CLASS II

ANNEX IV

You provide IoT platforms, RoT or TEE building blocks

Full Common Criteria is overkill for much of the IoT chain — that is what SESIP (EN 17927) and PSA Certified are for. Platform certificates become reusable claims in your customers’ device evaluations through composite evaluation. The commercial logic: certified silicon shortens every downstream certification, and buyers have noticed.

SESIP · EN 17927

PSA CERTIFIED

You serve automotive, payment or identity markets

Sector schemes stack on top: EMVCo and payment scheme approvals, GSMA eSA/SAS for eUICC production, ISO/SAE 21434 for automotive, and now EUDI-wallet-driven demand for certified secure hardware. Each has its own evaluation culture — and each accepts well-structured CC evidence if you built it right the first time.

SESIP · EN 17927

PSA CERTIFIED

The clock is running

Three transitions are running at once

Scheme transition, standard transition, regulatory transition. Sequence them wrong and you evaluate the same product three times.

27 Feb 2025 DONE

EUCC operational

First EU Cybersecurity Act scheme live; certification bodies and ITSEFs accredited and authorised.

27 Feb 2026 DONE

SOG-IS transition period closed

New certifications route through EUCC only. Legacy certificates need a maintenance strategy under the new scheme.

11 Sep 2026 WEEKS AWAY

CRA reporting obligations begin

Actively exploited vulnerabilities in your silicon and firmware become reportable to ENISA and CSIRTs — 24-hour early warning. PSIRT maturity is now a compliance requirement, not a differentiator.

11 Dec 2027

CRA applies in full — and CC 3.1 sunsets

Class II silicon needs notified-body conformity. Same month, EUCC stops accepting CC 3.1 evaluations. Plan both against the same date.

Horizon

Mandatory certification for critical products

The Commission can require EUCC certification for secure elements and hardware security modules by delegated act. The signal to the market: get ahead of it.

How we work

From silicon roadmap to living certificate portfolio

1

Portfolio strategy

Which products, which scheme, which assurance level, which CC version — mapped against your customers’ regulatory deadlines, not just yours.

2

Security target & PP work

Security targets, protection profile conformance and composite evaluation strategy written for CC:2022 from day one.

3

Vulnerability analysis readiness

AVA_VAN.4/5 preparation against current attack ratings — your product meets the state of the art before the ITSEF tests it.

4

Evidence production

ADV, ALC, AGD deliverables written the way evaluators read them. Site audits prepared, not survived.

5

Evaluation management

Lab selection, kick-off to certificate. We speak evaluator — decades of it — and we sit on your side.

6

Certificate lifecycle

Patch management under EUCC, assurance continuity, re-assessment triggers, CRA reporting alignment. A certificate is an asset only while it is valid.

One evaluation, reused across every downstream claim

A well-built EUCC or SESIP evaluation feeds composite evaluations, sector approvals and your customers’ CRA files. Build the evidence once, at the right level, and let the whole chain inherit it.

PLATFORM CERT EUCC composite Customer CRA file SESIP claims EMVCo / payment GSMA eSA EUDI wallet WSCD

For the specialists

The detail behind the summary

If you already live in the CC world, start here.

EUCC mechanics after SOG-IS

EUCC carries the Common Criteria substance over but changes the machinery: certification bodies under ISO/IEC 17065, ITSEFs under ISO/IEC 17025, with NCCA authorisation required for assurance level “high” (AVA_VAN.4/5). State-of-the-art documents — including composite evaluation for CC:2022 — replace the SOG-IS supporting documents and are maintained under ENISA governance.

The practical differences bite in the details: patch management and assurance continuity are now formalised in the scheme, certificate maintenance follows EU rules, and the mutual-recognition question (CCRA vs. EU-internal) needs an answer per market.

Our position: treat EUCC as a new scheme that happens to speak CC, not as SOG-IS renamed. The teams that audit the deltas now avoid surprises at their first EUCC surveillance.

CC 3.1 evaluations remain acceptable under EUCC only until 31 December 2027. CC:2022 restructures the ADV/ASE landscape, introduces exact conformance for protection profiles and multi-assurance packages, and the smartcard PP ecosystem (BSI-PP-0084 lineage) is migrating with it.

The trap: a certification started late on CC 3.1 that slips past the sunset, or a composite evaluation where base and dependent certificates sit on different CC versions.

Our position: any evaluation starting now targets CC:2022 unless there is a contractual reason not to. Maintenance of existing 3.1 certificates gets a bridge plan with explicit re-evaluation triggers — decided now, not in 2027.

Implementing Regulation 2025/2392 pins down the definitions: tamper-resistant microprocessors and microcontrollers sit in Class II (notified-body assessment mandatory), while secure elements, HSMs and smart meter gateways populate the critical list — where a delegated act can make EUCC certification compulsory.

For silicon vendors the overlap is the opportunity: an EUCC certificate at the right level is expected to carry a presumption of conformity for the corresponding CRA essential requirements. One evaluation, two regulatory outcomes.

Our position: scope your next EUCC evaluation with CRA Annex I mapped from the start. The marginal cost is small; retrofitting the mapping after certification is not.

SESIP (EN 17927) gives platform-level claims at five levels, mapped to CC assurance components but evaluated at IoT-realistic cost. GlobalPlatform operates the scheme; PSA Certified rides the same logic for Arm-based platforms. The value is composite: your platform certificate becomes a reusable evaluation result in every downstream device certification — RED, CRA, EN 303 645 labels.

Attack ratings matter here too: SESIP L3+ brings JIL-style attack potential calculations into scope, and labs differ in how they apply them to non-smartcard targets.

Our position: pick the SESIP level your customers’ certifications actually consume — usually L2 or L3 — and document the composition interface properly. An impressive level with an unusable composition rationale is money spent on marketing.

Talk to people who have sat on every side of the table

Vendor, lab, certifier, scheme — our consultants have worked all four. Thirty minutes, a straight answer on your portfolio.

Contact us

Request this document

We’ll send you access by email.