SOG-IS is gone — EUCC is the only game in town. CC:2022 is coming, and the CRA puts tamper-resistant silicon in its strictest classes. We get chips, secure elements and platforms through evaluation — and keep the certificates alive.
The landscape
The most mature certification ecosystem in cybersecurity just changed owners. Here is what that means for you.
SOG-IS certification ended with the transition period in February 2026. EUCC is now the single European route — same Common Criteria substance, new governance, new state-of-the-art documents. Certificates at assurance level “high” (AVA_VAN.4/5) require authorised ITSEFs and certification bodies. If your certificate portfolio still says SOG-IS, its renewal path has changed under you.
EUCC
SOG-IS CLOSED
EUCC certifies against CC:2022; certificates on CC 3.1 remain possible only until 31 December 2027. Protection profiles, composite evaluation state-of-the-art and evaluation methods are being reissued for the new version. Starting an evaluation today on the wrong CC version is an expensive way to do it twice.
CC:2022
CC 3.1 SUNSET 2027
Tamper-resistant microprocessors and microcontrollers are CRA Class II — notified-body assessment, no self-declaration. Secure elements appear on the critical list, where the Commission can make European certification mandatory by delegated act. Your customers will ask for your CRA position in every design-in conversation from now on.
CRA CLASS II
ANNEX IV
Full Common Criteria is overkill for much of the IoT chain — that is what SESIP (EN 17927) and PSA Certified are for. Platform certificates become reusable claims in your customers’ device evaluations through composite evaluation. The commercial logic: certified silicon shortens every downstream certification, and buyers have noticed.
SESIP · EN 17927
PSA CERTIFIED
Sector schemes stack on top: EMVCo and payment scheme approvals, GSMA eSA/SAS for eUICC production, ISO/SAE 21434 for automotive, and now EUDI-wallet-driven demand for certified secure hardware. Each has its own evaluation culture — and each accepts well-structured CC evidence if you built it right the first time.
SESIP · EN 17927
PSA CERTIFIED
The clock is running
Scheme transition, standard transition, regulatory transition. Sequence them wrong and you evaluate the same product three times.
First EU Cybersecurity Act scheme live; certification bodies and ITSEFs accredited and authorised.
New certifications route through EUCC only. Legacy certificates need a maintenance strategy under the new scheme.
Actively exploited vulnerabilities in your silicon and firmware become reportable to ENISA and CSIRTs — 24-hour early warning. PSIRT maturity is now a compliance requirement, not a differentiator.
Class II silicon needs notified-body conformity. Same month, EUCC stops accepting CC 3.1 evaluations. Plan both against the same date.
The Commission can require EUCC certification for secure elements and hardware security modules by delegated act. The signal to the market: get ahead of it.
How we work
Which products, which scheme, which assurance level, which CC version — mapped against your customers’ regulatory deadlines, not just yours.
Security targets, protection profile conformance and composite evaluation strategy written for CC:2022 from day one.
AVA_VAN.4/5 preparation against current attack ratings — your product meets the state of the art before the ITSEF tests it.
ADV, ALC, AGD deliverables written the way evaluators read them. Site audits prepared, not survived.
Lab selection, kick-off to certificate. We speak evaluator — decades of it — and we sit on your side.
Patch management under EUCC, assurance continuity, re-assessment triggers, CRA reporting alignment. A certificate is an asset only while it is valid.
A well-built EUCC or SESIP evaluation feeds composite evaluations, sector approvals and your customers’ CRA files. Build the evidence once, at the right level, and let the whole chain inherit it.
For the specialists
If you already live in the CC world, start here.
EUCC carries the Common Criteria substance over but changes the machinery: certification bodies under ISO/IEC 17065, ITSEFs under ISO/IEC 17025, with NCCA authorisation required for assurance level “high” (AVA_VAN.4/5). State-of-the-art documents — including composite evaluation for CC:2022 — replace the SOG-IS supporting documents and are maintained under ENISA governance.
The practical differences bite in the details: patch management and assurance continuity are now formalised in the scheme, certificate maintenance follows EU rules, and the mutual-recognition question (CCRA vs. EU-internal) needs an answer per market.
Our position: treat EUCC as a new scheme that happens to speak CC, not as SOG-IS renamed. The teams that audit the deltas now avoid surprises at their first EUCC surveillance.
CC 3.1 evaluations remain acceptable under EUCC only until 31 December 2027. CC:2022 restructures the ADV/ASE landscape, introduces exact conformance for protection profiles and multi-assurance packages, and the smartcard PP ecosystem (BSI-PP-0084 lineage) is migrating with it.
The trap: a certification started late on CC 3.1 that slips past the sunset, or a composite evaluation where base and dependent certificates sit on different CC versions.
Our position: any evaluation starting now targets CC:2022 unless there is a contractual reason not to. Maintenance of existing 3.1 certificates gets a bridge plan with explicit re-evaluation triggers — decided now, not in 2027.
Implementing Regulation 2025/2392 pins down the definitions: tamper-resistant microprocessors and microcontrollers sit in Class II (notified-body assessment mandatory), while secure elements, HSMs and smart meter gateways populate the critical list — where a delegated act can make EUCC certification compulsory.
For silicon vendors the overlap is the opportunity: an EUCC certificate at the right level is expected to carry a presumption of conformity for the corresponding CRA essential requirements. One evaluation, two regulatory outcomes.
Our position: scope your next EUCC evaluation with CRA Annex I mapped from the start. The marginal cost is small; retrofitting the mapping after certification is not.
SESIP (EN 17927) gives platform-level claims at five levels, mapped to CC assurance components but evaluated at IoT-realistic cost. GlobalPlatform operates the scheme; PSA Certified rides the same logic for Arm-based platforms. The value is composite: your platform certificate becomes a reusable evaluation result in every downstream device certification — RED, CRA, EN 303 645 labels.
Attack ratings matter here too: SESIP L3+ brings JIL-style attack potential calculations into scope, and labs differ in how they apply them to non-smartcard targets.
Our position: pick the SESIP level your customers’ certifications actually consume — usually L2 or L3 — and document the composition interface properly. An impressive level with an unusable composition rationale is money spent on marketing.
Vendor, lab, certifier, scheme — our consultants have worked all four. Thirty minutes, a straight answer on your portfolio.
We’ll send you access by email.