Services

Evaluation Support

From scoping to certificate maintenance — expert support across Common Criteria, SESIP, CSPN, GlobalPlatform, PCI, FITCEM and FIDO.

Introduction

What evaluation support covers

Security evaluation and certification are no longer optional differentiators — they are opposable requirements in payments, identity, mobile, automotive and critical infrastructure. Yet skilled certification talent is scarce, and every misstep multiplies lab cycles and time-to-market.

Internet of Trust accompanies developers, manufacturers and service providers from basic to the highest assurance levels, adapting to V, Agile or hybrid development models across the schemes below.

This page details our four-phase delivery method, the four engagement modes available, deliverables across Security Targets, audit reports and certification documentation, and how to anticipate scheme convergence under the EU Cybersecurity Act.

Common Criteria EAL4+ → EAL7

SESIP

CSPN

GlobalPlatform

PCI

FITCEM

FIDO

Process

Scope, Plan, Execute, Maintain

Activities are tailored to applicable regulations and to the customer’s code of practice. Every phase is anchored in measurable certification milestones — from scoping decisions to post-issuance assurance continuity.

01

Scope

Workshop to define the Target of Evaluation, scheme and assurance level, security requirements, certification body and laboratory.

02

Plan

Gap analysis against the target EAL or scheme level; concrete action plan covering time, resources, reuse strategy and long-term certification roadmap.

03

Execute

Joint delivery with the customer: write missing evidences (Security Target, traceability), interface with the lab and certification body up to certificate issuance.

04

Maintain

Assurance continuity: Change Impact Analysis Reports, updated evidences, re-submission management, follow-up of corrective action plans.

Delivery plan

What we deliver

Deliverables are tailored to customer milestones — from executive overviews to traceable engineering artefacts ready for evaluation labs and certification bodies.

Security Target writing

CC, CSPN and scheme-specific STs aligned to the chosen Protection Profile and EAL.

Trainings & workshops

Targeted enablement on CC, Protection Profiles, EAL specifics and lab interaction.

Audit reports & corrective plans

Site Security Audit reports with alternative measures and tracked remediation.

Technical documentation

Functional/design specs, test plans, user manuals, cryptographic analyses (AES-GCM, ML-KEM, ECDSA).

Certification documentation

Requirements traceability, security rationales, evaluation evidence packs.

Project management tools

Cadence, RAID, lab interface protocols, milestone dashboards.

Engagement modes

Types of services

Four engagement shapes, selected by scope, assurance target and life-cycle stage.

Mode 01

Scoping & Team Set-up

Define project, resources and stakeholders. Select scheme, security requirements and assurance level for single- or multi-purpose products.

Mode 02

Integral Support

Whole life-cycle accompaniment across one or more certifications — project management, lab/certifier interface, technical documentation. Typical for vendors moving from EAL4+/EAL5+ to EAL6/EAL7.

Mode 03

Focused Support

Targeted intervention at a specific moment of preparation or evaluation — typically Security Target writing or evaluation project management.

Mode 04

Site Security Audit

Study of development / manufacturing / integration/ personalization sites against applicable regulations, optionally followed by on-site inspection ahead of formal third-party audit.

Field record

Examples of services

Recent engagements include Common Criteria EAL5+/EAL6 evaluations for secure elements and TEEs, SESIP Level 3 preparation for IoT platforms, CSPN security targets for connected industrial gateways, FITCEM and PCI evaluation strategies for payment acceptance terminals, and pre-audits for GSMA SAS and ANSSI site qualification.

Related case studies

GlobalPlatform SESIP: Preparing Developers for Security Evaluation

Hands-on SESIP scoping, target-level selection and draft Security Target work for a connected EV charger platform…

Read case study →

Common Criteria EAL4+ Certification for a Trusted Platform Module

Nations Technologies manufactures Trusted Platform Modules — developing both the hardware and the integrated software for secure computing environments. A TPM is a …

Read case study →

Contact us

Request this document

We’ll send you access by email.