Services

Scheme Definition

Designing the technical, organizational and process backbone of trustworthy security evaluation and certification schemes.

Introduction

What scheme definition covers

A security evaluation and certification scheme is the framework that establishes — and maintains — trust in cybersecurity products, processes and services. With ENISA’s reinforced mandate under the EU Cybersecurity Act, scheme proliferation is now a structural feature of the regulatory landscape.

Internet of Trust helps organizations design schemes that are technically credible, market-feasible and regulator-acceptable: technical and organizational requirements, evaluation methodologies, lab accreditation criteria, and certification processes.

This page outlines the three-step definition method, the four-axis writing scope, deliverables from Protection Profiles to communication plans, and the engagement modes for new schemes, scheme updates and requirements analysis against CRA, NIS 2 and sectorial mandates.

EU Cybersecurity Act

ENISA mandate

EUCC

EUCS

CRA

NIS 2

Process

Outline, Write, Validate

A three-step definition method, iterative by construction, calibrated to the scheme owner’s ambition and to the ecosystem of stakeholders it must serve.

01

Outline

Identify the scheme owner’s goals and outline its principles. Associate a representative stakeholder group to integrate market expectations, domain-specific technology and life-cycle constraints.

02

Write

Address four axes: scope, evaluation methodology and test requirements, lab accreditation criteria, and accreditation/evaluation/certification processes — the scheme’s backbone.

03

Validate

Iterative or end-of-cycle stakeholder review. For some schemes, validation includes formal approval by evaluation authorities or certification bodies.

Delivery plan

What we deliver

Deliverables span the four scheme axes — scope, methodology, processes and stakeholder communication — ready to be adopted by evaluation authorities, certification bodies and accredited laboratories.

Scope of evaluation

Protection Profiles, PP-Modules, requirement catalogs and detailed questionnaires defining what is in and out of scope.

Evaluation methodologies & test requirements

How labs perform assessments, standardized test plans, reporting criteria and templates.

Accreditation, evaluation & certification processes

Detailed instructions and documentation templates for scheme users, evaluators, certifiers and auditors.

Communication plan & media resources

Presentations, white papers, FAQs and stakeholder onboarding material.

Engagement modes

Types of services

Three engagement shapes covering new schemes, scheme processes and analysis of existing frameworks.

Mode 01

Scheme Requirements

Define evaluation scope, the requirements products must meet, and the methodology labs use to verify compliance — Protection Profiles, security guidelines, test plans, attack catalogs.

Mode 02

Scheme Processes

Design the accreditation, evaluation and certification process backbone — workflows, templates, decision criteria and appeal mechanisms.

Mode 03

Scheme Requirements Analysis

Study existing schemes against new regulations or functional specifications — identify gaps, propose updates, support the maintenance of national or sectorial schemes.

Field record

Examples of services

Past engagements cover Protection Profile drafting for IoT platforms and connected industrial control, scheme update assessments under the EU Cybersecurity Act, lab accreditation criteria for sectorial schemes, and process design for national certification authorities transitioning to EUCC alignment.

Related case studies

CRA Box Unified Standard for HWSB

Mapping Cyber Resilience Act obligations onto existing HWSB certification baselines — Common Criteria, FIPS 140-3, PCI and CSPN — so HSM, payment terminal and tachograph manufacturers avoid duplicated evaluation work….

Read case study →

O-RAN Security Test Plan and Assurance Program Development

Security test specifications and assurance material for the O-RAN ALLIANCE, translating WG11 requirements into concrete, repeatable evaluation criteria aligned…

Read case study →

GlobalPlatform TEE Scheme Creation and Operation

Built and operated the GlobalPlatform TEE security evaluation and certification scheme mapping TEE specifications to Common Criteria, defining Protection Profile-style…

Read case study →

Common Criteria Development and Maintenance in the ISO Framework

Contributing to the ISO/IEC 15408 and 18045 editions alongside ANSSI — shaping the international Common Criteria standard that underpins EUCC and CRA-aligned certification across Europe….

Read case study →

Contact us

Request this document

We’ll send you access by email.