Common Criteria defines how to state security claims (security targets, protection profiles), how to evaluate them (the ISO/IEC 18045 methodology), and how to grade the effort (assurance components, packaged as EALs). Its centre of gravity is vulnerability analysis: at AVA_VAN.4/5, evaluators with insider-level knowledge attack the product using state-of-the-art techniques and rated attack potential — which is why CC at high levels remains the only widely recognised proof that hardware resists a well-funded attacker.
Since February 2025, the European home of CC is EUCC — the first scheme under the EU Cybersecurity Act. It carried over the SOG-IS technical heritage (including composite evaluation for smartcards) but changed the machinery: ISO 17065 certification bodies and ISO 17025 labs, NCCA authorisation for level “high”, ENISA-governed state-of-the-art documents, and formalised patch management and assurance continuity. The SOG-IS transition closed in February 2026; there is no other European CC route.
Two clocks are running. CC:2022 replaces CC 3.1, which EUCC stops accepting at the end of 2027 — the same month the Cyber Resilience Act fully applies, with EUCC positioned as the certification anchor for CRA critical products. Starting an evaluation today means choosing versions, levels and timing with both deadlines in view.