Standard & Scheme · General Purpose

Common Criteria — and EUCC, its European home

The deepest, most demanding product security evaluation methodology in use — and since 2025, an EU-regulated certification scheme. If your product is a trust anchor for someone else's security, this is eventually your standard.

At a glance

Basis

ISO/IEC 15408 + 18045

Current version CC:2022; CC 3.1 accepted under EUCC only until 31 Dec 2027

EU scheme

EUCC (Cybersecurity Act)

Operational since Feb 2025; replaced SOG-IS, transition closed Feb 2026

Assurance

EAL1–7, AVA_VAN 1–5

EUCC levels “substantial” and “high”; high requires NCCA-authorised CB/ITSEF

Recognition

EU-wide + CCRA

EUCC certificates circulate in the EU by regulation; CCRA recognition per market

Typical targets

Secure elements, smartcards, HSMs

Plus OS kernels, signature devices, network security products

Regulatory hooks

CRA critical products, eIDAS QSCD

Delegated acts can make EUCC mandatory for secure elements and HSMs

What it is

The evaluation methodology everything else borrows from

Common Criteria defines how to state security claims (security targets, protection profiles), how to evaluate them (the ISO/IEC 18045 methodology), and how to grade the effort (assurance components, packaged as EALs). Its centre of gravity is vulnerability analysis: at AVA_VAN.4/5, evaluators with insider-level knowledge attack the product using state-of-the-art techniques and rated attack potential — which is why CC at high levels remains the only widely recognised proof that hardware resists a well-funded attacker.

Since February 2025, the European home of CC is EUCC — the first scheme under the EU Cybersecurity Act. It carried over the SOG-IS technical heritage (including composite evaluation for smartcards) but changed the machinery: ISO 17065 certification bodies and ISO 17025 labs, NCCA authorisation for level “high”, ENISA-governed state-of-the-art documents, and formalised patch management and assurance continuity. The SOG-IS transition closed in February 2026; there is no other European CC route.

Two clocks are running. CC:2022 replaces CC 3.1, which EUCC stops accepting at the end of 2027 — the same month the Cyber Resilience Act fully applies, with EUCC positioned as the certification anchor for CRA critical products. Starting an evaluation today means choosing versions, levels and timing with both deadlines in view.

When it's the right tool

CC is a scalpel, not a checkbox

Use it when the product is a trust anchor

Secure elements, smartcard ICs, HSMs, QSCDs, TEEs — anything other parties build their security on. Here CC is not optional: markets, protection profiles and increasingly EU law demand it.

Use it when composition pays

A certified platform lets every downstream product reuse its claims — composite evaluation is how one chip certificate cuts cost across an entire product family and your customers’ CRA files.

Think twice for fast-moving products

Full CC on a product with quarterly releases is a losing race. Consider SESIP for IoT platforms, or fixed-time methodologies (FITCEM, CSPN) when the assurance question is narrower.

Never do it without a target strategy

The security target determines cost, duration and reusability more than the product does. Most CC budget overruns were lost in the ST, months before the lab was even chosen.

Where it matters

CC in your industry

The home turf

EUCC after SOG-IS, CC:2022 migration, AVA_VAN.5 readiness and composite evaluation — the full playbook for silicon vendors.

The wallet's foundation

EUDI wallet security composes upward from EUCC-certified hardware — WSCDs, QSCDs and the remote-signing HSM layer.

The root of device trust

Devices built on certified silicon inherit claims through composition — the cheapest assurance an IoT product can buy.

The operators' view

EUCC accreditation, NCCA authorisation for “high”, CC:2022 evaluator fluency and the capacity crunch — for those who run the machinery.

Expert notes

What we tell clients before they commit

Version and timing strategy

Any evaluation starting now should target CC:2022 unless a protection profile or composition partner forces 3.1 — in which case the completion date must clear the December 2027 sunset with margin for findings. Composite evaluations need version alignment between base and dependent certificates; check your platform vendor’s migration plan before fixing yours.

Our position: the CC 3.1 evaluations still worth starting in 2026 can be counted on one hand. If a lab proposes one without a written sunset analysis, ask why.

The Article 14 flow — 24-hour early warning, 72-hour notification, final report — via ENISA’s single reporting platform coexists with NIS2 reporting, GDPR breach notification and sector regimes. Products in the field for fifteen years, telemetry you may not have, and “actively exploited” determinations under time pressure: this is an operational capability with legal deadlines attached.

Our position: one intake, one severity model, one decision log, mapped outward to every regime’s clock. Design it once in 2026, or improvise it per incident forever.

Decades of CC, on your side of the table

Security targets, lab selection, evaluation management, certificate lifecycle — talk to people who have done all of it, under SOG-IS and under EUCC.

Contact us

Request this document

We’ll send you access by email.