FITCEM standardises what France’s CSPN proved over fifteen years: a competent lab, a fixed time budget, a defined set of conformity and vulnerability-testing activities, and a report that says what was tested and what an attacker of a stated potential could do. EN 17640 turns that recipe into a European standard with defined evaluation tasks and attack-potential-based rigor options, so that national schemes — CSPN in France, BSZ in Germany, LINCE in Spain — rest on a common methodological floor.
The trade against Common Criteria is explicit. CC buys depth, composition and mutual recognition at the cost of duration and documentation; FITCEM buys speed and cost-predictability at the cost of narrower claims — no EALs, no protection-profile ecosystem, recognition still largely national. For a large class of products, that narrower claim is exactly the right size: the question is “does this product resist a realistic attacker”, not “can this platform anchor a decade of composite certifications”.
The strategic reason to watch FITCEM in 2026: the CRA creates demand for third-party assessment at a scale the CC world cannot serve — thousands of important products, notified bodies needing a defensible technical methodology, harmonised standards arriving late. A European, standardised, fixed-time methodology is the obvious instrument, and national schemes built on it are the obvious operational template.