Standard & Scheme · General Purpose

FITCEM — fixed-time evaluation, European standard

EN 17640 answers the question the CC world couldn't: how do you get credible third-party evaluation in weeks, at predictable cost? It is the methodology under Europe's lightweight national schemes — and a serious candidate for the CRA's evaluation workhorse.

At a glance

Owner

CEN/CENELEC

European standard, published 2022 (FIT-CEM: fixed-time cybersecurity evaluation methodology)

Type

Evaluation methodology

Not a scheme itself — schemes adopt and parameterise it

Core idea

Time-boxed evaluation

Fixed evaluator effort, defined activities, conformity + penetration testing

Built on it

CSPN, BSZ, LINCE lineage

France, Germany and Spain’s first-level schemes align with or map to it

Duration

Weeks, not years

Typical engagements measured in tens of evaluator-days

Regulatory hooks

CRA evaluation gap

Prime candidate methodology where the CRA needs scalable third-party assessment

What it is

Assurance priced like engineering, not like a moonshot

FITCEM standardises what France’s CSPN proved over fifteen years: a competent lab, a fixed time budget, a defined set of conformity and vulnerability-testing activities, and a report that says what was tested and what an attacker of a stated potential could do. EN 17640 turns that recipe into a European standard with defined evaluation tasks and attack-potential-based rigor options, so that national schemes — CSPN in France, BSZ in Germany, LINCE in Spain — rest on a common methodological floor.

The trade against Common Criteria is explicit. CC buys depth, composition and mutual recognition at the cost of duration and documentation; FITCEM buys speed and cost-predictability at the cost of narrower claims — no EALs, no protection-profile ecosystem, recognition still largely national. For a large class of products, that narrower claim is exactly the right size: the question is “does this product resist a realistic attacker”, not “can this platform anchor a decade of composite certifications”.

The strategic reason to watch FITCEM in 2026: the CRA creates demand for third-party assessment at a scale the CC world cannot serve — thousands of important products, notified bodies needing a defensible technical methodology, harmonised standards arriving late. A European, standardised, fixed-time methodology is the obvious instrument, and national schemes built on it are the obvious operational template.

When it's the right tool

Right-sized assurance, chosen deliberately

Use it when the claim is product-level resistance

Firewalls, VPN gateways, IoT devices, software products — where a time-boxed expert attack answers the buyer’s actual question at a tenth of CC cost.

Use it as the fast lane in a national market

CSPN opens doors in France (including toward ANSSI qualification); BSZ increasingly plays that role in Germany. Know which national flavour your market reads.

Use it to pre-position for the CRA

A FITCEM-based evaluation exercises exactly the muscles CRA assessment will demand — documented security functions, vulnerability handling, penetration test evidence.

Don't use it where composition is the point

Secure elements, platforms others certify on top of, products needing international recognition — that is CC/EUCC or SESIP territory, by design.

Where it matters

FITCEM in your industry

The volume market

Connected products facing RED and CRA obligations are FITCEM’s natural constituency — credible evaluation at product-economics cost.

The wallet's foundation

EUDI wallet security composes upward from EUCC-certified hardware — WSCDs, QSCDs and the remote-signing HSM layer.

The methodology bet

Labs building CRA-era capacity and schemes needing a standardised evaluation engine are both, in practice, making a FITCEM decision.

Software products in the stack

Security software and virtualisation components serving French and German markets meet CSPN/BSZ expectations built on this methodology.

Expert notes

What we tell clients before they commit

Fixed time only works with a fixed target

The methodology’s honesty depends on scoping discipline: a well-defined security problem, a testable product configuration, and documentation the lab can consume on day one. Vendors who arrive with vague claims burn half the time budget on scoping — inside the evaluation clock. The preparation the methodology doesn’t mandate is precisely what determines whether its verdict is useful.

Our position: spend two weeks preparing before the clock starts — security rationale, configuration freeze, evidence pack. It converts fixed-time evaluation from a gamble into a measurement.

FITCEM-family certificates are national instruments; there is no CCRA equivalent. What exists is methodological convergence — EN 17640 makes a CSPN, a BSZ and a LINCE report structurally comparable, which eases second-market acceptance case by case, and positions the family for whatever European mechanism the CRA era produces. Betting a multi-country strategy on automatic recognition today would be premature; ignoring the convergence would be equally wrong.

Our position: pick the national scheme where your revenue is, structure the evidence to EN 17640 so the second market is a delta, not a redo. That is the cheap option now and the CRA-ready option later.

Right-sized evaluation, prepared properly

Scheme selection, scoping, evidence preparation, lab liaison — thirty minutes to see if fixed-time is your fast lane.

Contact us

Request this document

We’ll send you access by email.