As a cybersecurity solutions provider, you’re probably aware of all the advantages behind Common Criteria (CC). Besides ensuring product security claims, CC can also help you boost confidence with your end clients and set your product apart from similar, non-certified competitors.
But as cybersecurity improvements move at fleeting speed, the only way to take full advantage of these benefits is to be up to date with the latest CC version.
What effects can the latest ISO/IEC 15408:2022 and ISO/IEC 18045:2022 Common Evaluation Methodology (CEM) revisions have on your product evaluation? Keep reading for insight on the latest procedure implications, transition deadlines, and next steps.
During the ongoing transition period, both CCv3.1R5 and CC:2022 R1 are acceptable, providing clients with the flexibility to choose the version that best suits their needs, for evaluations starting no later than the 30th of June 2024.
However, Security Targets that are conformant to CC:2022, but still based on PPs certified according to CCv3.1R5, will be accepted until the 31st of December 2027.
Finally, after the 30th of June 2024, the re-evaluation and re-assessment assurance continuity activities based on CCv3.1R5 evaluations can be started for up to 2 years from the initial certification date.
Cybersecurity best practices have evolved since the earlier CCv3.1R5 implementation. But even if ISO/IEC 15408 and ISO/IEC 18045 changes seem considerable, they’re only a mere reflection of how far our cybersecurity expertise has come.
One of the main changes behind the latest CC:2022 standard is structural. Instead of three parts, it will have five.
Our Laboratory is well prepared for handling evaluations and certifications under both CCv3.1R5 and CC:2022 standards. Thanks to this, we can ensure a seamless transition for our clients, providing valuable advice and support to address any concerns or doubts regarding updates.
We are an accredited lab for SOG-IS technical domain’s evaluations up to EAL7, and experts at facilitating and expediting Common Criteria evaluations, thanks to our:
For further insight and precision into what we do, please stop by our official Cybersecurity Services or get in touch with one of our industry experts.
Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.
They allow the operation of the website, loading media content and its security. See the cookies we store in our Cookies Policy.
They allow us to know how you interact with the website, the number of visits in the different sections and to create statistics to improve our business practices. See the cookies we store in our Cookies Policy.