Your situation

BSZ: Accelerated Security Certification for IT products

You are a manufacturer and want to demonstrate the security of your IT product – without lengthy preparation? The Accelerated Security Certification (BSZ) offers you a clear, practical and lean approach.

Free of charge and without obligation.

  • BSI-recognised BSZ evaluation facility
  • BSI-recognised Common Criteria evaluation facility
Dividers fixing a position on the world map
Accelerated Security Certification: a fast and robust course to BSZ evidence.

Your situation

You want to prove the security of your IT product with a BSI certificate – without a full Common Criteria evaluation?

Your customers ask for independent security evidence for your IT product. A Common Criteria certification, however, requires a number of specific manufacturer documents and corresponding lead time. What you need is a procedure that works with the product itself and still ends with a certificate from the BSI.

The Accelerated Security Certification (BSZ) of the BSI aims to keep the effort for the manufacturer to a minimum. All that is needed is the product and a Security Target. In short, the BSZ is a high-quality product penetration test: it checks whether your product is free of security flaws. After the application, testing takes about two to three months.

Our BSI evaluation facility has been recognised for BSZ evaluations since 1 December 2022. It combines the experience of an evaluation facility recognised by the BSI since 1992 with our BSI-certified penetration testing team. Whether BSZ, Common Criteria or another form of evidence fits your product, we clarify in our consulting for product manufacturers.

Services & results

From pre-evaluation to BSI certificate

You enter a lean BSI procedure with your product and a Security Target: the evaluation covers conformity with the Security Target, robustness by means of penetration testing and the implemented cryptography. After the application, testing takes about two to three months. A pre-evaluation shows you beforehand where your product stands; our evaluation facility has been recognised for the BSZ since 1 December 2022.

The BSZ focuses on the technical security robustness of the product. The BSI decides on the result; our task as the evaluation facility is a robust, traceable evaluation.

Security Target and pre-evaluation

The basis of the BSZ is the Security Target, which describes the security properties to be evaluated and usually has to be written first.

Before the actual procedure, we offer a pre-evaluation of your product. It makes the certification procedure easier and reduces risks in the process.

Evaluation in the BSZ procedure

After the application, we carry out the tests over a period of about two to three months. As a BSZ evaluation facility, we evaluate, among other things:

  • Conformity of the product with the Security Target
  • Robustness of the product by means of penetration tests and detailed analyses
  • Correctness of the implemented cryptography
  • Correctness of the installation guide

Decision and certificate by the BSI

The BSI makes the final decision on whether the evaluation was successful. If the result is positive, the BSI issues the certificate.

BSZ certificate from the BSI

If the result is positive, the manufacturer receives the certificate.

After certification

With the certificate, you as the manufacturer commit to continue monitoring the product for new vulnerabilities and to provide updates.

Our expertise

Since 1 December 2022, our BSI evaluation facility has been officially recognised for evaluations under the Accelerated Security Certification. The evaluation facility itself has been recognised by the BSI since 1992; we have been evaluating IT products in cooperation with the BSI since 1991.

For the BSZ, the quality of the penetration tests is what counts most. Product Security therefore works closely with our penetration testing business unit, which the BSI has certified as an IT security service provider for IS penetration testing since 2013. We also use the experience from black-box product evaluations for component evaluations according to IEC 62443-4-2.

The head of our evaluation facility, Sebastian Fritsch, also explains how BSZ, Common Criteria and IEC 62443 relate to each other in the training course “Rechtskonform: IT-Produkte prüfen und zertifizieren” (in German) at heise conferences.

Getting started

Discussing BSZ suitability and the benefit of a pre-evaluation

Matching the Security Target with the product

Describe the security functions, product status and planned use. We clarify which documents and access are available for the BSZ evaluation and whether a technical pre-evaluation before the procedure makes sense.

Clarifying the BSZ process in the introductory workshop

A free technical workshop offers room for questions about the product evaluation and your manufacturer contributions. In particular, we discuss the preparation of the Security Target and the roles of the evaluation facility and the BSI.

Prepare your BSZ evaluation
An open brass compass lying in a hand in front of a world map and sticky notes
Your product's suitability realistically assessed in advance.

Monitoring vulnerabilities after the BSZ

The manufacturer commits to continue monitoring the product for new vulnerabilities afterwards and to provide updates.

Questions about the Accelerated Security Certification

Which documents do we need for a BSZ?

The essential basis is the product and the Security Target. The installation guide is also evaluated. Which further manufacturer documents, access and prerequisites your procedure requires is clarified for the specific product.

What is a BSZ pre-evaluation for?

A pre-evaluation examines the product before the certification procedure. It can reveal technical or documentation gaps that your team still needs to address. This reduces risks later in the process; it does not promise a certificate.

Who issues the BSZ certificate and what happens afterwards?

The BSI decides on the success of the evaluation and on certification. As the manufacturer, you commit to continue monitoring the product for new vulnerabilities and to provide updates. This product maintenance remains a separate task.

How long does a BSZ evaluation take?

After the application, we carry out the tests over a period of about two to three months. A pre-evaluation before the procedure can reveal open points early and reduce risks in the process.

How does the BSZ differ from a Common Criteria certification?

The BSZ is a penetration-test-driven security analysis overseen by the BSI; it essentially requires the product and a Security Target. Common Criteria is the internationally standardised evaluation standard (ISO/IEC 15408), whose certificates are accepted across Europe and worldwide, and requires more extensive manufacturer documents. We discuss which route fits in the free workshop.

Articles on this topic (in German)

All 6 articles on the topic (in German)

How can we support you with BSZ certification?