Common Criteria and EUCC: having your product evaluated
You want to demonstrate the security of your product according to Common Criteria or in the EUCC scheme? As an evaluation facility, we carry out the product evaluation and deliver the results for certification.
BSI-recognised Common Criteria evaluation facility
DAkkS-accredited for the EUCC scope
Longest-serving evaluation facility in Germany, since 1992
Common Criteria and EUCC: an experienced crew on the way to evaluation.
Your situation
Your customers require your product to be certified according to Common Criteria or EUCC?
A tender, a public sector project or a major customer requires a certificate according to Common Criteria (ISO/IEC 15408). Since February 2025, certifications can also be started under the European EUCC scheme (EU cybersecurity certification scheme on Common Criteria) in accordance with Commission Implementing Regulation (EU) 2024/482. It is often unclear which assurance level is required, which parts of the product belong in the evaluation and which manufacturer documents still have to be produced.
For certification you have to provide a number of specific documents, above all the Security Target.
This is where we come in: with the evaluation by our evaluation facility, which has been recognised by the BSI since 1992 and is thus the longest-serving evaluation facility in Germany. The certification itself is carried out by the BSI.
Services & results
From the target of evaluation to re-certification
Your IT product is evaluated according to Common Criteria (ISO/IEC 15408) or under the European scheme EUCC (EU cybersecurity certification scheme on Common Criteria) by an evaluation facility recognised by the BSI since 1992. The documented evaluation results are the basis for certification by the BSI.
The evaluation checks whether your product implements the security functions described in the Security Target with the required assurance. The evaluation facility works according to the independence requirements of the procedure; the results go to the certification body.
01
Defining the target of evaluation and the procedure
We clarify the product and version, the intended security functions, operating conditions and the required evidence goal. The status of the Security Target and other manufacturer documents determines the evaluation schedule.
02
Evaluation by our evaluation facility
Our evaluators are trained in the criteria by the BSI and prepared for product evaluation through an internal training programme. For the vulnerability analysis, they work closely with our BSI-certified penetration testing team. We have specialised experts for the following product types:
Composite systems such as appliances consisting of hardware, operating system and application
Evaluation results for the BSI
Documented evaluation results as the basis for certification by the BSI.
03
Re-certification and patch management
Products with regular updates need a concept for maintaining the level of assurance after patches. The re-certification of genugate 11 by genua included modern patch management according to ISO/IEC TS 9569. We co-developed this approach to patch management for certified products and contributed it internationally. The head of our evaluation facility reported on first practical experience with ALC_PAM and fast-track re-certifications together with the BSI at the International Common Criteria Conference 2026 in Rome.
Our expertise
Our evaluation facility was recognised by the BSI in 1992 as an evaluation facility for “trusted systems” and is the longest-serving evaluation facility in Germany. It is recognised for evaluations according to Common Criteria and ITSEC and has been accredited by DAkkS (German national accreditation body) to ISO/IEC 17025 since the end of 2023. Since February 2025, the accreditation has met the requirements for EUCC; in addition, the BSI has granted authorisation for EUCC evaluations at assurance level “high”. DAkkS and the BSI assess the evaluation facility every 18 months.
We have supported evaluations of the genugate and genuscreen products by genua for many years, most recently the re-certification of genugate 11 according to CC 3.1 at EAL4 augmented. Further examples are the WEYTEC distribution PLATFORM WDP MX (EAL2) and the evaluation of Deutsche Telekom's SiMKo3 in preparation for its approval. Our experience includes firewalls, VPN solutions, mobile systems, healthcare products, databases and composite systems.
We contribute to the criteria themselves: the head of our evaluation facility, Sebastian Fritsch, chairs the DIN working group NA 043-01-27-03 “Evaluation criteria for IT security” and is a project leader in ISO and IEC. At “BSI im Dialog” he reported on CC:2022, and we have repeatedly spoken together with the BSI at the International Common Criteria Conference.
Getting started
Clarifying product boundaries and the intended CC/EUCC procedure
Describing security functions and product boundaries
We look at which product version and security functions are to be evaluated and which procedure your customer expects. An existing Security Target and architecture documents show where manufacturer contributions are still missing.
Agreeing on the proposal and schedule
Based on the product version, Security Target and intended assurance level, we prepare the proposal for the evaluation and align the schedule with the certification procedure.
Product boundaries and procedure clearly defined before the evaluation starts.
Independence and certification decision
The evaluation is carried out in line with the independence requirements of the procedure. The certification decision is a separate step taken by the certification body and is not anticipated by the evaluation.
Questions about Common Criteria and EUCC evaluation
What needs to be settled before a proposal for a Common Criteria evaluation?
Important are the product and version, the intended security functions, operating conditions and the required evidence goal. The status of the Security Target and other manufacturer documents influences the preparation.
Is the product evaluation already the certificate?
No. The evaluation provides documented evaluation results for the certification procedure. The responsible certification body makes the decision. The evaluation does not anticipate this decision.