Your situation

Common Criteria and EUCC: having your product evaluated

You want to demonstrate the security of your product according to Common Criteria or in the EUCC scheme? As an evaluation facility, we carry out the product evaluation and deliver the results for certification.

Free of charge and without obligation.

  • BSI-recognised Common Criteria evaluation facility
  • DAkkS-accredited for the EUCC scope
  • Longest-serving evaluation facility in Germany, since 1992
Four members of the secuvera team planning a project at a map with navigation instruments
Common Criteria and EUCC: an experienced crew on the way to evaluation.

Your situation

Your customers require your product to be certified according to Common Criteria or EUCC?

A tender, a public sector project or a major customer requires a certificate according to Common Criteria (ISO/IEC 15408). Since February 2025, certifications can also be started under the European EUCC scheme (EU cybersecurity certification scheme on Common Criteria) in accordance with Commission Implementing Regulation (EU) 2024/482. It is often unclear which assurance level is required, which parts of the product belong in the evaluation and which manufacturer documents still have to be produced.

For certification you have to provide a number of specific documents, above all the Security Target.

This is where we come in: with the evaluation by our evaluation facility, which has been recognised by the BSI since 1992 and is thus the longest-serving evaluation facility in Germany. The certification itself is carried out by the BSI.

Services & results

From the target of evaluation to re-certification

Your IT product is evaluated according to Common Criteria (ISO/IEC 15408) or under the European scheme EUCC (EU cybersecurity certification scheme on Common Criteria) by an evaluation facility recognised by the BSI since 1992. The documented evaluation results are the basis for certification by the BSI.

The evaluation checks whether your product implements the security functions described in the Security Target with the required assurance. The evaluation facility works according to the independence requirements of the procedure; the results go to the certification body.

Defining the target of evaluation and the procedure

We clarify the product and version, the intended security functions, operating conditions and the required evidence goal. The status of the Security Target and other manufacturer documents determines the evaluation schedule.

Evaluation by our evaluation facility

Our evaluators are trained in the criteria by the BSI and prepared for product evaluation through an internal training programme. For the vulnerability analysis, they work closely with our BSI-certified penetration testing team. We have specialised experts for the following product types:

  • Firewalls
  • VPN solutions
  • Smartphones
  • Mobile systems
  • eHealth components (network connectors, card terminals)
  • Android-based systems
  • Communication systems
  • Signature applications
  • Database systems
  • Healthcare systems
  • Space technology
  • Composite systems such as appliances consisting of hardware, operating system and application

Evaluation results for the BSI

Documented evaluation results as the basis for certification by the BSI.

Re-certification and patch management

Products with regular updates need a concept for maintaining the level of assurance after patches. The re-certification of genugate 11 by genua included modern patch management according to ISO/IEC TS 9569. We co-developed this approach to patch management for certified products and contributed it internationally. The head of our evaluation facility reported on first practical experience with ALC_PAM and fast-track re-certifications together with the BSI at the International Common Criteria Conference 2026 in Rome.

Our expertise

Our evaluation facility was recognised by the BSI in 1992 as an evaluation facility for “trusted systems” and is the longest-serving evaluation facility in Germany. It is recognised for evaluations according to Common Criteria and ITSEC and has been accredited by DAkkS (German national accreditation body) to ISO/IEC 17025 since the end of 2023. Since February 2025, the accreditation has met the requirements for EUCC; in addition, the BSI has granted authorisation for EUCC evaluations at assurance level “high”. DAkkS and the BSI assess the evaluation facility every 18 months.

We have supported evaluations of the genugate and genuscreen products by genua for many years, most recently the re-certification of genugate 11 according to CC 3.1 at EAL4 augmented. Further examples are the WEYTEC distribution PLATFORM WDP MX (EAL2) and the evaluation of Deutsche Telekom's SiMKo3 in preparation for its approval. Our experience includes firewalls, VPN solutions, mobile systems, healthcare products, databases and composite systems.

We contribute to the criteria themselves: the head of our evaluation facility, Sebastian Fritsch, chairs the DIN working group NA 043-01-27-03 “Evaluation criteria for IT security” and is a project leader in ISO and IEC. At “BSI im Dialog” he reported on CC:2022, and we have repeatedly spoken together with the BSI at the International Common Criteria Conference.

Getting started

Clarifying product boundaries and the intended CC/EUCC procedure

Describing security functions and product boundaries

We look at which product version and security functions are to be evaluated and which procedure your customer expects. An existing Security Target and architecture documents show where manufacturer contributions are still missing.

Agreeing on the proposal and schedule

Based on the product version, Security Target and intended assurance level, we prepare the proposal for the evaluation and align the schedule with the certification procedure.

Classify your CC/EUCC project
The points of a pair of dividers resting on coloured sticky notes above a map
Product boundaries and procedure clearly defined before the evaluation starts.

Independence and certification decision

The evaluation is carried out in line with the independence requirements of the procedure. The certification decision is a separate step taken by the certification body and is not anticipated by the evaluation.

Questions about Common Criteria and EUCC evaluation

What needs to be settled before a proposal for a Common Criteria evaluation?

Important are the product and version, the intended security functions, operating conditions and the required evidence goal. The status of the Security Target and other manufacturer documents influences the preparation.

Is the product evaluation already the certificate?

No. The evaluation provides documented evaluation results for the certification procedure. The responsible certification body makes the decision. The evaluation does not anticipate this decision.

Articles on this topic (in German)

All 11 articles on the topic (in German)

How can we plan your evaluation according to Common Criteria or EUCC?