ISO/IEC 15408:2022 Common Criteria (CC) is an international standard for evaluating the security properties of information technology (IT) products and systems. It provides a framework in which users can specify their security requirements, and manufacturers can implement and verify the security features of their products. The evaluation process is conducted by independent, accredited testing laboratories according to predefined and standardized security criteria.
The purpose of Common Criteria certification is to ensure that IT products and systems meet specific security requirements. The standard is the result of years of negotiations between various national security bodies (e.g., the USA, Canada, Germany, the UK, and other countries) and enables governments, organizations, and users to make informed decisions about the security features of IT products.
Closely linked with the ISO/IEC 15408 standard is ISO/IEC 18045, an international standard that provides guidelines for the methodology of evaluating the security of information technologies, and is associated with ISO/IEC 15408 (Common Criteria). While ISO/IEC 15408 defines the security requirements that products must meet, ISO/IEC 18045 describes how evaluators should conduct the evaluation of these security requirements.
ISO/IEC 15408 and ISO/IEC 18045 together form a comprehensive framework for the evaluation of IT product and system security, ensuring consistency and reliability in the world of computing and networks. Governments and international organizations rely on these standards as key tools to ensure the security of IT products in the global market.
As cyber threats evolve, the European Union has taken significant steps to enhance cybersecurity in its member states. A central part of this effort is the EU Cybersecurity Certification Scheme based on Common Criteria (EUCC), led by the European Union Agency for Cybersecurity (ENISA).
Launched in early 2024, the EUCC aims to create a unified security benchmark for ICT (Information and Communication Technology) products and services. This is part of a broader initiative to promote a secure and trusted digital ecosystem within the EU.