Common Criteria (CC)
Common Criteria (ISO/IEC 15408): security certification of IT products against a protection profile, rated EAL1-7. Used for QSCDs and HSMs.
Common Criteria (ISO/IEC 15408) is the international framework for security evaluation of IT products. An accredited lab (an ITSEF) evaluates a product against a Security Target, which may follow a protection profile (predefined security requirements for a product class) or be vendor-specific, at an assurance level (EAL1-7). The EAL reflects the depth and rigour of the evaluation, not the raw strength of the product, and a certificate covers only the exact product version and configuration tested. Certificates are mutually recognised globally under the CCRA (capped at EAL2 or agreed collaborative protection profiles) and, for higher levels, across European countries under SOG-IS and its EU successor scheme, EUCC, established under the Cybersecurity Act.
In the trust-services world CC is everywhere: HSMs used for qualified trust services are certified against EN 419 221-5, QSCDs against protection profiles such as EN 419211 (referenced in eIDAS Implementing Decision (EU) 2016/650), and the secure elements of the EUDI Wallet (WSCD) are expected to follow the same route, through the certification schemes being worked out under Implementing Regulation (EU) 2024/2981. Qualified status leans on these certificates as hard evidence.