European Common Criteria-based cybersecurity certification framework, EUCC

The EUCC certification framework (European Common Criteria-based cybersecurity certification framework) is the first cybersecurity certification framework of the European Union developed under Regulation (EU) 2019/881. The framework is developed in the Implementing Regulation (EU) 2024/482 of January 31, 2024, amended by the Implementing Regulation (EU) 2024/3144 of December 18, 2024. It provides a standardized framework for assessing and certifying the security of Information and Communication Technology (ICT) products within the EU, based on the Common Criteria (CC; ISO/IEC 15408 and ISO/IEC 18045). To this end, it establishes a comprehensive set of standards, technical specifications, and procedures that will be applied throughout the Union.

The new EUCC framework, which is voluntary, promotes trust in certified products by ensuring that they meet certain security requirements, fostering interoperability and harmonization in the European market. It is a key tool for strengthening cybersecurity in the EU, supporting technological innovation, and facilitating the marketing of solutions in the European market.

Main features

1.

It is based on the Common Criteria (ISO/IEC 15408) and the Common Methodology for Evaluation (ISO/IEC 18045), which are international standards that provide a framework for assessing the security properties of Information Technology (IT) products and systems.

These criteria and methodologies ensure that evaluations are rigorous and standardized at an international level.

2.

It offers two levels of assurance: substantial and high.

The level of assurance determines the depth and rigor of the evaluation, taking into account the resistance to different threat profiles. For example, the substantial level corresponds to the assurance requirements AVA_VAN. 1 or 2, while the high level corresponds to the assurance requirements AVA_VAN. 3, 4 or 5.

3.

ICT products are certified based on their security objectives, which may incorporate certified protection profiles, if applicable.

Certification at the high assurance level must be based on the Technical Domains defined in the Framework or protection profiles adopted as state-of-the-art documents.

4.

Applicants must provide complete documentation, including the results of previous evaluations if applicable, to support the certification process.

Certification bodies will issue certificates if all conditions are met, and these certificates will include specific information detailed in Annex VII of the regulation.

5.

This allows certificates issued under the EUCC framework to be recognized in all EU member states, facilitating the free movement of certified ICT products and services.

Main actors and responsibilities

The European Cybersecurity Agency (ENISA) coordinates the development and oversight of the EUCC framework at the European level.

In the Spanish case, it is the ANCC of the National Cryptologic Center who authorizes and oversees the EUCC CABs (evaluation and conformity assessment bodies of the European Framework) and their issued certificates, and, furthermore, it also issues EUCC certificates for high level.

Within the EUCC framework, CABs are divided into:

  • They are responsible for the evaluation and certification of products, services, and processes in information and communication technologies (ICT). These bodies must ensure that evaluations are conducted in accordance with the Common Criteria and the associated evaluation methodology. Additionally, they are responsible for issuing cybersecurity certificates and maintaining detailed records of all evaluations conducted. They must also ensure that certified products meet the specified security requirements over time and that any potential vulnerabilities are adequately addressed by the applicants. These bodies must be accredited against the norm ISO/IEC 17065.
  • Laboratories (ITSEF): It is responsible for carrying out the necessary testing and analysis to assess the security of ICT products. These laboratories must follow strict procedures to ensure the accuracy and reliability of their evaluations. Furthermore, they must work closely with certification bodies, providing detailed reports on the results of their tests. Laboratories also have the responsibility to maintain the confidentiality of the evaluated information and to ensure that their operations comply with international quality and security standards. These bodies must be accredited against the norm ISO/IEC 17025.

 

They request certifications and provide appropriate technical documentation for the requested level of assurance. They are responsible for monitoring, resolving, and reporting vulnerabilities in certified products.

 

They rely on certificates to acquire secure ICT products.

 

It publishes the frameworks and oversees their harmonized implementation.

 

It accredits CABs to ensure their technical competence.

FAQ

The EUCC guidelines, the state of the art of the EUCC, and other documents related to the framework are published on the official website of the Certification Agency of the European Union for Cybersecurity (ENISA).