Common Criteria definition
Examples of Common Criteria in a sentence
A hardware crypto module with a unit design form factor certified as conforming to at least FIPS 140 Level 2, Common Criteria EAL 4+, or equivalent.
Another type of hardware storage token with a unit design form factor of SD Card or USB token (not necessarily certified as conformant with FIPS 140 Level 2 or Common Criteria EAL 4+).
Provisioned Secure Storage Subsystems shall be built on hardware which carries a valid certificate according to Common Criteria Protection Profile: o EAL4+ using PP0109 or o EAL4+ using PP Automotive-Thin TPM ANSSI-CC-PP-2019/02 or later or o EAL4+ using PP TPM ANSSI-CC-PP-2018/03 or ANSSI-CC-PP-2020/01 or later, or o Dedicated Security Components - DSC cPP (collaborative Protection Profile) v1.0 & SD (Supporting Document) v1.0. Serial number in this text means “certificate serial number”.
These may include accreditation under the relevant national implementation of ISO/IEC 17025 (Criteria for the competence of testing and calibration laboratories), ISO 9000 (Quality management systems), ISO 15408 (Common Criteria for IT security evaluations) or other similar international, national, or industry standards.
Firewall shall be tested and certified for ISO15408 Common Criteria for least EAL4+.
Effective April 24, 2023, for Non-EV and EV Code Signing Certificates: Subscriber represents that Subscriber will use one of the following options to generate and protect their Code Signing Certificate Private Keys in a Hardware Crypto Module with a unit design form factor certified as conforming to at least FIPS 140‐2 Level 2 or Common Criteria EAL 4+: • Subscriber uses a Hardware Crypto Module meeting the specified requirement.
The Common Criteria Certificate must display BSI-CC-PP-0035-2007 / BSI-CC-PP-0084-2014 (or newer) Protection Profile.
The Private Key must be stored in a type of hardware storage token with a unit design form factor of SD Card or USB token (not necessarily certified as conformant with FIPS 140 Level 2 or Common Criteria EAL 4+).
Each Participant is to provide to each of the other Participants a copy of each Common Criteria or ITSEC certificate, Certification Report and Certified Products List it authorises.
If a CB wishes to achieve the status of compliant CB under this Agreement for IT technical domains including higher assurance levels (including augmentations) than the Common Criteria Evaluation Assurance Level 4 or ITSEC Assurance Level E3, it should submit an application in writing through the Participant in its country to the Management Committee.