Common Criteria (ISO/IEC 15408) is the international standard for formally evaluating the security of IT products. You define what your product protects and against which attacker in a security target, an independent laboratory tests that claim, and a certification body issues the certificate. Government, identity, payment, and secure-hardware buyers worldwide rely on it, and more than thirty countries recognize CC certificates under the CCRA.

The EU Cybersecurity Certification Scheme on Common Criteria (EUCC) brings a unified European approach under the EU Cybersecurity Act (Regulation (EU) 2019/881). Adopted as Implementing Regulation (EU) 2024/482 and applicable since February 2025, it supersedes SOG-IS and the national schemes, which are being phased out over a transition period. Under EUCC, assurance is expressed as substantial or high and tied to the AVA_VAN vulnerability analysis level, laboratories must be accredited and, for evaluations at high, separately authorised, and a certificate carries vulnerability management and disclosure obligations for as long as it remains valid.

Keysight's Device Security Lab in Delft, the Netherlands, is a licensed EUCC IT Security Evaluation Facility (ITSEF), accredited for evaluations at assurance levels substantial and high, with more than two decades of Common Criteria work behind it. We assess your security target, review your design and development evidence against it, identify the potential vulnerabilities in the product, and run the attack campaign that tests those claims. Your certification body receives the evaluation technical report it needs, and you get a certification strategy matched to the markets you sell into and a clear view of the obligations that follow the certificate.

eucc logo
Your Path to Certification
red icon with a grid

Scoping

We begin by defining what you are certifying and at what level: the boundary of the target of evaluation, substantial or high, whether a protection profile applies, and what you can reuse from certificates held by the layers beneath you. These choices drive your cost and timeline, and they are expensive to revisit later.

red icon with a folder

Security Target and Documentation

The security target defines what the evaluation is run against. Your design, architecture, guidance, lifecycle, and site evidence is what gets assessed. We review it early, while a gap is still a documentation fix rather than a re-spin — documentation readiness is the single biggest factor in how long an evaluation takes.

red icon with a magnifying glass

Evaluation and Evidence Assessment

Our evaluators work through the assurance requirements in scope: design, guidance, life-cycle support, testing, and your development and production site evidence. For composite products we also check that you have correctly applied the guidance from the underlying certificates.

red icon with a masked figure

Vulnerability Analysis and Testing

This is the stage where we try to break your product. Your security target claims a certain attacker cannot get in; here we play that attacker, putting in the effort your AVA_VAN level demands. The methods include side-channel analysis, fault injection, physical and invasive attacks, and logical and protocol attacks. We pick the ones that suit your product.

red icon with a certificate

Reporting and Certification

We produce the evaluation report and send it to EMVCo once you have paid the registration invoice. EMVCo reviews the report and issues your Security Evaluation Certificate, published with a SECN. We handle questions raised during the review until the report satisfies the requirements.

red icon with two circular arrows

Maintenance and Reuse

An EUCC certificate lasts up to five years, and throughout that time you have to monitor for vulnerabilities, disclose them to your certification body, and seek re-assessment when a change affects your security claims. We plan that path at the start, so renewals and new variants land in your roadmap instead of on top of a launch.

Technologies and Platforms We Evaluate

  • Secure integrated circuits, secure elements (eSE, iSE), and cryptographic libraries
  • Secure operating systems, trusted execution environments, hypervisors, and rich OS
  • JavaCard, GlobalPlatform, and native smart card platforms
  • Applets and integrated circuit cards for payment, electronic identification, authentication and trust services, ICAO travel documents, transportation, and automotive
  • Hardware security modules and hardware devices with security boxes
  • Automotive components including V2X hardware security modules
  • Connected and embedded devices that need a formal assurance claim

Working with Keysight

Focus on advancing your product while Keysight guides you through Common Criteria preparation and evaluation.

two evaluators working with software

Support at Every Step

We shape the program around your team and your budget, combining pre-evaluation, consultancy, and evaluation. Workshops, design reviews, and on-site support come with it, and the plan can shift when your dates do. We support you every step of the way, while keeping certification timelines among the fastest in the market.

engineer with magnifying glass

Access to World-Class Testing Expertise

Reaching the highest Common Criteria assurance levels requires physical attack testing. Our team is a market leader in side-channel analysis and fault injection and has been testing secure elements since 2001. We are also the company behind Inspector, the side-channel and fault injection toolset used by labs and vendors worldwide.

three engineers examining graphs

Reuse the Evidence

We also evaluate for EMVCo, GlobalPlatform, SESIP, PSA Certified, GSMA eSA, and the Cyber Resilience Act. Plan them together and one campaign can cover several schemes and several product variants, so each new version costs less to certify than the last.

Learn Resources

Frequently Asked Questions