We begin by defining what you are certifying and at what level: the boundary of the target of evaluation, substantial or high, whether a protection profile applies, and what you can reuse from certificates held by the layers beneath you. These choices drive your cost and timeline, and they are expensive to revisit later.
The security target defines what the evaluation is run against. Your design, architecture, guidance, lifecycle, and site evidence is what gets assessed. We review it early, while a gap is still a documentation fix rather than a re-spin — documentation readiness is the single biggest factor in how long an evaluation takes.
Our evaluators work through the assurance requirements in scope: design, guidance, life-cycle support, testing, and your development and production site evidence. For composite products we also check that you have correctly applied the guidance from the underlying certificates.
This is the stage where we try to break your product. Your security target claims a certain attacker cannot get in; here we play that attacker, putting in the effort your AVA_VAN level demands. The methods include side-channel analysis, fault injection, physical and invasive attacks, and logical and protocol attacks. We pick the ones that suit your product.
We produce the evaluation report and send it to EMVCo once you have paid the registration invoice. EMVCo reviews the report and issues your Security Evaluation Certificate, published with a SECN. We handle questions raised during the review until the report satisfies the requirements.
An EUCC certificate lasts up to five years, and throughout that time you have to monitor for vulnerabilities, disclose them to your certification body, and seek re-assessment when a change affects your security claims. We plan that path at the start, so renewals and new variants land in your roadmap instead of on top of a launch.
Focus on advancing your product while Keysight guides you through Common Criteria preparation and evaluation.
We shape the program around your team and your budget, combining pre-evaluation, consultancy, and evaluation. Workshops, design reviews, and on-site support come with it, and the plan can shift when your dates do. We support you every step of the way, while keeping certification timelines among the fastest in the market.
Reaching the highest Common Criteria assurance levels requires physical attack testing. Our team is a market leader in side-channel analysis and fault injection and has been testing secure elements since 2001. We are also the company behind Inspector, the side-channel and fault injection toolset used by labs and vendors worldwide.
We also evaluate for EMVCo, GlobalPlatform, SESIP, PSA Certified, GSMA eSA, and the Cyber Resilience Act. Plan them together and one campaign can cover several schemes and several product variants, so each new version costs less to certify than the last.
Common Criteria (ISO/IEC 15408, with the test methodology in ISO/IEC 18045) is the international standard for evaluating the security of IT products. You write down what your product protects and which attacker it should stop. An independent lab tests that claim. A certification body issues the certificate. Government, identity, payment, and automotive buyers have used it for decades.
EUCC is the European scheme for Common Criteria, set out in Regulation (EU) 2024/482 under the EU Cybersecurity Act. It has applied since 27 February 2025 and replaces the separate national schemes, which were previously linked by the SOG-IS agreement, with one scheme recognized across the EU. The standard underneath is the same. What changes is how labs are accredited, how assurance is written on the certificate, and what you owe after it is issued.
No. National schemes stopped taking new applications on 27 February 2025, and since February 2026 they can no longer issue certificates at all. Any new Common Criteria certificate in Europe is an EUCC certificate. Certificates already issued stay valid, and limited maintenance on them is still possible under the rules of the scheme that issued them.
It stays valid until it expires. When you next need a new certificate, for a new product, a new version, or a renewal, it comes from EUCC. Existing certificates can be moved across once they have been checked against what EUCC adds. The real work is usually in the new post-certificate obligations, and in any state-of-the-art documents that have changed since your original evaluation.
They map to the AVA_VAN levels. Substantial is AVA_VAN.1 and 2. High is AVA_VAN.3, 4, and 5. The difference is which attacker your product is tested against, and that changes both how deep the testing goes and who is allowed to do it. At high, the lab must be authorized by the national authority, and that authority helps issue the certificate.
Yes, in the standard and in schemes outside Europe. Under EUCC your certificate says substantial or high, tied to the AVA_VAN level, and may also carry an EAL. If your customers or procurement documents still ask for an EAL, we can help you map that onto the EUCC equivalent.
A technical domain is a shared rulebook for a product category, covering how attacks are rated and applied. EUCC keeps the two from SOG-IS: smart cards and similar devices, and hardware devices with security boxes. Certifying at AVA_VAN.4 or 5 normally means working within a technical domain or a certified protection profile, so if you are going for high, settle this early.
No, and no lab should tell you otherwise. Keysight is an accredited ITSEF: we run the evaluation and write the evaluation technical report. The certificate comes from a certification body, with the national authority also involved at high. We work with them throughout and handle the technical back-and-forth for you.
Up to five years, as long as you keep meeting the scheme's obligations. A certificate can be suspended or withdrawn if you do not, or if a serious vulnerability is found in the certified product.
This is the part most teams underestimate. You have to watch for new vulnerabilities in the certified product, handle them, report them to your certification body within the scheme's timelines, and ask for re-assessment when a change affects your security claims. Certification is no longer something you pass and file away. It is a process you need people and budget for, for five years.
It helps, but it does not cover everything. An EUCC certificate lets your product be presumed compliant with the CRA obligations a Common Criteria evaluation actually addresses, and the evidence overlaps well. It does not cover the rest of what the CRA asks of you as a manufacturer, especially technical documentation, SBOM, and reporting, including the early warning you owe when a vulnerability is being actively exploited. It is cheaper to plan both together than one after the other. See our EU Cyber Resilience Act security evaluation services.
A pre-evaluation is testing we run before the formal campaign, to find problems while they are still cheap to fix. It is not required. It is the most reliable way we know to keep a certification timeline on track, especially for a first certification or a new design.
An evaluation that builds on the certified results of the layer below instead of repeating them: a platform on a certified chip, an application on a certified platform. It is much cheaper than starting over, on one condition — your layer has to follow the guidance that came with the certificate below. When these projects run late, that is almost always the reason.
Keysight consistently delivers exceptional services for our products testing. Their deep expertise and meticulous approach provide confidence and assurance.
International Marketing Director, Tongxin Microelectronics
What are you looking for?