Common Criteria
Common Criteria is an international standard, formally published as ISO/IEC 15408, used to evaluate the security features and trustworthiness of information technology products. It provides a common framework so that buyers, developers, and evaluators can describe and test what security a product is meant to provide and how thoroughly that has been checked. It is a voluntary standard rather than a law, though its results may be required under certain government or contractual procurement arrangements.
Common Criteria (CC), formally designated ISO/IEC 15408, is an international standard and associated certification scheme for evaluating the security functionality and assurance of IT products. Within its framework, security needs are expressed as Security Functional Requirements (SFRs) and Security Assurance Requirements (SARs), and evaluations establish a corresponding Evaluation Assurance Level reflecting the rigor of the assessment. It is a voluntary product-security standard rather than binding regulation, and while it supports a model of mutual recognition of certification results across participating parties, its specific applicability, recognized scope, and current version should be verified against the latest authoritative CC and ISO/IEC 15408 texts. The standard defines a framework and criteria for evaluation; it is distinct from any single jurisdiction's legal mandate, and its use in a given context (for example, government or critical-infrastructure procurement) depends on contractual or policy requirements rather than the standard itself.
Why it matters
Common Criteria matters because it provides a shared, structured language for describing and verifying the security of IT products, allowing buyers, developers, and independent evaluators to work from a common reference rather than ad hoc or vendor-defined claims. For organizations procuring security-sensitive technology, a Common Criteria evaluation offers a documented basis for assessing what security a product is intended to provide and how rigorously that has been checked, which can reduce reliance on unverified marketing assertions. This is particularly significant in contexts such as government or critical-infrastructure procurement, where evaluation results may be required under contractual or policy terms.
It is important to keep Common Criteria in proper perspective: it is a voluntary product-security standard, not a law. A Common Criteria certificate is not the same as regulatory compliance, and being certified does not by itself satisfy obligations under any particular jurisdiction's legal regime. Its relevance in a given situation flows from procurement requirements, contracts, or organizational policy rather than from the standard carrying legal force on its own.
Because Common Criteria supports a model of mutual recognition across participating parties, a certification issued under the scheme may be accepted by multiple procurement authorities, which can reduce duplicative evaluation effort. However, the recognized scope of any certificate, the assurance level it reflects, and the current version of the standard all vary and should be verified against the latest authoritative Common Criteria and ISO/IEC 15408 texts rather than assumed.
Who it's relevant to
Inside CC
Common questions
Answers to the questions practitioners most commonly ask about CC.
