Formalized as ISO/IEC 15408, Common Criteria (CC) defines a hierarchical framework of security concepts and terminology. The CC defines an evaluation assurance level (EAL) that specifies predefined sets of security assurance components that may be referenced in Protection Profiles (PPs) and Security Targets (STs). These also specify the appropriate security assurances to be provided to a target of evaluation (TOE).
Under an EAL, there are seven levels that offer progressively greater certainty. From February 2026 onwards, EALs will no longer be used as a result of the implementation of the EU Cybersecurity Certification Scheme on Common Criteria (EUCC). Instead, vulnerability analysis (AVA_VAN) levels will be used to determine the assurance level for certification; levels up to two will be classified as “Substantial” and levels above that as “High.”
The European Commission established the EUCC under the legal framework of the EU Cybersecurity Act in order to harmonize the European framework for the EU cybersecurity certification of information and computer technology (ICT) goods, services and procedures. The CC also defines the PP construct, which is a product category-specific but product-agnostic requirements template. This allows prospective consumers, developers and regulatory groups to create standardized sets of security threats, objectives, requirements and assurance measures.
The TOE can be part of the product or system that is subject to evaluation if it complies with or refers to a PP. The ST contains the product-specific instantiation along with a summary specification of how the TOE satisfies the Security Functional Requirements (SFRs) and is used by the evaluators as the basis for evaluation.
The Common Criteria Recognition Agreement (CCRA) is an international cooperative agreement in which participating government organizations verify that certification bodies issuing CC certificates consistently meet the conditions for mutual recognition and all applicable standards.