Publications
The member organisations of the CCRA declare that defined assurance levels (EALs) between versions of the criteria are equivalent and can therefore be used without restrictions for composition activities.
![]() CC:2022 Release 1 consists of five parts. Make sure to download and use these files. XML versions will be forthcoming: |
|||
Part 1: Introduction and general model |
![]() |
||
Part 2: Security functional requirements |
![]() |
||
Part 3: Security assurance requirements |
![]() |
||
Part 4: Framework for the specification of evaluation methods and activities |
![]() |
||
Part 5: Pre-defined packages of security requirements |
![]() |
||
CEM:2022 consists of one part: |
|||
CEM |
![]() |
||
Transition Policy to CC:2022 and CEM: 2022 |
![]() |
| |
![]() CC v3.1 R5 is the last revision of version 3.1 and may optionally be used for evaluations of Products and Protection Profiles starting no later than the 30th of June 2024. Security Targets conformant to CC:2022 based on Protection Profiles certified according to CC v3.1 will be accepted up to the 31st of December 2027. After 30th of June 2024, re-evaluations and re-assessments based on CC v3.1 evaluations can be started for up to 2 years from the initial certification date. Further details will be forthcoming. |
| ||
CC v3.1. Release 5
CC v3.1 Release 5 consists of three parts. Make sure to download and use these files: |
|||
XML | |||
Part 1: Introduction and general model |
![]() |
CC3R3.dtd | |
![]() |
|||
Part 2: Security functional requirements |
![]() |
cc3R5.XML.zip | |
![]() |
|||
Part 3: Security assurance requirements |
![]() |
||
![]() |
|||
CEM v3.1 consists of one part: |
|||
CEM |
![]() |
||
CEM |
![]() |
||
Addenda to the CC and CEM |
![]() |
||
| |||
CC v3.1. Release 4
CC v3.1 Release 4 consists of three parts. Make sure to download and use these files: |
|||
XML | |||
Part 1: Introduction and general model |
![]() |
CC3R3.dtd | |
![]() |
|||
Part 2: Security functional requirements |
![]() |
cc3R4.XML.zip | |
![]() |
|||
Part 3: Security assurance requirements |
![]() |
||
![]() |
|||
CEM v3.1 consists of one part: |
|||
CEM |
![]() |
||
CEM |
![]() |
||
Addenda to the CC and CEM |
![]() |
||
CC v3.1 Release 3 CC v3.1 consists of three parts. Make sure to download and use these files marked as "Final": |
|||
XML | |||
Part 1: Introduction and general model |
![]() |
CC3R3.dtd | |
Part 2: Security functional requirements |
![]() |
cc3R3.XML.zip | |
![]() |
|||
Part 3: Security assurance requirements |
![]() |
||
![]() |
|||
CEM v3.1 consists of one part: |
|||
CEM |
![]() |
||
CEM |
![]() |
||
|
|||
See the guides: |
|||
For previous versions of the CC and CEM please click here For unofficial versions of the CC and CEM please click here |
The following documents are CC Supporting Documents. Supporting documents are used within the Common Criteria certification process to define how the criteria and evaluation methods are applied when certifying specific technologies. They replace multiple individual interpretations and hence provide clarity for developers, evaluators, and users. Their relevance and use for particular technologies is approved through an external approval process in which all CCRA members have input.
There are two classes of CC Supporting documentation:
- Those which are termed 'Mandatory Supporting Documents' are required to have been applied when a product involving the particular technology is certified in order to support mutual recognition.
- Those which are termed 'Guidance Supporting Documents' contain more general advice.
For more information see the CCRA Procedure for Supporting Documents.
CCRA Supporting Documents
Document Number | Title |
CCDB-2015-01-004 | Full Drive Encryption: Encryption Engine |
CCDB-2015-01-003 | Full Drive Encryption: Authorization Acquisition |
CCDB-2015-01-002 | Evaluation Activities for Stateful Traffic |
CCDB-2015-01-001 | Evaluation Activities for Network Device cPP |
CCDB-2008-09-002 | Characterizing Attacks to Fingerprint Verification Mechanisms |
Collection of Developer Evidence | |
Evaluation methodology for product series, v1.0 | |
2002-08-009 | Reuse of Evaluation Results and Evidence |
CCDB-011-v2.2-2021-Sep-30 | Assurance Continuity |
CCDB-012-v1.0-2021-Sep-30 | Certificate Validity |
2004-07-001 | Conducting Shadow Certifications |
2005-06-021 | Conducting Voluntary Periodic Assessments of Schemes Participating in the CCRA |
CCDB-2006-04-004 | ST sanitising for publication |
CCDB-2007-11-001 | Site Certification |