atsec Becomes the First Accredited EUCC Conformity Assessment Body

atsec is thrilled to announce it is the first accredited conformity assessment body (CAB) for the new EU Common Criteria (EUCC) certification scheme! With this accreditation, atsec can provide certifications and evaluations for both the Substantial and High1 assurance levels, as well as offer post-certification compliance support.

This is a major milestone, as the EUCC represents an evolution in cybersecurity regulations in the EU and a crucial requirement for ICT product manufacturers, given it provides a harmonized approach to security certification across the region.

atsec is a Conformity Assessment Body that provides both Information Technology Security Evaluation Facility (ITSEF) and Certification Body (CB) services, resulting in a seamless end-to-end EUCC certification process for manufacturers.

By offering both evaluation and certification, we eliminate unnecessary complexity and streamline the certification journey for manufacturers.

As you consider EUCC certification, here’s an overview of the four-step process to receive one: 

  1. Determine the Required Assurance Level
    • Substantial – cover vulnerability analysis at AVA_VAN level 1 or 2. 
    • High – cover vulnerability analysis AVA_VAN level 3, 4 or 5. 
  2. Prepare Security Documentation
    Each assurance level has requirements for security documentation, including providing guidance documentation, development & lifecycle evidence, test documentation. The manufacturers will need to provide the Security Target (ST) which can claim compliance to a Protection Profile (PP).
  3. Conduct Independent Evaluation
    The EUCC-approved ITSEF performs evaluation of your product against security assurance requirements defined in the ST. This includes: 
    • Vulnerability Analysis & Penetration Testing
    • Functional Testing
    • Evaluating design and guidance documentation
  4. Certification
    Once the evaluation is completed, the EUCC-approved CB issues an EUCC certificate, allowing your product to be recognized across the EU market.

It’s important to note that EUCC certification is not a one-time process—manufacturers must maintain security compliance after certification. Certificate holders are required to:

  • Provide security guidance for end users to ensure secure configuration, installation, operation, and maintenance of the certified product.
  • Commit to providing security updates and defining the period during which security updates and cybersecurity-related patches will be provided to end users. 
  • Establish a vulnerability disclosure process and maintain clear contact information and procedures for receiving vulnerability reports from end users and security researchers.
  • Monitor and address publicly disclosed vulnerabilities and to reference online vulnerability repositories as well as respond to security advisories related to the certified product.

Failure to meet these requirements could impact the validity of the EUCC certificate.

Details for atsec’s accreditation and approvals can be found on our certificates page.

For more information about our EUCC services, please visit the CC evaluation and CC certification pages on our website.

1.The authorization process with the National NCCA is ongoing. ↩︎

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值