Common Criteria
What is Common Criteria?
An international standard (ISO/IEC 15408) for computer security certification that provides a framework for evaluating the security properties of IT products. Common Criteria evaluations are mutually recognised by 31 countries.
Terms that appear alongside common criteria
Each of these is named in at least one of the same controls as common criteria. The number is how many controls name both.
- cybersecurity 3 shared controls
- certification 2 shared controls
- iso 27001 2 shared controls
- compliance 2 shared controls
Frameworks that govern common criteria
What the standards actually require on common criteria
Requirements naming common criteria across 5 standards, quoted from the control text.
Mobile Device Management solutions that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Management, version 4.0 or later, are used to enforce mobile device management policy.
ISM-1195 · Mobile Device Management solutions that have completed a Common Criteria evaluation agains →Common Criteria 1 to 9 establish baseline security covering control environment, communication, risk, monitoring, and operations.
SOC3-SECURITY · Common Criteria Security →Article 15 requires competent authorities and the Commission to perform risk analyses on CBAM declarations and on declarant compliance, using common criteria, and to share results across Member States and with customs/tax/anti-fraud authorities.
CBAM-Art.15 · Risk analysis by competent authorities and the Commission (Article 15) →NSS-17 + NSS-42-G require supply chain + third party + OEM security across CBS lifecycle. Vendor due diligence: cyber maturity assessment + ISO 27001 / IEC 62443 / IEC 27036 alignment + cybersecurity governance + secure development + incident history + foreign...
IAEA-NSS17-SupplyChain-ThirdParty-OEM-Trust · IAEA NSS-17 - Supply Chain + Third Party + OEM + Vendor Security + Trustworthy Components →Lebanon Law 81/2018 Articles 15-25 + LB81-2 + LB81-3 Electronic Signature and Trust Services. Article 15-19 Electronic Signature Validity - electronic signatures recognised with same legal effect as handwritten signatures provided meeting requirements: (a) uni...
LB81-Electronic-Signature-Validity-Certified-Providers-Articles-15-25-LB81-2-3-Trust-Services · Lebanon Law 81/2018 Electronic Signature Validity + Certified Providers + Articles 15-25 →Questions people ask about common criteria
What is Common Criteria?
Why is Common Criteria important for compliance?
Which compliance frameworks address Common Criteria?
Where can I learn more about Common Criteria?
See how Common Criteria applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.