Skip to content

Common Criteria

What is Common Criteria?

An international standard (ISO/IEC 15408) for computer security certification that provides a framework for evaluating the security properties of IT products. Common Criteria evaluations are mutually recognised by 31 countries.

Compliance

Each of these is named in at least one of the same controls as common criteria. The number is how many controls name both.

What the standards actually require on common criteria

Requirements naming common criteria across 5 standards, quoted from the control text.

Mobile Device Management solutions that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Management, version 4.0 or later, are used to enforce mobile device management policy.

ISM-1195 · Mobile Device Management solutions that have completed a Common Criteria evaluation agains
AICPA SOC 31 control

Common Criteria 1 to 9 establish baseline security covering control environment, communication, risk, monitoring, and operations.

SOC3-SECURITY · Common Criteria Security

Article 15 requires competent authorities and the Commission to perform risk analyses on CBAM declarations and on declarant compliance, using common criteria, and to share results across Member States and with customs/tax/anti-fraud authorities.

CBAM-Art.15 · Risk analysis by competent authorities and the Commission (Article 15)

NSS-17 + NSS-42-G require supply chain + third party + OEM security across CBS lifecycle. Vendor due diligence: cyber maturity assessment + ISO 27001 / IEC 62443 / IEC 27036 alignment + cybersecurity governance + secure development + incident history + foreign...

IAEA-NSS17-SupplyChain-ThirdParty-OEM-Trust · IAEA NSS-17 - Supply Chain + Third Party + OEM + Vendor Security + Trustworthy Components

Lebanon Law 81/2018 Articles 15-25 + LB81-2 + LB81-3 Electronic Signature and Trust Services. Article 15-19 Electronic Signature Validity - electronic signatures recognised with same legal effect as handwritten signatures provided meeting requirements: (a) uni...

LB81-Electronic-Signature-Validity-Certified-Providers-Articles-15-25-LB81-2-3-Trust-Services · Lebanon Law 81/2018 Electronic Signature Validity + Certified Providers + Articles 15-25

Questions people ask about common criteria

What is Common Criteria?
An international standard (ISO/IEC 15408) for computer security certification that provides a framework for evaluating the security properties of IT products. Common Criteria evaluations are mutually recognised by 31 countries.
Why is Common Criteria important for compliance?
Common Criteria is a key concept in Compliance. Understanding common criteria helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Common Criteria?
Common Criteria appears in the requirement text of Australian Information Security Manual, AICPA SOC 3, EU Carbon Border Adjustment Mechanism (CBAM), IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1), Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018). Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Common Criteria?
Explore our compliance framework pages to see how common criteria applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Common Criteria applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.