Independent assurance supports better decisions and stronger capability
AISEP certification provides independently assessed evidence about the security functionality of an information and communications technology product. Evaluation using international Common Criteria scheme can help organisations understand what was tested, the assurance achieved and the conditions under which that assurance applies.
Why certification matters
Product security claims can be difficult to compare across complex technologies and global supply chains. AISEP certification provides structured evidence that can support procurement, product development, system design and risk-management decisions.
Certification does not, however, remove risk or guarantee that a product is suitable for every environment.
Evidence for informed decisions
Certification provides a security target, certification report and defined evaluated configuration. These documents help purchasers compare security claims and understand the scope and limitations of the evaluation.
Independent security assurance
Evaluation is performed by a licensed Australian Information Security Evaluation Facility under the oversight of the Australian Certification Authority, providing evidence independent of the product developer.
Support for government and business
Evaluated products can support procurement, architecture and deployment decisions where organisations need credible evidence about defined product security functionality.
Opportunity for product developers
Certification can strengthen the credibility of product security claims and support engagement with government, critical-infrastructure, international and security-conscious markets.
International recognition
Eligible certificates can be recognised by participants in the Common Criteria Recognition Arrangement, reducing the need to duplicate evaluations in multiple participating countries.
Australian sovereign capability
AISEP supports Australian evaluation laboratories, specialist product-security expertise and Australia’s participation in international security-assurance standards.
Using certification effectively
- Confirm that the certified product version matches the version being considered.
- Review the security target to understand the evaluated security claims and assumptions.
- Review the certification report for the evaluation scope, findings and conditions of use.
- Use the product in its evaluated configuration and supported operational environment.
- Consider supply-chain, integration, deployment, maintenance and residual risks.
- Check certificate status, vendor support and any assurance-continuity or flaw-remediation arrangements.
AISEP certification is not an endorsement, guarantee or warranty of a product. Organisations remain responsible for determining whether a product is suitable for their requirements and risk environment.
Need help with AISEP?Contact the Australian Certification Authority for program and certification enquiries. | Related resources |