From initial enquiry to certification
The certification process is completed in partnership with a licensed Australian Information Security Evaluation Facility (AISEF) and under the oversight of the Australian Certification Authority (ACA).
Certification journey
A collaborative process between the vendor, AISEF and ACA to achieve independent security certification under the Australian Information Security Evaluation Program (AISEP).
Ready to begin? Find a licensed evaluation facility.
Engage an AISEF keyboard_arrow_down
- Vendor engages a licensed AISEF (evaluation facility).
- Define the product, scope, evaluation pathway and obligations.
- Agree on terms of engagement.
VENDOR + AISEF
Plan & submit the AAP keyboard_arrow_down
- Vendor provides Security Target and supporting information.
- AISEF prepares the Evaluation Work Program.
- AISEF submits the AIESP Acceptance Package (AAP) to ACA (including required sponsorship where needed).
VENDOR + AISEF
ACA accepts & opens the task keyboard_arrow_down
- AISEF submits the AAP to ACA for review.
- Upon acceptance, ACA formally opens the task.
- Task Start-up Meeting held to confirm scope, roles, schedule, confidentiality and certification requirements.
AISEF + ACA
Evaluate, test & oversee keyboard_arrow_down
- AISEF evaluates and tests the product against the applicable Common Criteria and assurance requirements.
- ACA oversees the evaluation, reviews evidence, conducts assurance activities and test witnessing (as required).
AISEF + ACA
Finalise reports & certify keyboard_arrow_down
- AISEF submits Evaluation Technical Report and supporting evidence, and publishable Security Target to ACA.
- ACA resolves issues and prepares the Certification Report.
- Vendor and AISEF may review draft for factual accuracy.
AISEF + ACA + VENDOR
Publish, close & maintain keyboard_arrow_down
- ACA publishes certification information and issues the signed certificates.
- AISEF coordinates formal task closure and final record handling.
- Ongoing changes to the product may be managed through AISEP Assurance Continuity.
AISEF + ACA
Key roles
Vendor
- Provides the product, Security Target and supporting information.
- Ensures resources, test access and timely responses to support the evaluation.
AISEF
- Australian Information Security Evaluation Facility.
- Plans, evaluates and tests the product and reports the evaluation results to ACA.
ACA
- Australian Certification Authority.
- Accepts and oversees the task, reviews evaluation evidence, witnesses testing (where required) and determines certification.
AISEP
- Australian Information Security Evaluation program.
- The Australian program under which Common Criteria product evaluations and certifications are conducted.
Together, AISEP, AISEF and ACA help build a trusted environment for secure technology in Australia.
Need help with AISEP?Contact the Australian Certification Authority for program and certification enquiries. | Related resources |