Common questions about AISEP
Select a topic below to learn more about Common Criteria certification, purchasing evaluated products, undertaking an evaluation and becoming an Australian Information Security Evaluation Facility.
About AISEP and Common Criteria ISO/IEC 15408
What is the Common Criteria? keyboard_arrow_down
The Common Criteria, defined in the ISO/IEC 15408 series, is an international framework for specifying and evaluating the security functionality and assurance of information technology products.
What is the difference between a certificate-authorising nation and a certificate-consuming nation? keyboard_arrow_down
A certificate-authorising nation operates a scheme that can issue Common Criteria certificates. A certificate-consuming nation recognises eligible certificates issued by authorising nations but does not issue Common Criteria certificates itself.
Where can I find AISEP policy? keyboard_arrow_down
The AISEP Policy Manual, version 6.3 explains the framework for AISEP evaluations and certifications.
What is the Information Security Manual? keyboard_arrow_down
The Information Security Manual, or ISM, is a cyber security framework that organisations can apply through their risk-management framework to protect information technology and operational technology systems, applications and data from cyber threats.
What is the difference between Common Criteria and High Assurance evaluation? keyboard_arrow_down
Common Criteria evaluations support broad government and economic use cases. ASD's High Assurance Evaluation Program evaluates products intended to protect SECRET and TOP SECRET information.
For purchasers and system owners
How can I request an AISEP evaluation? keyboard_arrow_down
An interested end-user can request an EAL-based AISEP evaluation where there is a demonstrated need for an evaluated product. The request is a non-committal indication of interest and can be submitted by the vendor as part of the AISEP acceptance package.
Learn how to request a product evaluation and access the request form.
What happens when a certificate is withdrawn or archived? keyboard_arrow_down
A withdrawn certificate is no longer represented as an active AISEP certification. Purchasers and system owners should review the reason for withdrawal; assess whether the product remains suitable for their environment; and consider replacement, remediation or other risk treatments.
Certificates are generally archived on the Common Criteria portal five years after certification. An archived certificate records that the evaluated version was certified, but does not confirm that the product remains supported, current or suitable.
Organisations should review the evaluated version, certification report, assurance-continuity status, vendor support and applicable security requirements before continued use or procurement.
Why should I consider a certified product? keyboard_arrow_down
Products certified under the internationally recognised Common Criteria framework offer more assurance in the security features and functionality within the evaluated scope. Certification provides independently assessed evidence that can support product comparison, procurement and risk decisions.
Certification does not, however, guarantee that a product is suitable for every environment. Organisations should also consider supply-chain, operational and other risks.
What should I review before purchasing a certified product? keyboard_arrow_down
Review the product's Security Target and Certification Report. These documents describe the evaluated product, security claims, evaluated configuration, scope of evaluation and conditions under which the assurance applies.
How do I confirm that a product is Common Criteria certified? keyboard_arrow_down
Check the Common Criteria portal certified products list. Products are generally moved to the archived list five years after certification.
What assurance does an AISEP-certified product provide? keyboard_arrow_down
AISEP evaluation and certification provides assurance that an independent licensed evaluation facility has examined the product’s documentation and tested the product's security functions within the scope defined by the vendor's Security Target.
What is the difference between a Protection Profile and an EAL2 evaluation? keyboard_arrow_down
An endorsed Protection Profile defines security functionality and evaluation activities for a class of products, supporting more consistent comparison between products.
For an Evaluation Assurance Level (EAL)-based evaluation, the vendor defines the product's security scope in its Security Target. AISEP accepts EAL-based evaluations up to EAL2.
Are there legal implications if an organisation does not use a certified product? keyboard_arrow_down
Legal and regulatory obligations depend on the organisation, system and operating context. Organisations should obtain advice from an appropriately qualified legal practitioner.
For product developers and vendors
How do I request a product evaluation? keyboard_arrow_down
Begin by contacting a licensed Australian Information Security Evaluation Facility (AISEF) to discuss product eligibility, evaluation scope, applicable requirements, documentation, cost and scheduling. Following suitable planning, the facility submits an AISEP Acceptance Package to the Australian Certification Authority on the vendor's behalf.
What types of evaluation are available through AISEP? keyboard_arrow_down
AISEP facilitates Common Criteria evaluations and certifications. EAL-based evaluations are available up to EAL2. Protection Profile-based evaluations are available against Protection Profiles endorsed by the Australian Certification Authority and applicable collaborative Protection Profiles listed on the Common Criteria portal.
Is a request required for an AISEP evaluation? keyboard_arrow_down
A request from an interested end-user is required for an EAL-based AISEP evaluation and can be submitted as part of the AISEP Acceptance Package. The request is a non-committal indication that the end-user is interested in the product being evaluated. Evaluations against an Australian Certification Authority (ACA) -endorsed Protection Profile do not require a request.
Who pays for an evaluation and what fees apply? keyboard_arrow_down
The vendor typically contracts directly with a licensed evaluation facility and pays the facility for its evaluation activities. Costs depend on the product, evaluation scope, applicable requirements and commercial arrangement. Contact an evaluation facility for a quotation.
How long does an evaluation take? keyboard_arrow_down
Six months is a typical planning estimate for completing an evaluation and certification. Actual duration depends on product readiness, evaluation scope, documentation quality, testing outcomes, remediation and other delays. Vendors should confirm an indicative schedule with their selected evaluation facility.
How can a developer reduce evaluation time? keyboard_arrow_down
Apply secure-by-design practices early and engage with a licensed evaluation facility before critical design decisions become difficult to change. Clear security requirements, complete documentation and well-designed security implementations can reduce avoidable delays. Developers new to Common Criteria may also consider engaging an independent specialist consultant.
How long does a Common Criteria certificate remain listed? keyboard_arrow_down
Certified products are generally listed as active on the Common Criteria portal for five years after certification and are then moved to the archived list. Product users should also consider the evaluated version, assurance-continuity status and vendor support.
What is AISEP assurance continuity? keyboard_arrow_down
Assurance continuity enables a vendor to maintain assurance following changes to a certified product through defined maintenance or re-evaluation activities. The required activity depends on the nature and security impact of the changes.
My product was certified in another country. Does it need another evaluation for Australia? keyboard_arrow_down
Eligible certificates issued by certificate-authorising participants in the Common Criteria Recognition Arrangement are generally recognised in Australia within the arrangement's scope. This typically includes EAL-based certificates up to EAL2 and eligible Protection Profile-based certificates listed on the Common Criteria portal.
Recognition does not, however, determine whether a product is suitable for a particular Australian system or environment. Organisations must undertake their own risk assessment. Vendors seeking entry to the United States NIAP Product Compliant List should refer to the NIAP website.
For evaluation facilities
How does an organisation apply to become an AISEF? keyboard_arrow_down
Email aca.certifications@defence.gov.au, marked for the attention of the ACA Manager. Annex B of the AISEP Policy Manual, version 6.3 describes the information required for an AISEF application.
What ongoing obligations apply to an AISEF? keyboard_arrow_down
An AISEF must maintain its licence agreement with the Australian Certification Authority, maintain its applicable NATA accreditation and meet all program requirements. This includes submitting quarterly reports covering matters such as staffing changes, prospective work and relevant information-security activities.
Contact the Australian Certification Authority for program and certification enquiries.
Need help with AISEP?Contact the Australian Certification Authority for program and certification enquiries. | Related resources |