Skip to main content
Category: CMMC & DIB Assessment

Common Criteria Evaluation and Validation Scheme

Also known as: CCEVS, U.S. Common Criteria Evaluation Scheme, NIAP CCEVS
Simply put

The Common Criteria Evaluation and Validation Scheme (CCEVS) is the U.S. program that provides government oversight, or 'validation,' of Common Criteria security evaluations of information technology products. It is implemented under the National Information Assurance Partnership (NIAP) so that products tested in the United States conform correctly to the international Common Criteria standard. Independent, accredited testing laboratories perform the evaluations, and validated products are listed on a compliance list that agencies can consult.

Formal definition

CCEVS is the U.S. evaluation scheme implemented under NIAP to meet the requirements of the Common Criteria and to provide governmental validation of Common Criteria (CC) evaluations, ensuring correct conformance to the applicable CC methodology and Protection Profiles. Under CCEVS, accredited Common Criteria Testing Laboratories (CCTLs) conduct product evaluations, and NIAP validators oversee the process and issue validation of the results, with validated products placed on the Product Compliant List. The scheme operates within the framework of the Common Criteria Recognition Arrangement (CCRA), whose status, certification schemes, licensed laboratories, and certified products are tracked through the Common Criteria portal. Practitioners should verify current governance and operational responsibilities, including the roles assigned to NIAP and to NIST-related accreditation functions, against current NIAP Scheme publications and official sources, as these arrangements and the underlying evaluation requirements evolve over time. This entry does not address the specific procedural, contractual, or accreditation details a reader must confirm in current authoritative CCEVS and CCRA documentation.

Why it matters

For federal agencies and their vendors, CCEVS provides a government-validated basis for trusting that a commercial IT product's security functionality has been independently evaluated against the international Common Criteria standard rather than relying on a manufacturer's own claims. Validated products appear on the Product Compliant List (PCL) maintained under NIAP, which acquisition officials and system owners can consult when selecting components for national security systems and other environments where NIAP-evaluated products are expected. This matters because procurement policy in some defense and national security contexts directs acquisition of products from the PCL where a suitable evaluated product exists, making CCEVS validation a practical gating factor for market access.

Who it's relevant to

Product vendors and manufacturers
IT product developers seeking to sell into federal, defense, and national security markets rely on CCEVS validation to demonstrate that their products have been independently evaluated and to earn placement on the Product Compliant List. Vendors should confirm the applicable Protection Profile and current evaluation requirements before engaging a CCTL, and should understand that validation applies to a specific evaluated configuration.
Acquisition and procurement officials
Personnel responsible for acquiring IT products for government systems use the Product Compliant List to identify NIAP-validated products. They should verify whether applicable procurement policy directs selection of validated products for their specific environment, and confirm current guidance rather than assuming validation requirements are uniform across all federal, civilian, defense, and national security contexts.
System owners and authorizing officials
Those responsible for system security and authorization decisions should recognize that CCEVS validation supports, but does not replace, separate authorization processes such as the Risk Management Framework. A validated product must be deployed in its evaluated configuration to preserve the assurance the validation represents, and validation should not be treated as equivalent to an authorization to operate.
Common Criteria Testing Laboratories
Accredited CCTLs perform the technical evaluations under CCEVS and operate under the oversight of NIAP validators. Laboratories should confirm their current accreditation status and the applicable evaluation methodology, and track the licensing and certification information published through the Common Criteria portal.
Compliance officers and auditors
Practitioners verifying whether deployed products meet applicable evaluation expectations can use the Product Compliant List as a reference point, while confirming current CCEVS and CCRA governance against official NIAP Scheme publications. They should flag the common error of treating Common Criteria validation as a general certification of security or as a substitute for ongoing continuous monitoring and authorization obligations.

Inside CCEVS

National Information Assurance Partnership (NIAP)
The U.S. government body under which CCEVS operates. NIAP is managed operationally by the National Security Agency (NSA). While NSA leads day-to-day operation of the scheme, NIST retains certain statutory responsibilities related to standards and laboratory accreditation; practitioners should verify the current division of roles against official NIAP and NIST publications, as governance descriptions have changed over time.
Common Criteria Testing Laboratories (CCTLs)
Accredited commercial laboratories that perform the security evaluations of information technology products under CCEVS. These laboratories are accredited through the NIST National Voluntary Laboratory Accreditation Program (NVLAP), reflecting NIST's continuing operational role in the scheme.
Protection Profiles (PPs)
Standardized sets of security requirements for a category of products against which evaluations are generally conducted. In current U.S. practice, NIAP emphasizes evaluation against approved Protection Profiles rather than assigning generalized assurance levels alone.
Common Criteria (ISO/IEC 15408)
The international standard for IT security evaluation on which CCEVS is based. CCEVS applies this standard within the U.S. national scheme; readers should confirm the applicable version and any national interpretations against authoritative sources.
Validation and Certification Outputs
Products that successfully complete evaluation are placed on the NIAP Product Compliant List (or equivalent published listing). This validation attests that a product was evaluated against specified requirements and does not, by itself, constitute an authorization to operate the product on a given system.

Common questions

Answers to the questions practitioners most commonly ask about CCEVS.

Is CCEVS operated jointly by NIST and NSA, or is it run by NSA alone?
Neither characterization is fully accurate. The National Information Assurance Partnership (NIAP), which operates CCEVS, is managed operationally by the National Security Agency (NSA). However, the National Institute of Standards and Technology (NIST) retains a continuing role: NIST's National Voluntary Laboratory Accreditation Program (NVLAP) accredits the Common Criteria Testing Laboratories that perform evaluations under the scheme. NIST also has responsibilities associated with statutory authorities related to information security. Readers should treat older references describing CCEVS as 'jointly operated' day-to-day by NIST and NSA as reflecting an earlier governance arrangement, and should verify current roles against NIAP scheme publications and official NIAP and NIST sources.
Does a Common Criteria certification under CCEVS mean a product is secure or approved for any government use?
No. A CCEVS validation attests that a product (the Target of Evaluation) was evaluated against a specified set of security functional and assurance requirements, generally as expressed in a Protection Profile or Security Target, in a defined evaluated configuration. It does not certify that the product is secure in all deployments, nor does it constitute an authorization to operate on any specific system. Certification is distinct from authorization: a validated product still must be assessed within the context of a system undergoing the applicable authorization process (for example, the DoD Risk Management Framework), and it must be deployed in its evaluated configuration for the validation to be meaningful. Confirm applicability against current official guidance.
How do I find products that have been validated under CCEVS?
Validated products are generally listed on the NIAP Product Compliant List, which identifies products that have completed evaluation and validation under the scheme. Because listings, evaluated configurations, and any assurance maintenance or expiration status can change, consult the current NIAP-maintained list directly rather than relying on cached or secondhand references, and confirm that the specific version and configuration you intend to deploy matches what was evaluated.
Which Common Criteria Testing Laboratory should perform an evaluation, and how is that lab's authority established?
Evaluations under CCEVS are performed by Common Criteria Testing Laboratories that are accredited through NIST's NVLAP and approved to operate within the NIAP scheme. When selecting a laboratory, verify its current accreditation and approval status through the applicable NVLAP and NIAP sources, and confirm the scope of its accreditation covers the type of evaluation you require. The vendor typically contracts directly with an accredited laboratory. This entry does not cover contractual, pricing, or scheduling specifics, which you should confirm with the laboratory and NIAP.
What is the role of a Protection Profile in a CCEVS evaluation?
In most current CCEVS evaluations, a Protection Profile defines the standardized set of security requirements for a category of technology, and products are generally evaluated for conformance to an applicable Protection Profile rather than against an arbitrary assurance level chosen in isolation. NIAP publishes and endorses Protection Profiles for use within the scheme. Because the available Protection Profiles and the requirements they contain are revised over time, verify which Protection Profile applies to your technology type and its current version through official NIAP publications.
Does a CCEVS validation remain valid indefinitely, and how does it relate to product updates?
A validation should not be treated as permanent or as automatically covering later versions of a product. Validations apply to a specific evaluated version and configuration, and processes such as assurance maintenance or re-evaluation may be relevant when a product changes. Because validity status, assurance continuity provisions, and any listed dates can change, confirm the current status of a specific product against the NIAP Product Compliant List and applicable scheme publications rather than assuming an existing validation still applies to an updated release.

Common misconceptions

CCEVS is jointly operated by NIST and NSA as co-equal operators of the scheme.
The scheme is operated under NIAP, which is managed operationally by NSA. NIST does not co-operate the scheme in the way it once did, but it retains statutory responsibilities and an operational role, notably accrediting Common Criteria Testing Laboratories through NVLAP. Practitioners should verify the current governance structure against official NIAP and NIST publications rather than assuming co-equal operation.
A Common Criteria validation under CCEVS means a product is authorized for use on a federal or DoD system.
Validation is an evaluation outcome, not an authorization. It confirms a product was evaluated against specified security requirements. Deploying the product on a system generally still requires a separate authorization process (for example, under the applicable Risk Management Framework and agency tailoring), and readers should confirm requirements against current authoritative guidance.
A Common Criteria validation is equivalent to overall product security.
A validation reflects evaluation against a defined scope, typically an approved Protection Profile and stated configuration, as of the evaluation date. It does not guarantee security under all conditions, cover subsequent changes, or substitute for ongoing security management.

Best practices

Confirm the current governance and division of roles between NSA (operational management of NIAP) and NIST (including NVLAP accreditation of testing laboratories) against official NIAP and NIST publications before relying on any summary.
Verify that a product appears on the current NIAP Product Compliant List (or equivalent official listing) and check the specific Protection Profile and evaluated configuration, rather than assuming a general assurance level.
Ensure the evaluated configuration matches your intended deployment, since a validation applies only to the specific version, settings, and scope evaluated.
Treat Common Criteria validation as one input to system authorization, not as a substitute for the applicable authorization process or continuous monitoring under your governing framework.
Confirm the applicable version of the Common Criteria standard and any U.S. national interpretations, as scheme requirements and Protection Profiles are updated over time.