Common Criteria Evaluation and Validation Scheme
The Common Criteria Evaluation and Validation Scheme (CCEVS) is the U.S. program that provides government oversight, or 'validation,' of Common Criteria security evaluations of information technology products. It is implemented under the National Information Assurance Partnership (NIAP) so that products tested in the United States conform correctly to the international Common Criteria standard. Independent, accredited testing laboratories perform the evaluations, and validated products are listed on a compliance list that agencies can consult.
CCEVS is the U.S. evaluation scheme implemented under NIAP to meet the requirements of the Common Criteria and to provide governmental validation of Common Criteria (CC) evaluations, ensuring correct conformance to the applicable CC methodology and Protection Profiles. Under CCEVS, accredited Common Criteria Testing Laboratories (CCTLs) conduct product evaluations, and NIAP validators oversee the process and issue validation of the results, with validated products placed on the Product Compliant List. The scheme operates within the framework of the Common Criteria Recognition Arrangement (CCRA), whose status, certification schemes, licensed laboratories, and certified products are tracked through the Common Criteria portal. Practitioners should verify current governance and operational responsibilities, including the roles assigned to NIAP and to NIST-related accreditation functions, against current NIAP Scheme publications and official sources, as these arrangements and the underlying evaluation requirements evolve over time. This entry does not address the specific procedural, contractual, or accreditation details a reader must confirm in current authoritative CCEVS and CCRA documentation.
Why it matters
For federal agencies and their vendors, CCEVS provides a government-validated basis for trusting that a commercial IT product's security functionality has been independently evaluated against the international Common Criteria standard rather than relying on a manufacturer's own claims. Validated products appear on the Product Compliant List (PCL) maintained under NIAP, which acquisition officials and system owners can consult when selecting components for national security systems and other environments where NIAP-evaluated products are expected. This matters because procurement policy in some defense and national security contexts directs acquisition of products from the PCL where a suitable evaluated product exists, making CCEVS validation a practical gating factor for market access.
Who it's relevant to
Inside CCEVS
Common questions
Answers to the questions practitioners most commonly ask about CCEVS.