Evaluation Assurance Level
An Evaluation Assurance Level (EAL) is a rating on a standardized scale used under the Common Criteria framework to indicate how thoroughly an IT product's security has been tested and evaluated. A higher EAL generally reflects greater depth and rigor in the evaluation process, not necessarily a more secure product. The choice of level depends on the assurance needs for a given product and its intended use.
Under the Common Criteria, an Evaluation Assurance Level is a defined set of assurance requirements representing a specific point on the Common Criteria predefined assurance scale, as reflected in the NIST CSRC glossary. Each EAL packages assurance components that specify the depth and rigor applied when evaluating a Target of Evaluation, and evaluation may address characteristics such as audit mechanisms, cryptographic capability, and access controls. EAL denotes the assurance (the degree of confidence derived from the evaluation effort) rather than a direct measure of the product's inherent security, and certification against an evaluated set of security properties is issued through Certificate Authorizing Schemes recognized within the Common Criteria arrangement. Readers should note that the specific number and definitions of EAL levels, tailoring, and mutual recognition scope should be confirmed against the current authoritative Common Criteria text, and that this entry does not address DoD RMF, FedRAMP, or CUI-related requirements, which are governed by separate authorities.
Why it matters
For product security evaluation, the Evaluation Assurance Level provides a standardized, internationally recognized way to communicate how thoroughly an IT product's security has been examined under the Common Criteria. This matters to acquisition and security personnel because it allows a common vocabulary when comparing evaluated products and setting procurement expectations. Rather than relying on a vendor's self-assertion, an EAL reflects an evaluation performed against defined assurance requirements, and certification issued through a recognized Certificate Authorizing Scheme.
The most consequential point for practitioners is that a higher EAL generally reflects greater depth and rigor in the evaluation process, not a more secure product. Treating EAL as a direct measure of inherent security is a common and significant error. A product evaluated at a higher level has been examined more rigorously against its stated security claims, but the assurance derives from the evaluation effort itself and from the specific security properties in scope, not from a guarantee that the product is safer in every deployment. Selecting a level should be driven by the assurance needs of the product and its intended use.
Because the specific number of levels, tailoring options, and the scope of mutual recognition can change, readers should confirm current details against the authoritative Common Criteria text rather than relying on any single summary. It is also important not to conflate a Common Criteria EAL with authorization or compliance regimes such as DoD RMF, FedRAMP, or CUI-related requirements, which are governed by separate authorities and are out of scope for this term.
Who it's relevant to
Inside EAL
Common questions
Answers to the questions practitioners most commonly ask about EAL.