Skip to main content
Category: CMMC & DIB Assessment

Evaluation Assurance Level

Also known as: EAL, Common Criteria Evaluation Assurance Level
Simply put

An Evaluation Assurance Level (EAL) is a rating on a standardized scale used under the Common Criteria framework to indicate how thoroughly an IT product's security has been tested and evaluated. A higher EAL generally reflects greater depth and rigor in the evaluation process, not necessarily a more secure product. The choice of level depends on the assurance needs for a given product and its intended use.

Formal definition

Under the Common Criteria, an Evaluation Assurance Level is a defined set of assurance requirements representing a specific point on the Common Criteria predefined assurance scale, as reflected in the NIST CSRC glossary. Each EAL packages assurance components that specify the depth and rigor applied when evaluating a Target of Evaluation, and evaluation may address characteristics such as audit mechanisms, cryptographic capability, and access controls. EAL denotes the assurance (the degree of confidence derived from the evaluation effort) rather than a direct measure of the product's inherent security, and certification against an evaluated set of security properties is issued through Certificate Authorizing Schemes recognized within the Common Criteria arrangement. Readers should note that the specific number and definitions of EAL levels, tailoring, and mutual recognition scope should be confirmed against the current authoritative Common Criteria text, and that this entry does not address DoD RMF, FedRAMP, or CUI-related requirements, which are governed by separate authorities.

Why it matters

For product security evaluation, the Evaluation Assurance Level provides a standardized, internationally recognized way to communicate how thoroughly an IT product's security has been examined under the Common Criteria. This matters to acquisition and security personnel because it allows a common vocabulary when comparing evaluated products and setting procurement expectations. Rather than relying on a vendor's self-assertion, an EAL reflects an evaluation performed against defined assurance requirements, and certification issued through a recognized Certificate Authorizing Scheme.

The most consequential point for practitioners is that a higher EAL generally reflects greater depth and rigor in the evaluation process, not a more secure product. Treating EAL as a direct measure of inherent security is a common and significant error. A product evaluated at a higher level has been examined more rigorously against its stated security claims, but the assurance derives from the evaluation effort itself and from the specific security properties in scope, not from a guarantee that the product is safer in every deployment. Selecting a level should be driven by the assurance needs of the product and its intended use.

Because the specific number of levels, tailoring options, and the scope of mutual recognition can change, readers should confirm current details against the authoritative Common Criteria text rather than relying on any single summary. It is also important not to conflate a Common Criteria EAL with authorization or compliance regimes such as DoD RMF, FedRAMP, or CUI-related requirements, which are governed by separate authorities and are out of scope for this term.

Who it's relevant to

Acquisition and procurement officials
Personnel selecting IT products can use EAL as a standardized reference point when comparing evaluated products and defining assurance expectations in requirements. They should choose a level based on the assurance needs for the product's intended use, and avoid treating a higher EAL as proof of greater inherent security or as a substitute for authorization requirements under separate authorities.
Product vendors and developers
Vendors seeking Common Criteria certification define the Target of Evaluation and the security properties to be examined, then pursue evaluation and certification through a recognized Certificate Authorizing Scheme. Because the depth of evaluation increases with the level, vendors should confirm current requirements and tailoring options against the authoritative Common Criteria text before committing to a target level.
Information system security managers and evaluators
Security practitioners interpreting product claims need to understand that an EAL reflects the degree of confidence derived from the evaluation effort, not a direct measure of security. Evaluations may address characteristics such as audit mechanisms, cryptographic capability, and access controls, so practitioners should review what security properties were actually in scope for a given certification.
Compliance officers and auditors
Those verifying that products meet stated assurance expectations should distinguish a Common Criteria evaluation and certification from compliance or authorization under separate regimes such as DoD RMF, FedRAMP, or CUI-related requirements. An EAL does not by itself satisfy those obligations, which are governed by different authorities and must be confirmed independently.

Inside EAL

Assurance Rating Scale
EAL is expressed on a graduated scale, commonly cited as EAL1 through EAL7, under the Common Criteria (ISO/IEC 15408) framework. Higher levels reflect more rigorous and formally verified evaluation of the assurance requirements, not necessarily greater inherent security functionality. Practitioners should confirm the exact level definitions against the current authoritative Common Criteria text.
Common Criteria Basis
EAL is a construct of the Common Criteria for Information Technology Security Evaluation, an international standard (ISO/IEC 15408) used to specify and evaluate security assurance. In the U.S. context, evaluations are generally associated with the National Information Assurance Partnership (NIAP) and its scheme; readers should verify the governing scheme and applicable Protection Profiles.
Target of Evaluation (TOE) and Scope
An EAL applies to a specific Target of Evaluation (the product or system portion under review) as defined in its Security Target, and typically within a defined evaluated configuration. The rating characterizes the depth and rigor of evaluation of that TOE, not an unbounded claim about the product as deployed.
Security Assurance Requirements
Each EAL corresponds to a package of security assurance requirements addressing aspects such as design documentation, testing, and vulnerability analysis. The specific requirements bundled at each level are defined in the Common Criteria; verify the current revision because assurance packages and their contents can change.
Relationship to Protection Profiles
Modern NIAP-based evaluations increasingly emphasize evaluation against Protection Profiles rather than standalone EAL numbers. Where this applies, a numeric EAL may not be the primary or applicable assurance descriptor; practitioners should confirm which approach governs a given product listing.

Common questions

Answers to the questions practitioners most commonly ask about EAL.

Does a higher Evaluation Assurance Level mean a product is more secure?
Not necessarily. An EAL indicates the depth and rigor of the evaluation activities applied to a product, not the inherent strength of its security functionality. A higher EAL means greater assurance that the product behaves as described and was evaluated more thoroughly, but a product evaluated at a higher EAL is not automatically "more secure" than one at a lower EAL. Security depends heavily on the Security Target and the specific security functional requirements claimed and tested. Readers should evaluate what was actually assessed rather than treating the EAL number alone as a security ranking.
Does Common Criteria certification or an EAL rating satisfy federal or DoD authorization requirements on its own?
No. An EAL rating reflects the outcome of a product-level evaluation under the Common Criteria and should not be confused with system authorization. It does not by itself constitute an Authority to Operate (ATO), nor does it automatically satisfy RMF, FISMA, FedRAMP, or DoD requirements. Authorization is a separate, system-specific process. A certified product may be one input into an authorization decision, but authorizing officials generally consider it alongside broader control implementation, continuous monitoring, and risk determinations. Verify current agency and DoD acquisition policies for how product certifications are treated.
How does an EAL relate to the Security Target and Protection Profile when interpreting an evaluation result?
The EAL describes the assurance rigor, but the Security Target defines what security functionality was actually claimed and evaluated, and any applicable Protection Profile defines standardized requirements for a product category. To interpret a result meaningfully, review the Security Target and Protection Profile to understand the evaluated configuration, assumptions, and functional claims. An EAL number without that context does not tell you whether the evaluated functionality aligns with your operational and threat environment. Confirm details against the certification report and associated documentation.
How should an EAL rating factor into a product selection or acquisition decision?
Treat an EAL as one factor among several rather than a decisive criterion. Consider whether the evaluated configuration matches your intended deployment, whether the Security Target's functional claims address your requirements, and whether the certification remains current. Also confirm any procurement-specific mandates that may apply to your environment, since requirements can differ across federal civilian, defense, and national security contexts. Consult current acquisition guidance and the authoritative certification documentation before relying on an EAL in a selection decision.
Does an EAL rating remain valid indefinitely once a product is certified?
An evaluation result applies to a specific version and evaluated configuration of a product at the time it was assessed. Later patches, version changes, or configuration differences may not be covered by the original evaluation. Certificate maintenance or re-evaluation processes may exist to address updates, but you should not assume an EAL rating carries forward automatically to newer releases. Verify the current status, covered version, and any maintenance activities against the official certification records.
What should be documented to support the use of an EAL-rated product in an authorization package?
Documentation should generally identify the specific evaluated product version and configuration, reference the Security Target and any applicable Protection Profile, and clarify how the evaluated functionality maps to the security controls or requirements you are addressing. It should also note any deviations between the deployed configuration and the evaluated configuration, since those may affect the assurance you can rely upon. Because authorization is system-specific and separate from product evaluation, confirm documentation expectations with your authorizing official and current governing guidance.

Common misconceptions

A higher EAL means a more secure product.
EAL indicates the rigor and depth of the evaluation performed, not the absolute security of the product. A product evaluated at a higher EAL was assessed more thoroughly, but the rating does not by itself guarantee stronger security functionality, and it is scoped to a specific TOE and evaluated configuration.
A Common Criteria EAL certification automatically satisfies federal or DoD security requirements.
An EAL evaluation is distinct from authorization decisions such as an ATO under the RMF, and from frameworks like FedRAMP, FISMA-based controls, or CMMC. A certified product may support meeting requirements, but it does not replace the applicable control implementation, assessment, and authorization processes. Verify how a given program treats Common Criteria evaluation as of the current guidance.
An EAL rating applies to the product as generally deployed.
The rating applies only to the defined Target of Evaluation and, in most cases, a specific evaluated configuration. Deploying the product outside that configuration can fall outside the scope of what was evaluated, so practitioners should confirm the evaluated configuration and its boundaries.

Best practices

Treat EAL as a measure of evaluation rigor and depth rather than a proxy for overall security, and pair it with your own risk-based assessment of the product's fitness for your environment.
Confirm the Target of Evaluation, Security Target, and evaluated configuration for any certified product, and align your deployment to that configuration where feasible.
Do not assume a Common Criteria EAL substitutes for RMF authorization, FedRAMP, FISMA-based control implementation, or CMMC obligations; verify the specific requirements applicable to your system category (CUI, DoD RMF, civilian FISMA, or national security).
Check whether the applicable scheme (such as NIAP in the U.S.) emphasizes evaluation against Protection Profiles rather than standalone EAL numbers, and use the descriptor that governs the current product listing.
Verify the current Common Criteria revision (ISO/IEC 15408) and the exact assurance requirements at each level against authoritative sources, since assurance packages and level definitions can change.
Document how any evaluated product supports specific control objectives, keeping assessment evidence separate from authorization decisions and confirming acceptance with the relevant authorizing official.