Panel Discussion — Where Evaluations Derail and (W01a)
The points where real projects go off the rails: bad TOE scope, unrealistic timelines, poor ownership of evidence, misunderstandings with labs, and failure to account... Read More
Common Criteria Management Committee (CCMC) Update (P10d)
This talk provides an update on the activities of the CCMC.
Panel: Common Criteria Challenges in Mutual Recognition: Is It Getting Any Better? (P32a)
A look at multiple national schemes and the challenges to move towards true mutual recognition. Are we getting any closer? What conversations need to be... Read More
Evaluation of AI-Based Technology (C31c)
Building on previous talks at ICCC in Doha 2024 and Songdo 2025, which proposed a new AI security evaluation framework, the presenter is pleased to... Read More
French Proposal for Evaluating Products Integrating AI (C31b)
ANSSI, the French cybersecurity Agency, has launched in 2025 a working group with French ITSEFs and other French organisations to establish cybersecurity evaluation methodologies for... Read More
A New Way (Undiscovered) to Evaluate, Certify and Maintain Products in the Age of Artificial Intelligence (C31a)
In recent years, manufacturers are increasingly adopting Artificial Intelligence systems in the essential phases of the Development Life Cycle, creating increasingly complex products that are... Read More
OSCAL and the Certification Lifecycle: Machine-Readable Compliance for Common Criteria (C30c)
As EUCC, US Cyber Trust Mark, and global regulatory frameworks demand faster, more consistent certifications, the Common Criteria community faces mounting documentation burdens. OSCAL, the... Read More
Strategies for CC Compliance for Systems with LLMs (C30b)
Common Criteria (ISO/IEC 15408) certifications are philosophically rooted in determinism: the principle that a Target of Evaluation (TOE) given input X will produce a predictable,... Read More
Towards a Protection Profile for Generic Native Platforms in Emerging Secure Domains Under CC:2022 (C30a)
In emerging domains such as robotics, wearables, and automotive, it is essential to ensure security without compromising performance. This necessitates direct control over hardware resources... Read More
Network Device iTC Update (C23e)
This talk will include an update of the ND iTC since the last ICCC, latest NDcPP and module postings, where we are today and what... Read More