From “Certify before Patching” to “Risk and Lifecycle Management” (A30a)
How vulnerability handling shifted from awkward surprises to standardized processes? Over the last decade, vulnerability handling for certified ICT products evolved from a “do not... Read More
Using the ISO 9569 Patch Management Methodology in Practice. Experience, Expectations, Surprises. (A30b)
Developing a good methodology that makes Common Criteria Certification faster and fit for Future is one thing. Gaining initial practical experience with it is quite... Read More
From EUCC Certification to CRA Conformity: A Resilience-Oriented Path for Network Devices (A23c)
Common Criteria is not the problem: in many respects, it is already stricter than the likely CRA baseline. The real challenge is turning that rigor... Read More
Adapting to the Cyber Resilience Act: Challenges, Opportunities, and Certification Strategies by Using EUCC (A23b)
The newly enacted Cyber Resilience Act (CRA) legislation is set to impose a range of new requirements and responsibilities across the digital market. These obligations... Read More
Technical Domain Software – Our Activities and Way Forward (A23a)
The Technical Domain Software focus on attack methods, attack potential and minimum tooling in the domain of software evaluation. One of the presenters’ goals as... Read More
Quality for CABs as the Foundation of Cyber Trust : Leveraging ISO 17065 Within the Common Criteria Framework (A22c)
This talk explores the pivotal role of ISO/IEC 17065 – the international standard for bodies certifying products, processes, and services – as the bedrock of... Read More
Parsing Assurance: Dissecting LLM Vulnerability Reasoning and Building a Graded Evaluation Pipeline (A22b)
As AI-integrated systems seek security certification, conventional evaluation methods struggle with the non-deterministic nature of LLMs. This talk introduces a rigorous, evidence-based pipeline for verifying... Read More
Certifying Modern Development Environments Under Common Criteria (A22a)
Secure development environments have traditionally been assessed against MSSR measures. However, as development environments shift toward cloud infrastructure, MSSR appears limited in its ability to... Read More
TLS Evaluation Tooling for NDcPP: Lessons from TLS 1.2, TLS 1.3 and the Role of AI in Closing the Gaps (A21c)
The presenters have developed an automated test tool for NDcPP and Package PP TLS conformance evaluation, covering Security Functional Requirements across both TLS 1.2 and... Read More
Evolving CC for the AI Era: Enabling Secure Use of Cloud and LLMs in High-Assurance Design Environments (A21b)
Minimum Site Security Requirements (MSSR v2) impose strict isolation constraints on critical and critical+ assets, effectively prohibiting the use of external networks, cloud platforms, and... Read More