EN ISO/IEC 15408-4:2026
(Main)Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 4: Framework for the specification of evaluation methods and activities (ISO/IEC 15408-4:2026)
General Information
- Abstract
This document specifies requirements and a standardized framework for specifying objective, repeatable and reproducible evaluation methods and evaluation activities.
This document does not specify how to evaluate, adopt, or maintain evaluation methods and evaluation activities. These aspects are a matter for those originating the evaluation methods and evaluation activities in their particular area of interest.
- Status
- Published
- Publication Date
- 26-May-2026
- Technical Committee
- CEN/CLC/TC 13 - Cybersecurity and Data Protection
- Current Stage
- 6060 - Definitive text made available (DAV) - Publishing
- Start Date
- 27-May-2026
- Completion Date
- 27-May-2026
Overview
EN ISO/IEC 15408-4:2026 is an international standard developed by the European Committee for Standardization (CEN) under the ISO/IEC 15408 series for information security, cybersecurity, and privacy protection. This part specifies a standardized framework for the specification of evaluation methods and evaluation activities. It supports organizations and evaluation authorities in defining objective, repeatable, and reproducible processes for IT security assessments.
The document provides foundational requirements and a structural model for how evaluation methods and activities should be described, ensuring comparability, transparency, and alignment with broader assurance frameworks. EN ISO/IEC 15408-4:2026 does not dictate how to perform, adopt, or maintain evaluation methods - these choices are left to those developing the methods for specific technological or regulatory needs.
Key Topics
- Framework Specification: Outlines how to structure the definition of IT security evaluation methods and activities so that results are credible and reproducible.
- Terminology Alignment: Ensures consistent use of terminology by referencing ISO/IEC 15408-1, 15408-2, 15408-3, and ISO/IEC 18045.
- Modular Approach: Supports tailoring of evaluation activities for specific technologies, products or security requirements, promoting reuse and scalability.
- Objective and Repeatable Results: Emphasizes the importance of defined methods and activities being objective and allowing for reproducible outcomes.
- Separation of Specification and Practice: Focuses solely on the framework for specification, not on implementation or assessment techniques.
Applications
EN ISO/IEC 15408-4:2026 is designed for a broad range of stakeholders involved in cybersecurity and IT security evaluation contexts, including:
- Standards Developers & Evaluation Authorities: As a foundation for developing new evaluation methods for emerging technologies such as cloud services, IoT devices, or AI systems.
- IT Product Vendors: To align security evaluation documentation with international best practice, facilitating acceptance in global markets.
- Conformance Assessment Bodies: For structuring how evaluation activities are mandated and reported in protection profiles (PPs), security targets (STs), or specific evaluation contexts.
- Regulators & Government Agencies: To reference a consistent approach for specifying security evaluation requirements in procurement or certification schemes.
- Cybersecurity Consultants: As a guideline for advising clients in the preparation of repeatable and transparent evaluation activities for IT security certification.
Practical uses range from the development of protection profiles requiring specific evaluation activities, through bespoke security assurance for technology deployments, to consistent reporting and audit processes for compliance verification.
Related Standards
EN ISO/IEC 15408-4:2026 is part of an internationally recognized series for IT security evaluation. Key related standards include:
- ISO/IEC 15408-1: Introduction and general model - establishes principles and structure for IT security evaluation.
- ISO/IEC 15408-2: Security functional components - outlines standardized security functions for IT products.
- ISO/IEC 15408-3: Security assurance components - details assurance requirements and classes.
- ISO/IEC 18045: Methodology for IT security evaluation - provides companion methodology for many assurance requirements defined in the 15408 series.
- ISO/IEC 15408-5: Extended components definitions - for extended sets of security requirements where needed.
These standards work together to form the Common Criteria framework, widely adopted for global IT security certification and evaluation.
By adhering to EN ISO/IEC 15408-4:2026, organizations can ensure their IT security evaluation methods are robust, standardized, and recognized internationally, supporting interoperability, transparency, and improved assurance in cybersecurity and privacy protection.
Relations
- Effective Date
- 17-Apr-2024
- Effective Date
- 12-Feb-2026
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

Bureau Veritas
Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

DNV
DNV is an independent assurance and risk management provider.
Sponsored listings
Frequently Asked Questions
EN ISO/IEC 15408-4:2026 is a standard published by the European Committee for Standardization (CEN). Its full title is "Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 4: Framework for the specification of evaluation methods and activities (ISO/IEC 15408-4:2026)". This standard covers: This document specifies requirements and a standardized framework for specifying objective, repeatable and reproducible evaluation methods and evaluation activities. This document does not specify how to evaluate, adopt, or maintain evaluation methods and evaluation activities. These aspects are a matter for those originating the evaluation methods and evaluation activities in their particular area of interest.
This document specifies requirements and a standardized framework for specifying objective, repeatable and reproducible evaluation methods and evaluation activities. This document does not specify how to evaluate, adopt, or maintain evaluation methods and evaluation activities. These aspects are a matter for those originating the evaluation methods and evaluation activities in their particular area of interest.
EN ISO/IEC 15408-4:2026 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security. The ICS classification helps identify the subject area and facilitates finding related standards.
EN ISO/IEC 15408-4:2026 has the following relationships with other standards: It is inter standard links to EN ISO/IEC 15408-4:2023, ISO/IEC 15408-4:2026. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
EN ISO/IEC 15408-4:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-oktober-2026
Nadomešča:
SIST EN ISO/IEC 15408-4:2024
Informacijska varnost, kibernetska varnost in varstvo zasebnosti - Merila za
vrednotenje varnosti IT - 4. del: Okvir za specifikacijo metod vrednotenja in
dejavnosti (ISO/IEC 15408-4:2026)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT
security - Part 4: Framework for the specification of evaluation methods and activities
(ISO/IEC 15408-4:2026)
Informationssicherheit, Cybersicherheit und Schutz der Privatsphäre -
Evaluationskriterien für IT-Sicherheit - Teil 4: Rahmen für die Festlegung von
Bewertungsmethoden und -tätigkeiten (ISO/IEC 15408-4:2026)
Sécurité de l'information, cybersécurité et protection de la vie privée - Critères
d'évaluation pour la sécurité des technologies de l'information - Partie 4: Cadre de
spécification de méthodes et activités d'évaluation (ISO/IEC 15408-4:2026)
Ta slovenski standard je istoveten z: EN ISO/IEC 15408-4:2026
ICS:
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
EUROPEAN STANDARD EN ISO/IEC 15408-4
NORME EUROPÉENNE
EUROPÄISCHE NORM
May 2026
ICS 35.030
Supersedes EN ISO/IEC 15408-4:2023
English version
Information security, cybersecurity and privacy protection
- Evaluation criteria for IT security - Part 4: Framework for
the specification of evaluation methods and activities
(ISO/IEC 15408-4:2026)
Sécurité de l'information, cybersécurité et protection Informationssicherheit, Cybersicherheit und Schutz
de la vie privée - Critères d'évaluation pour la sécurité der Privatsphäre - Evaluationskriterien für IT-
des technologies de l'information - Partie 4: Cadre de Sicherheit - Teil 4: Rahmen für die Festlegung von
spécification de méthodes et activités d'évaluation Bewertungsmethoden und -tätigkeiten (ISO/IEC
(ISO/IEC 15408-4:2026) 15408-4:2026)
This European Standard was approved by CEN on 3 March 2026.
CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for
giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.
CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.
CEN-CENELEC Management Centre:
Rue de la Science 23, B-1040 Brussels
© 2026 CEN/CENELEC All rights of exploitation in any form and by any means Ref. No. EN ISO/IEC 15408-4:2026 E
reserved worldwide for CEN national Members and for
CENELEC Members.
Contents Page
European foreword . 3
European foreword
This document (EN ISO/IEC 15408-4:2026) has been prepared by Technical Committee ISO/IEC JTC 1
"Information technology" in collaboration with Technical Committee CEN-CENELEC/ JTC 13
“Cybersecurity and Data Protection” the secretariat of which is held by DIN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by November 2026, and conflicting national standards
shall be withdrawn at the latest by November 2026.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN-CENELEC shall not be held responsible for identifying any or all such patent rights.
This document supersedes EN ISO/IEC 15408-4:2023.
Any feedback and questions on this document should be directed to the users’ national standards
body/national committee. A complete listing of these bodies can be found on the CEN and CENELEC
websites.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Endorsement notice
The text of ISO/IEC 15408-4:2026 has been approved by CEN-CENELEC as EN ISO/IEC 15408-4:2026
without any modification.
International
Standard
ISO/IEC 15408-4
Second edition
Information security, cybersecurity
2026-05
and privacy protection —
Evaluation criteria for IT security —
Part 4:
Framework for the specification of
evaluation methods and activities
Sécurité de l'information, cybersécurité et protection de la vie
privée — Critères d'évaluation pour la sécurité des technologies
de l'information —
Partie 4: Cadre de spécification de méthodes et activités
d'évaluation
Reference number
ISO/IEC 15408-4:2026(en) © ISO/IEC 2026
ISO/IEC 15408-4:2026(en)
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC 15408-4:2026(en)
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms, definitions and abbreviated terms . 1
4 General model of evaluation methods and evaluation activities . 2
4.1 Concepts and model .2
4.2 Deriving evaluation methods and evaluation activities .3
4.3 Verb usage in the description of evaluation methods and evaluation activities .6
4.4 Conventions for the description of evaluation methods and evaluation activities .6
5 Structure of an evaluation method . 6
5.1 Overview .6
5.2 Specification of an evaluation method .7
5.2.1 Overview .7
5.2.2 Identification of evaluation methods .8
5.2.3 Entity responsible for the evaluation method .8
5.2.4 Scope of the evaluation method .9
5.2.5 Dependencies .9
5.2.6 Required input from the developer or other entities .9
5.2.7 Required tool types .10
5.2.8 Required evaluator competences .10
5.2.9 Requirements for reporting .10
5.2.10 Rationale for the evaluation method .10
5.2.11 Additional verb definitions . 12
5.2.12 Set of evaluation activities. 12
6 Structure of evaluation activities .12
6.1 Overview . 12
6.2 Specification of an evaluation activity . 12
6.2.1 Unique identification of the evaluation activity . 12
6.2.2 Objective of the evaluation activity . 12
6.2.3 Evaluation activity links to SFRs, SARs, and other evaluation activities . 13
6.2.4 Required input from the developer or other entities . 13
6.2.5 Required tool types . 13
6.2.6 Required evaluator competences . 13
6.2.7 Assessment strategy . 13
6.2.8 Pass/fail criteria .14
6.2.9 Requirements for reporting . 15
6.2.10 Rationale for the evaluation activity . 15
Bibliography .16
© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 15408-4:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 27, Information security, cybersecurity and privacy protection, in collaboration with the
European Committee for Standardization (CEN) Technical Committee CEN/CLC/JTC 13, Cybersecurity and
data protection, in accordance with the Agreement on technical cooperation between ISO and CEN (Vienna
Agreement).
This second edition cancels and replaces the first edition (ISO/IEC 15408-4:2022), which has been
technically revised.
The main changes are as follows:
— minor typographical and editorial errors corrected.
A list of all parts in the ISO/IEC 15408 series can be found on the ISO website.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.
© ISO/IEC 2026 – All rights reserved
iv
ISO/IEC 15408-4:2026(en)
Introduction
The model of security evaluation in ISO/IEC 15408-1 identifies that high-level generic evaluation activities
are defined in ISO/IEC 18045, but that more specific evaluation activities (EAs) can be defined as technology-
specific adaptations of these generic activities for particular evaluation contexts, e.g. for security functional
requirements (SFRs) or security assurance requirements (SARs) applied to specific technologies or
target of evaluation (TOE) types. Specification of such evaluation activities is already occurring amongst
practitioners, and this creates a need for a specification for defining such evaluation activities.
This document describes a framework that can be used for deriving evaluation activities from work units
of ISO/IEC 18045 and grouping them into evaluation methods (EMs). Evaluation activities or evaluation
methods can be included in protection profiles (PPs) and any documents supporting them. Where a PP, PP-
Configuration, PP-Module, package, or Security Target (ST) identifies that specific evaluation methods/
evaluation activities must be used, the evaluators are required by ISO/IEC 18045 to follow and report
the relevant evaluation methods/evaluation activities when assigning evaluator verdicts. As noted in
ISO/IEC 15408-1, in some cases an evaluation authority can decide not to approve the use of particular
evaluation methods/evaluation activities. In such a case, the evaluation authority can decide not to carry out
evaluations following an ST that requires those evaluation methods/evaluation activities.
This document also allows for evaluation activities to be defined for extended SARs, in which case derivation
of the evaluation activities relates to equivalent evaluator action elements and work units defined for that
extended SAR. Where reference is made in this document to the use of ISO/IEC 18045 or ISO/IEC 15408-3
for SARs (such as when defining rationales for evaluation activities), then, in the case of an extended SAR,
the reference applies instead to the equivalent evaluator action elements and work units defined for that
extended SAR.
For clarity, this document specifies how to define evaluation methods and evaluation activities but does not
itself specify instances of evaluation methods or evaluation activities.
Several governmental organizations have contributed to the development of this version of the
Common Criteria for Information Technology Security Evaluations. As the joint holders of the copyright
in the Common Criteria for Information Technology Security Evaluations (called CC), they hereby
grant non-exclusive license to ISO/IEC to use CC in the continued development/maintenance of the
ISO/IEC 15408 series of standards. However, these governmental organizations retain the right to use,
copy, distribute, translate, or modify CC as they see fit. More information on these agencies can be found at
https://commoncriteriaportal.org/cc/copyright/index.cfm.
© ISO/IEC 2026 – All rights reserved
v
International Standard ISO/IEC 15408-4:2026(en)
Information security, cybersecurity and privacy protection —
Evaluation criteria for IT security —
Part 4:
Framework for the specification of evaluation methods and
activities
1 Scope
This document specifies requirements and a standardized framework for specifying objective, repeatable
and reproducible evaluation methods and evaluation activities.
This document does not specify how to evaluate, adopt, or maintain evaluation methods and evaluation
activities. These aspects are a matter for those originating the evaluation methods and evaluation activities
in their particular area of interest.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 15408-1, Information security, cybersecurity and privacy protection — Evaluation criteria for IT
security — Part 1: Introduction and general model
ISO/IEC 15408-2, Information security, cybersecurity and privacy protection — Evaluation criteria for IT
security — Part 2: Security functional components
ISO/IEC 15408-3:2026, Information security, cybersecurity and privacy protection — Evaluation criteria for IT
security — Part 3: Security assurance components
ISO/IEC 18045:2026, Information security, cybersecurity and privacy protection — Evaluation criteria for IT
security — Requirements and methodology for IT security evaluation
3 Terms, definitions and abbreviated terms
For the purposes of this document, the terms and definitions given in ISO/IEC 15408-1, ISO/IEC 15408-2,
ISO/IEC 15408-3, ISO/IEC 18045 apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
© ISO/IEC 2026 – All rights reserved
ISO/IEC 15408-4:2026(en)
4 General model of evaluation methods and evaluation activities
4.1 Concepts and model
ISO/IEC 18045 defines a generic set of work units that an evaluator carries out in order to reach a verdict
for most of the assurance classes, families and components defined in ISO/IEC 15408-3. The relationship
between the structure of a SAR in ISO/IEC 15408-3 and the work units in ISO/IEC 18045 is described in
ISO/IEC 18045 and summarized in Figure 1 showing that the derivation is flexible and not required to be
simply 1:1).
Figure 1 — Mapping of P3 and CEM to this document
For the purposes of defining new evaluation methods and evaluation activities, the main point to note is that
each action (representing an evaluator action element in ISO/IEC 15408-3 or an implied evaluator action
element) is represented in ISO/IEC 18045 as a set of work units that are carried out by an evaluator.
This document specifies the ways in which new evaluation activities can be derived from the generic work
units in ISO/IEC 18045, and combined into an evaluation method that is intended for use in some particular
evaluation context. A typical example of such an evaluation context is a particular TOE type or particular
technology type.
EXAMPLE 1
— TOE type: a network device
— Technology type: specific cryptographic functions
If evaluation methods (EM) and evaluation activities (EA) are required to be used with a particular PP, PP-
Module or PP-Configuration, then a PP or PP-Module or PP-Configuration shall identify this requirement in
its conformance statement. If evaluation methods and evaluation activities are required to be used with a
particular package, then the package shall identify this requirement in the security requirement section.
If EMs and EAs are claimed by an ST as a result of that ST claiming conformance to a PP, PP-Configuration,
or package, then the ST shall identify the EMs/EAs used in its conformance claim. No formal claim of
conformance to this document made in any of these cases.
NOTE 1 The contents of PPs, PP-Modules, PP-Configurations and packages are described in more detail in
ISO/IEC 15408-1.
© ISO/IEC 2026 – All rights reserved
ISO/IEC 15408-4:2026(en)
A PP, PP-Configuration, PP-Module or package may use more than one evaluation method or separate set of
evaluation activities.
EXAMPLE 2 Multiple evaluation methods can be used where separate evaluation methods have been defined for
cryptographic operations and for secure channel protocols used in a PP.
NOTE 2 Where exact conformance is used, ISO/IEC 15408-1 states that evaluation methods/evaluation activities
are not allowed to be defined in a PP-Configuration: the evaluation methods/evaluation activities to be used are
included in the PPs and PP-Modules and not in the PP-Configuration).
When a PP, PP-Module, PP-Configuration, or package identifies that certain evaluation methods/evaluation
activities shall be used, then this is done using a standard wording that states the requirement and
references the definition of the evaluation methods/evaluation activities to be used. An ST shall only
identify required evaluation methods and evaluation activities that are included in a PP, PP-Module, PP-
Configuration or package to which the ST claims conformance (i.e. the ST itself shall not add, modify or
remove any evaluation methods or evaluation activities). An ST shall include identification of all evaluation
methods/evaluation activities that it requires (i.e. including any that are required by PPs, PP-Modules, PP-
Configurations, or packages to which the ST claims conformance), so that there is a single list that can be
checked and referenced by evaluators and readers of the ST.
Evaluation methods and evaluation activities may be defined as part of a PP or required externally in a
different document (or in a combination of both). Although identification is required as described in the
paragraph above, it is not necessary to reproduce the text of the evaluation methods/evaluation activities in
other documents. For example, an ST is not required to include the full text of the evaluation methods and
evaluation activities from a PP to which it claims conformance.
4.2 Deriving evaluation methods and evaluation activities
In general, defining evaluation activities and evaluation methods can start either from an SAR, aiming to
make some or all parts of its work units more specific, or from an SFR, aiming to define specific aspects of
work units related to that SFR.
When starting from an SAR, the process is as follows.
— Identify the relevant ISO/IEC 18045 work units from which at least one individual evaluation activity or
groups of evaluation activities shall be derived;
— For each work unit from which an evaluation activity is derived:
— define the new evaluation activities in terms of the specific work to be carried out and evaluation
criteria as described in 6.2 (including, if required, pass/fail criteria as described in 6.2.8);
— group evaluation activities into an evaluation method if necessary;
— state the rationale for the new evaluation activities and the evaluation method under which they are
grouped as described in 5.2.10 and 6.2.10.
EXAMPLE 1 A rationale can include reference to the developer action, and content and presentation elements of the
work units from which they are derived.
A process for starting from an SFR is as follows:
— identify the relevant SFR,
— identify the SARs (from ISO/IEC 15408-3 or a set of extended SARs, or both) to be addressed for
that particular SFR, and the corresponding ISO/IEC 18045 work units,
— define the new evaluation activities in terms of the specific work to be carried out and evaluation
criteria as described in 6.2 (including, if required, pass/fail criteria as described in 6.2.8). For
example, evaluation activities can be defined to:
© ISO/IEC 2026 – All rights reserved
ISO/IEC 15408-4:2026(en)
— examine the presentation of a specific SFR in the TOE Summary Specification [derived from class
ASE (Security Target (ST) evaluation) (see ISO/IEC 15408-3:2026, Clause 9)],
— examine the presentation of the SFR in the guidance documentation [derived from class AGD
(Guidance documents) (see ISO/IEC 15408-3:2026, Clause 11)],
— to carry out specific tests of the SFR [derived from class ATE (Tests) (see ISO/IEC 15408-3:2026,
Clause 13)].
— map the affected work units for the SARs to the new evaluation activities;
— state the rationale for the new evaluation activities, and the evaluation method under which they are
grouped, as described in 5.2.10 and 6.2.10.
Although an author may choose to start from SARs or SFRs, it is noted that SARs ultimately cover all SFRs.
Starting from SFRs as described here is a technique that can be useful when clarifying the detail of how an
SAR applies to a particular SFR, and that can be useful for presenting SFRs alongside the description of their
evaluation activities.
It is not required to have a 1:1 mapping between work units and new evaluation activities, and the actual
correspondence is documented in a rationale (as described in 5.2.10). The derivation may be made in terms
of individual work units or groups of work units, and this is depicted in Figure 2. In case a) of Figure 2, the
author maps each work unit from ISO/IEC 18045 to a corresponding evaluation activity, while in case b), the
author maps different numbers of work units and evaluation activities, while still addressing all aspects of
an action (i.e. the collection of work units).
Figure 2 — Alternative approaches to mapping CEM to derived evaluation activities
Other approaches are possible depending on the content of the specific work units and evaluation activities:
even where the same number of work units and evaluation activities exist, a simple 1:1 mapping is sometimes
© ISO/IEC 2026 – All rights reserved
ISO/IEC 15408-4:2026(en)
not possible and therefore a mapping at the action level can be appropriate. Some more detailed mapping
situations are described in the examples below.
NOTE These examples assume that the evaluation activities described are being defined by a community that can
judge the suitability of the rationale for completeness of the evaluation activities. The examples are concerned only
with the form and structure of the mappings, not with the nature or acceptance of the completeness rationale.
EXAMPLE 2 For a TOE type that includes both software and hardware, additional evaluation activities can be defined
to deal with the manufacturing environment and its processes. Considering the ALC_DVS (Developer environment
security) (see ISO/IEC 15408-3:2026, 12.5) family, a possible approach is to adopt all the existing ALC_DVS (Developer
environment security) (see ISO/IEC 15408-3:2026, 12.5) work units for the software development environment and
to define additional evaluation activities for each of the relevant hardware and manufacturing aspects. These aspects
can include extensions of the normal ALC_DVS (Developer environment security) (see ISO/IEC 15408-3:2026, 12.5)
scope to additional items such as protection of hardware design in the development environment, secure transfer of
software from the development environment to the manufacturing environment, security of the manufacturing site,
and protection of the manufactured product while awaiting delivery. They can also include new aspects related to
objects and processes that arise only in the manufacturing environment, such as:
— confirming that the firmware used on a manufacturing line is reliably obtained from the authorized version
created on the firmware build system;
— checking configuration management of test programs for testing the TOE on the manufacturing line;
— confirming that processes to disable test or debug interfaces on the TOE operate correctly and reliably;
— examining the physical and logical security of key management systems used to inject keys or certificates into the
TOE during manufacture.
In this example, the original ALC_DVS.1.1E (see ISO/IEC 15408-3:2026, 12.5.4) action is mapped to include
all the new evaluation activities. An alternative approach is to define additional evaluation activities for
each individual work unit for ALC_DVS.1.1E (see ISO/IEC 15408-3:2026, 12.5.4), identifying the additional
activities to cover the manufacturing environment for that work unit.
EXAMPLE 3 Another example can be if AVA_VAN.1 (Vulnerability survey) (see ISO/IEC 15408-3:2026, 14.3.3)
vulnerability analysis is applied to a particular type of TOE, and there is a specific requirement to achieve consistency
in the public domain vulnerability sources used. A possible approach is to define an evaluation activity that covers the
AVA_VAN (Vulnerability analysis) (see ISO/IEC 15408-3:2026, 14.3) work unit dealing with searching public domain
sources by specifying the particular sources to be used. It is possible to do this with particular searches to be carried
out and decision criteria for selecting a resulting list of potential vulnerabilities to be analysed and tested. In this
example the original AVA_VAN.1–3 (see ISO/IEC 18045:2026, 16.3.1.5.2) work unit is mapped to the new evaluation
activity.
EXAMPLE 4
— For an evaluation method to be used with hardware such as an integrated circuit, evaluation activities can be
defined to examine the circuit's architecture, defining required inputs that give the evaluator specific details about
the operations and information available through the circuit's interfaces. The definition of these required inputs
can then make clear that the relevant interfaces include the circuit's physical surface, its executable programming
instructions, and its communication interfaces.
— Further evaluation activities within the evaluation method can examine the circuit's resistance against physical
probing in order to prevent manipulating or disabling TSF features.
— For testing activities, evaluation activities within the evaluation method can define a required input that presents
the circuit's design as a flow chart of security functions permeating through the circuit's subsystems. The flow
chart can then be used by the evaluator to create test cases and to confirm the test coverage of the circuit.
EXAMPLE 5
— For a TOE type such as a network device that provides cryptographically verifiable firmware updates, evaluation
activities can give specific details of how the evaluator is required to review the Security Target and guidance
documentation to confirm certain specific characteristics required of the cryptographic update process.
— Other evaluation activities can define specific test cases covering the verification of the current firmware, the
availability of updates, fetching updates, verifying the source of the updates using cryptographic signatures, and
the use of specific types of invalid update in order to test the TOE's acceptance functions.
© ISO/IEC 2026 – All rights reserved
ISO/IEC 15408-4:2026(en)
4.3 Verb usage in the description of evaluation methods and evaluation activities
Where a verb is defined in ISO/IEC 15408-1 then the description of evaluation activities shall use those verbs
only in accordance with the definitions. Alternative verbs may be used in an evaluation method for use in
its evaluation activities provided that the alternative verbs are defined in the evaluation method. Any such
verb definition shall make clear the extent to which evaluator judgement (as opposed to simple checking) is
involved.
EXAMPLE An evaluation method that includes automated test generation for a protocol can define a verb “cover”,
applied to enumerated types in a protocol parameter, to mean trying all defined and undefined values of the parameter
within the available parameter length. Then evaluation activities can be written in forms such as “The evaluator shall
cover the PaymentMode field”.
4.4 Conventions for the description of evaluation methods and evaluation activities
Conventions used in ISO/IEC 15408-3 and ISO/IEC 18045 support consistency within, and between, the
descriptions of evaluation methods and evaluation activities.
All work unit and sub-task verbs are preceded by the auxiliary verb “shall” and by presenting both the
verb and the “shall” in bold italic type face. The auxiliary verb “shall” is used only when the provided text is
mandatory and therefore only within the work units and sub-tasks. The work units and sub-tasks contain
mandatory activities that the evaluator shall perform in order to assign verdicts.
Guidance text accompanying work units and sub-tasks gives further explanation on how to apply the work
units and sub-tasks in an evaluation.
5 Structure of an evaluation method
5.1 Overview
An evaluation method and its constituent evaluation activities are defined for use in a particular evaluation
context. For example, separate evaluation methods may be defined for specific technology areas which can
range from specific functions up to specific product types or even in extreme cases, for a specific product
when the product is evaluated for unique features but where there is a requirement to have the product
evaluated using a separately defined method that supports visibility, repeatability and reproducibility of the
evaluation.
EXAMPLE Evaluation contexts for which separate evaluation methods can be defined are:
— specific product types like network devices, smart cards, biometric devices, mobile devices;
— specific security functions reused for multiple product types, such as cryptographic functions, cryptographic
protocols, digital certificate validation, identification and authentication schemes.
An evaluation method comprises a collection of individual evaluation activities, with additional information
about the way in which the evaluation activities collectively meet a goal related to an identified evaluation
context.
The description of an evaluation method includes:
— identification of the entity that is responsible for definition and maintenance of the evaluation method;
— the intended scope of the evaluation method, identifying the objective for deriving the evaluation
activities in the evaluation method, the evaluation context in which it is intended to be applied, and any
known limitation of, or aspects not intended to be covered by, the evaluation method;
— any tool types and/or evaluator competences required to carry out the evaluation activities contained in
the evaluation method;
— any requirements for reporting on the results of applying the evaluation method;
© ISO/IEC 2026 – All rights reserved
ISO/IEC 15408-4:2026(en)
— identification of each work unit in ISO/IEC 18045 (or equivalent for an extended SAR) that is addressed
by the evaluation activities in the evaluation method;
— identification of any extended SARs from which an evaluation method is derived (if applicable);
— any additional verbs used in the description of evaluation activities in place of verbs defined in
ISO/IEC 15408-1.
Further description of the content, including identification of which content elements are mandatory,
and how content elements may be distributed between evaluation method and its evaluation activities, is
given in 5.2 and 6.2 and is summarized in Table 1. Where a content element is optional (e.g. identification
of specific evaluator competences, or required tool types), then that part may simply be omitted from the
relevant definition: it is not necessary to include a blank section.
5.2 Specification of an evaluation method
5.2.1 Overview
An evaluation method is specified in terms of the information identified in 5.2.2 to 5.2.12. No specific
format is required for providing or presenting this information, except where stated for individual elements
in 5.2.2 to 5.2.12. The purpose of specifying the description of an evaluation method in 5.2.2 to 5.2.12 is
to ensure that the assurance techniques used in an evaluation can be unambiguously identified, and that
the evaluation method is used appropriately (in the context for which it was intended) and in a way that
supports consistent evaluation results.
In general, the description of an evaluation method can be taken to include the descriptions of the individual
evaluation activities that it contains. This means that aspects of the evaluation method description may be
deduced from the evaluation activity descriptions.
Figure 3 illustrates the content described in this document for an evaluation method. It does not define a
mandatory structure for describing an evaluation method.
Figure 3 — Contents of an evaluation method
© ISO/IEC 2026 – All rights reserved
ISO/IEC 15408-4:2026(en)
The contents shown in Figure 3 are described in more detail in 5.2.2 to 5.2.12 and 6.2. A summary of the
mandatory and optional requirements for specifying evaluation methods and evaluation activities is given
in Table 1.
Table 1 — Distribution of content between evaluation methods and evaluation activities
Content element Evaluation Evaluation
method activity
Identifier Mandatory Mandatory
Entity Responsible Mandatory Not applicable
Scope Mandatory Not applicable
Dependencies Optional Optional
Required inputs Mandatory Mandatory
Required tool types Optional Optional
Required evaluator competences Optional Optional
Requirements for reporting Optional Optional
Rationale Mandatory Mandatory
Evaluation activities Mandatory Not applicable
Additional verb definitions Optional Not applicable
Objective Not applicable Mandatory
Evaluation activity links to SFRs, SARs and other evaluation activities Not applicable Optional
Assessment strategy Not applicable Mandatory
Pass/fail criteria Not applicable Optional
5.2.2 Identification of evaluation methods
The definition of an evaluation method shall include a unique identifier in order to unambiguously identify
the set of evaluation activities to be applied in any given evaluation. An identifier shall be assigned at the
evaluation method level (rather than just at the level of the evaluation activities it contains), reflecting the
fact that an evaluation method is intended to be applied as a whole, and is subject to rationale and defined
purpose and objectives at this level. If a set of evaluation activities has been grouped into an evaluation
method, then it shall only be identified as the same evaluation method when the complete set of evaluation
activities in the evaluation method is used, with the same rationale as contained in the original evaluation
method. If there is a need to divide the evaluation method into smaller subsets of evaluation activities, then
a separate evaluation method, with its own rationale, shall be defined for each subset.
EXAMPLE 1 A unique identifier expressed by the title and version number of a supporting document or PP
containing the evaluation method.
EXAMPLE 2 An identifier obtained from
...



