General Information

Abstract

This document specifies the security assurance requirements of the ISO/IEC 15408 series. It includes the individual assurance components from which the evaluation assurance levels and other packages contained in ISO/IEC 15408-5 are composed, and the criteria for evaluation of Protection Profiles (PPs), PP-Configurations, PP-Modules and Security Targets (STs).

Status
Published
Publication Date
26-May-2026
Current Stage
6060 - Definitive text made available (DAV) - Publishing
Start Date
27-May-2026
Completion Date
27-May-2026

Buy Documents

Standard

EN ISO/IEC 15408-3:2026

English language (190 pages)
Preview
Preview
e-Library read for
1 day

Overview

EN ISO/IEC 15408-3:2026 is a key international standard developed by CEN, focusing on information security, cybersecurity, and privacy protection. As Part 3 of the ISO/IEC 15408 series (commonly known as the Common Criteria for Information Technology Security Evaluation), this document specifies the security assurance components used in the evaluation of IT security. It details the individual assurance components that form the basis for Evaluation Assurance Levels (EALs) and other security assurance packages referenced in ISO/IEC 15408-5.

This standard provides criteria for the evaluation of Protection Profiles (PPs), PP-Configurations, PP-Modules, and Security Targets (STs) - foundational elements in formal IT security evaluations for a broad range of digital assets.

Key Topics

  • Security Assurance Components
    The standard defines assurance components that measure how thoroughly a system or product’s security requirements are specified, designed, and tested. These components are structured into classes, families, and individual elements.

  • Evaluation Assurance Level (EAL) Foundation
    EN ISO/IEC 15408-3:2026 outlines the building blocks from which EALs are constructed. These EALs are widely used to communicate the rigor of security evaluations to stakeholders and customers.

  • Criteria for Protection Profiles and Security Targets
    The standard sets out the methodology and criteria for developing and evaluating PPs, PP-Modules, PP-Configurations, and STs. This ensures a consistent approach to specifying and assessing security in IT products and systems.

  • Component Structure & Dependencies
    Assurance components are systematically organized, with clear descriptions, objectives, application notes, and dependencies, supporting modular evaluation and efficient reuse of security specifications.

Applications

  • IT Product Certification
    Product developers use the standard to define and demonstrate the security assurance of software, hardware, and embedded systems during product certification processes under recognized Common Criteria schemes.

  • Risk Management
    Organizations and IT professionals rely on assurance components to select products and solutions that meet specific risk management and regulatory requirements regarding cybersecurity and privacy.

  • Procurement and Compliance
    Government and regulated industries reference security assurance levels and Protection Profiles defined using EN ISO/IEC 15408-3 in procurement specifications, ensuring products meet rigorous security expectations.

  • Development of Protection Profiles (PPs)
    Security architects and analysts use the criteria when drafting PPs for families of products, promoting standardization, comparability, and transparency across the IT security landscape.

  • Security Target (ST) Preparation
    Vendors and solution providers utilize the detailed criteria for constructing Security Targets, tailoring assurance arguments to particular products and operational environments.

Related Standards

  • EN ISO/IEC 15408-1: Information security - Evaluation criteria for IT security - Part 1: Introduction and general model
    Outlines the general principles and model underlying the security evaluation process.

  • EN ISO/IEC 15408-2: Information security - Evaluation criteria for IT security - Part 2: Security functional components
    Specifies the requirements for security functionality in IT systems.

  • EN ISO/IEC 15408-5: Information security - Evaluation criteria for IT security - Part 5: Pre-defined packages
    Provides ready-to-use packages of functional and assurance requirements.

  • ISO/IEC 18045: Information security techniques - Methodology for IT security evaluation
    Details the processes and activities for conducting security evaluations in line with the ISO/IEC 15408 series.


By providing a consistent and internationally recognized framework for specifying and assessing security assurance, EN ISO/IEC 15408-3:2026 enables organizations to improve IT security, demonstrate compliance, and gain customer trust within ever-evolving threat landscapes. For those involved in product development, assurance certification, or procurement, aligning with this standard is essential for demonstrating robust information security, cybersecurity, and privacy protection.

Relations

Effective Date
22-May-2024
Effective Date
24-Jun-2026
Effective Date
24-Jun-2026
Effective Date
24-Jun-2026
Effective Date
24-Jun-2026
Effective Date
24-Jun-2026
Effective Date
12-Feb-2026

Buy Documents

Standard

EN ISO/IEC 15408-3:2026

English language (190 pages)
Preview
Preview
e-Library read for
1 day

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

EN ISO/IEC 15408-3:2026 is a standard published by the European Committee for Standardization (CEN). Its full title is "Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 3: Security assurance components (ISO/IEC 15408-3:2026)". This standard covers: This document specifies the security assurance requirements of the ISO/IEC 15408 series. It includes the individual assurance components from which the evaluation assurance levels and other packages contained in ISO/IEC 15408-5 are composed, and the criteria for evaluation of Protection Profiles (PPs), PP-Configurations, PP-Modules and Security Targets (STs).

This document specifies the security assurance requirements of the ISO/IEC 15408 series. It includes the individual assurance components from which the evaluation assurance levels and other packages contained in ISO/IEC 15408-5 are composed, and the criteria for evaluation of Protection Profiles (PPs), PP-Configurations, PP-Modules and Security Targets (STs).

EN ISO/IEC 15408-3:2026 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security. The ICS classification helps identify the subject area and facilitates finding related standards.

EN ISO/IEC 15408-3:2026 has the following relationships with other standards: It is inter standard links to EN ISO/IEC 15408-3:2023, ISO/IEC 15408-2:2026, ISO/IEC 15408-5:2026, ISO/IEC 15408-1:2026, ISO/IEC 18045:2026, ISO/IEC 15408-4:2022, ISO/IEC 15408-3:2026. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

EN ISO/IEC 15408-3:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


SLOVENSKI STANDARD
01-oktober-2026
Nadomešča:
SIST EN ISO/IEC 15408-3:2024
Informacijska varnost, kibernetska varnost in varstvo zasebnosti - Merila za
vrednotenje varnosti IT - 3. del: Komponente za zagotavljanje varnosti (ISO/IEC
15408-3:2026)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT
security - Part 3: Security assurance components (ISO/IEC 15408-3:2026)
Informationssicherheit, Cybersicherheit und Schutz der Privatsphäre -
Evaluationskriterien für IT-Sicherheit - Teil 3: Komponenten für die Vertrauenswürdigkeit
der Sicherheit (ISO/IEC 15408-3:2026)
Sécurité de l'information, cybersécurité et protection de la vie privée - Critères
d'évaluation pour la sécurité des technologies de l'information - Partie 3: Composants
d'assurance de sécurité (ISO/IEC 15408-3:2026)
Ta slovenski standard je istoveten z: EN ISO/IEC 15408-3:2026
ICS:
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

EUROPEAN STANDARD EN ISO/IEC 15408-3

NORME EUROPÉENNE
EUROPÄISCHE NORM
May 2026
ICS 35.030
Supersedes EN ISO/IEC 15408-3:2023
English version
Information security, cybersecurity and privacy protection
- Evaluation criteria for IT security - Part 3: Security
assurance components (ISO/IEC 15408-3:2026)
Sécurité de l'information, cybersécurité et protection Informationssicherheit, Cybersicherheit und Schutz
de la vie privée - Critères d'évaluation pour la sécurité der Privatsphäre - Evaluationskriterien für IT-
des technologies de l'information - Partie 3: Sicherheit - Teil 3: Komponenten für die
Composants d'assurance de sécurité (ISO/IEC 15408- Vertrauenswürdigkeit der Sicherheit (ISO/IEC 15408-
3:2026) 3:2026)
This European Standard was approved by CEN on 1 May 2026.

CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for
giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.

CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.

CEN-CENELEC Management Centre:
Rue de la Science 23, B-1040 Brussels
© 2026 CEN/CENELEC All rights of exploitation in any form and by any means Ref. No. EN ISO/IEC 15408-3:2026 E
reserved worldwide for CEN national Members and for
CENELEC Members.
Contents Page
European foreword . 3

European foreword
This document (EN ISO/IEC 15408-3:2026) has been prepared by Technical Committee ISO/IEC JTC 1
"Information technology" in collaboration with Technical Committee CEN-CENELEC/ JTC 13
“Cybersecurity and Data Protection” the secretariat of which is held by DIN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by November 2026, and conflicting national standards
shall be withdrawn at the latest by November 2026.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN-CENELEC shall not be held responsible for identifying any or all such patent rights.
This document supersedes EN ISO/IEC 15408-3:2023.
Any feedback and questions on this document should be directed to the users’ national standards
body/national committee. A complete listing of these bodies can be found on the CEN and CENELEC
websites.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Endorsement notice
The text of ISO/IEC 15408-3:2026 has been approved by CEN-CENELEC as EN ISO/IEC 15408-3:2026
without any modification.
International
Standard
ISO/IEC 15408-3
Fifth edition
Information security, cybersecurity
2026-05
and privacy protection —
Evaluation criteria for IT security —
Part 3:
Security assurance components
Sécurité de l'information, cybersécurité et protection de la vie
privée — Critères d'évaluation pour la sécurité des technologies
de l'information —
Partie 3: Composants d'assurance de sécurité
Reference number
ISO/IEC 15408-3:2026(en) © ISO/IEC 2026

ISO/IEC 15408-3:2026(en)
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC 15408-3:2026(en)
Contents Page
Foreword .x
Introduction .xi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Overview . 5
5 Assurance paradigm . 5
5.1 General .5
5.2 CC approach .5
5.3 Assurance approach .5
5.3.1 General .5
5.3.2 Significance of vulnerabilities .5
5.3.3 Cause of vulnerabilities .6
5.3.4 CC assurance .6
5.3.5 Assurance through evaluation .6
5.4 CC evaluation assurance scale .7
6 Security assurance components . 7
6.1 General .7
6.2 Assurance class structure .7
6.2.1 General .7
6.2.2 Class name .8
6.2.3 Class introduction .8
6.2.4 Class application notes .8
6.2.5 Assurance families .8
6.3 Assurance family structure .8
6.3.1 General .8
6.3.2 Family name .8
6.3.3 Family objectives .8
6.3.4 Component levelling .9
6.3.5 Family application notes .9
6.3.6 Assurance components .9
6.4 Assurance component structure .9
6.4.1 General .9
6.4.2 Component name .9
6.4.3 Component objectives . .10
6.4.4 Component application notes .10
6.4.5 Component dependencies .10
6.4.6 Assurance elements .10
6.5 Assurance elements .11
6.6 Component taxonomy .11
7 Class APE Protection Profile (PP) evaluation .11
7.1 General .11
7.2 PP introduction (APE_INT) . 12
7.2.1 Objectives . 12
7.2.2 PP introduction (APE_INT.1) . 13
7.3 Conformance claims (APE_CCL) . 13
7.3.1 Objectives . 13
7.3.2 Conformance claims (APE_CCL.1) . 13
7.4 Security problem definition (APE_SPD) . 15
7.4.1 Objectives . 15
7.4.2 Security problem definition (APE_SPD.1) . 15
7.5 Security objectives (APE_OBJ) . 15

© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 15408-3:2026(en)
7.5.1 Objectives . 15
7.5.2 Component levelling . 15
7.5.3 Security objectives for the operational environment (APE_OBJ.1) . 15
7.5.4 Security objectives (APE_OBJ.2) . .16
7.6 Extended components definition (APE_ECD) .17
7.6.1 Objectives .17
7.6.2 Extended components definition (APE_ECD.1) .17
7.7 Security requirements (APE_REQ) .18
7.7.1 Objectives .18
7.7.2 Component levelling .18
7.7.3 Direct rationale security requirements (APE_REQ.1) .18
7.7.4 Derived security requirements (APE_REQ.2) .19
8 Class ACE Protection Profile Configuration evaluation .20
8.1 General . 20
8.2 PP-Module introduction (ACE_INT) . 22
8.2.1 Objectives . 22
8.2.2 PP-Module introduction (ACE_INT.1) . 22
8.3 PP-Module conformance claims (ACE_CCL) . 22
8.3.1 Objectives . 22
8.3.2 PP-Module conformance claims (ACE_CCL.1) . 23
8.4 PP-Module security problem definition (ACE_SPD) .24
8.4.1 Objectives .24
8.4.2 PP-Module security problem definition (ACE_SPD.1) .24
8.5 PP-Module security objectives (ACE_OBJ) .24
8.5.1 Objectives .24
8.5.2 Component levelling .24
8.5.3 PP-Module security objectives for the operational environment (ACE_OBJ.1) .24
8.5.4 PP-Module security objectives (ACE_OBJ.2) . 25
8.6 PP-Module extended components definition (ACE_ECD). 26
8.6.1 Objectives . 26
8.6.2 PP-Module extended components definition (ACE_ECD.1) . 26
8.7 PP-Module security requirements (ACE_REQ) .27
8.7.1 Objectives .27
8.7.2 Component levelling .27
8.7.3 PP-Module direct rationale security requirements (ACE_REQ.1) .27
8.7.4 PP-Module derived security requirements (ACE_REQ.2) . 28
8.8 PP-Module consistency (ACE_MCO) . 29
8.8.1 Objectives . 29
8.8.2 PP-Module consistency (ACE_MCO.1) . 29
8.9 PP-Configuration consistency (ACE_CCO) . 30
8.9.1 Objectives . 30
8.9.2 PP-Configuration consistency (ACE_CCO.1) . 30
9 Class ASE Security Target (ST) evaluation .32
9.1 General .32
9.2 ST introduction (ASE_INT) . 34
9.2.1 Objectives . 34
9.2.2 ST introduction (ASE_INT.1) . 34
9.3 Conformance claims (ASE_CCL) . 34
9.3.1 Objectives . 34
9.3.2 Conformance claims (ASE_CCL.1) . 35
9.4 Security problem definition (ASE_SPD) . 36
9.4.1 Objectives . 36
9.4.2 Security problem definition (ASE_SPD.1) . 36
9.5 Security objectives (ASE_OBJ) . 36
9.5.1 Objectives . 36
9.5.2 Component levelling . 36
9.5.3 Security objectives for the operational environment (ASE_OBJ.1) . 36
9.5.4 Security objectives (ASE_OBJ.2) .37

© ISO/IEC 2026 – All rights reserved
iv
ISO/IEC 15408-3:2026(en)
9.6 Extended components definition (ASE_ECD) . 38
9.6.1 Objectives . 38
9.6.2 Extended components definition (ASE_ECD.1) . 38
9.7 Security requirements (ASE_REQ). 39
9.7.1 Objectives . 39
9.7.2 Component levelling . 39
9.7.3 Direct rationale security requirements (ASE_REQ.1) . 39
9.7.4 Derived security requirements (ASE_REQ.2). 40
9.8 TOE summary specification (ASE_TSS) .41
9.8.1 Objectives .41
9.8.2 Component levelling .41
9.8.3 TOE summary specification (ASE_TSS.1) .41
9.8.4 TOE summary specification with architectural design summary (ASE_TSS.2) .42
9.9 Consistency of composite product Security Target (ASE_COMP) .42
9.9.1 Objectives .42
9.9.2 Component levelling .43
9.9.3 Application notes .43
9.9.4 Consistency of Security Target (ST) (ASE_COMP.1) . 44
10 Class ADV Development .44
10.1 General . 44
10.2 Security architecture (ADV_ARC) . 50
10.2.1 Objectives . 50
10.2.2 Component levelling . 50
10.2.3 Application notes . 50
10.2.4 Security architecture description (ADV_ARC.1) .51
10.3 Functional specification (ADV_FSP) .52
10.3.1 Objectives .52
10.3.2 Component levelling .52
10.3.3 Application notes .52
10.3.4 Basic functional specification (ADV_FSP.1) . 55
10.3.5 Security-enforcing functional specification (ADV_FSP.2) . 55
10.3.6 Functional specification with complete summary (ADV_FSP.3) . 56
10.3.7 Complete functional specification (ADV_FSP.4) .57
10.3.8 Complete semi-formal functional specification with additional error
information (ADV_FSP.5).57
10.3.9 Complete semi-formal functional specification with additional formal
specification (ADV_FSP.6). 58
10.4 Implementation representation (ADV_IMP) .59
10.4.1 Objectives .59
10.4.2 Component levelling .59
10.4.3 Application notes .59
10.4.4 Implementation representation of the TSF (ADV_IMP.1) . 60
10.4.5 Complete mapping of the implementation representation of the TSF (ADV_IMP.2) .61
10.5 TSF internals (ADV_INT) .62
10.5.1 Objectives .62
10.5.2 Component levelling .62
10.5.3 Application notes .62
10.5.4 Well-structured subset of TSF internals (ADV_INT.1) .62
10.5.5 Well-structured internals (ADV_INT.2) . 63
10.5.6 Minimally complex internals (ADV_INT.3) . 64
10.6 Formal TSF model (ADV_SPM). 65
10.6.1 Objectives . 65
10.6.2 Component levelling . 65
10.6.3 Application notes . 65
10.6.4 Formal TSF model (ADV_SPM.1) . 66
10.7 TOE design (ADV_TDS) .67
10.7.1 Objectives .67
10.7.2 Component levelling .67

© ISO/IEC 2026 – All rights reserved
v
ISO/IEC 15408-3:2026(en)
10.7.3 Application notes .67
10.7.4 Basic design (ADV_TDS.1) . 68
10.7.5 Architectural design (ADV_TDS.2) . 69
10.7.6 Basic modular design (ADV_TDS.3) .70
10.7.7 Semi-Formal modular design (ADV_TDS.4) .71
10.7.8 Complete semi-formal modular design (ADV_TDS.5) .71
10.7.9 Complete semi-formal modular design with formal high-level design
presentation (ADV_TDS.6) . 72
10.8 Composite design compliance (ADV_COMP) . 73
10.8.1 Objectives . 73
10.8.2 Component levelling . 73
10.8.3 Application notes . 73
10.8.4 Design compliance with the base component-related user guidance, ETR for
composite evaluation and report of the base component evaluation authority
(ADV_COMP.1) .74
11 Class AGD guidance documents .75
11.1 General . 75
11.2 Operational user guidance (AGD_OPE) . 75
11.2.1 Objectives . 75
11.2.2 Component levelling .76
11.2.3 Application notes .76
11.2.4 Operational user guidance (AGD_OPE.1) .76
11.3 Preparative procedures (AGD_PRE) . 77
11.3.1 Objectives . 77
11.3.2 Component levelling . 77
11.3.3 Application notes . 77
11.3.4 Preparative procedures (AGD_PRE.1) . 78
12 Class ALC life cycle support .78
12.1 General . 78
12.2 CM capabilities (ALC_CMC) . 80
12.2.1 Objectives . 80
12.2.2 Component levelling . 81
12.2.3 Application notes . 81
12.2.4 Labelling of the TOE (ALC_CMC.1) . 81
12.2.5 Use of the CM system (ALC_CMC.2) . 82
12.2.6 Authorization controls (ALC_CMC.3) .
...