Skip to content
Resource_Centre_600x320

Practical resources for navigating compliance, testing, and global market access.

Blog_writing_600x320

Expert insights on compliance, testing, certification, and evolving regulatory requirements.

Certificate_Finder_600x320

Verify certificate authenticity and certification status through Nemko’s online platform.

Locations_600x320

Find Nemko locations worldwide and connect with local experts for testing, certification, compliance, and global market access services.

Cybersecurity vector banner. 8-1

Cybersecurity Common Criteria evaluation and certification

ISO/IEC 15408-1:2009 provides an internationally-accepted framework for evaluating the security of information technology equipment (ITE). Also known as the 'Common Criteria', this standard details widely accepted criteria for the design, development, and evaluation of IT equipment for cyber security consideration.

portrait_two_creative_young_female_male

Certified by Nemko.
Trusted by the world.

Manufacturers worldwide trust Nemko’s independent testing and certification to ensure product safety, compliance, and global market access.
Global Market Access H1

Global trust starts with certified products

Gain access to global markets with Nemko’s independent testing, certification, and worldwide compliance expertise
safety-testing-experts

Your Trusted Partner in Product Certification

From testing to certification, Nemko helps manufacturers ensure safety, compliance, and global market access. 

Compliance with the Common Criteria detailed in ISO/IEC 15408-1 consists of two quality assurance aspects:

  • Assessment of Security Assurance Requirements (SARs) — This is a review of the processes undertaken during the development and evaluation of a given IT product to assess compliance with the prescribed security functionality, which may vary depending on their intended use and anticipated risk environment.

  • Evaluation Assurance Level (EAL) — This assesses the difficulty of the evaluation process itself, and can range from the most basic level of cyber security (EAL 1) through the most rigorous process to verify the claimed level of security (EAL 7).


How Nemko Can Help


Nemko can provide comprehensive guidance according to the Common Criteria requirements detailed in ISO/IEC 15408-1

  • Protection Profile Assessment — Procurement organizations may require third-party vendors to offer evidence that their product has been designed to conform to the requirements of one or more protection profiles (PP). Nemko experts can work with you to assess your equipment's compliance with relevant PPs and provide attestation to support your claims.

  • EAL/Security Target (ST) Assessment — The PP assessment can serve as a basis for defining the required security properties, so Nemko experts can conduct an evaluation of your equipment consistent with both the required STs and the requisite EAL.

  • Nemko can also conduct a preliminary functional gap assessment (FGA) ahead of more formal security analyses to help identify potential issues and ensure that these devices meet essential Common Criteria requirements ahead of time.

Benefits of Working with Nemko

Partnering with Nemko can provide your organization in addressing the challenges that occur in today's cyber security landscape.

Recognized Cyber Security Expertise

Acquired by Nemko in 2020, Systemsikkerhet is Norway's first information security consultancy and is one of only four information security testing laboratories authorized to perform Common Criteria evaluations, by the National certification authorities for IT security (SERTIT)

Active Involvement in Standards Development and Implementation

Nemko’s team of experts have developed state-of-the-art cyber security standards and protocols, and are knowledgeable about all new, emerging requirements.

Single Source Solution

With its combined expertise in cyber security, product safety, Radio/Telecom and electromagnetic compatibility (EMC), Nemko is a robust source for manufacturers.

Global Support

Nemko helps to support your global market access efforts, offering more than 30 locations across six continents around the world.

ilac mra

Compliance made clear

Compliance requirements can slow progress and create unnecessary risk. Nemko integrates compliance into the product development process to help teams reduce rework, simplify approvals, and move products to market with confidence.

Product testing

Product Testing

Make sure that risk and safety are taken care of by our internationally accredited organisation of engineers and testing laboratories.

Product certification

icon 02 - blue

As your certification partner, we provide certification marks that cover numerous multinational and national certification schemes.

Global market access

nb-nk-blue-icon-4

Conquer global markets with confidence—uncover the regulatory requirements for your target market here. 

Cyber assurance

Nemko_Cyber_security_logo_-_RGB_-_color

Our cyber security team helps you understand your cyber risk levels so you can efficiently and effectively protect your assets.

Management system certification

Management System Certification

Our highly experienced auditors provide accurate and insightful audit results to help you achieve management system certification.

Pre-compliance testing

Pre compliance Testing

Save your company valuable time and money by involving Nemko early in the product development process.

Field evaluation and special inspection services

Field Evaluation

As a Nationally Recognized Test Laboratory (NRTL), Nemko offers Field Evaluation and Special Inspection Services as a fast and economical alternative to traditional product safety certification.

Upcoming Events

Cybersecurity by Design: Preparing Connected Products for Global Compliance

Nemko Italy Customer Seminar 2026

Italy AI Training

Compliance without Complexity - SPS in Nürnberg

Other posts you might be interested in

Monitoring IT specialists wearing shirts analyzing code

For more information

Learn more about how Nemko can help your organization meet current and emerging cyber security challenges