Common Criteria and EUCC

We support your certification and evaluation needs.

Your product may be secure. Proving it is the challenge.

Customers, regulators, and procurement authorities increasingly expect independent evidence that digital products can withstand cyber threats. New regulations such as the EU Cyber Resilience Act (CRA) and the European Cybersecurity Act (CSA) are raising the bar for cybersecurity assurance.

Without recognised certification, organisations may face:

  • Difficulty qualifying for security-sensitive procurements
  • Delayed access to European and international markets
  • Increased scrutiny from customers and authorities
  • Challenges demonstrating compliance with cybersecurity requirements
  • Limited opportunities in defence, critical infrastructure, and NATO-related procurement processes

For many manufacturers and software providers, demonstrating trust has become just as important as building secure technology.

Network cables connected to switch.

Independent certification and evaluation

As a Conformity Assessment Body (CAB) and a Notified Body (NB), Combitech operates both a Certification Center and an Evaluation Center, providing a complete pathway to Common Criteria and EUCC certification.

We support organisations throughout the certification process, including:

  • EUCC certifications under the EU Cybersecurity Act
  • CCRA certifications
  • Common Criteria ISO/IEC 15408 evaluations
  • Product certification according to SS-EN ISO/IEC 17065
  • Security evaluations, testing, and vulnerability analysis
  • Consulting and training

Our experts assess products against internationally recognised requirements and verify security functionality, documentation, lifecycle management, and resilience against cyber threats.

Since 2007, our Evaluation Center has contributed to nearly 100 internationally recognised certifications across product categories including network equipment, printers, databases, PKI systems, applications, and KVM switches.

Laptop showing software development code

Turn cybersecurity assurance into a competitive advantage

Certification is more than a compliance exercise. It creates tangible business value.

By obtaining Common Criteria certification, you can:

  • Strengthen market confidence: Provide independent evidence that your product's security claims have been verified.
  • Accelerate market access: Support procurement requirements across Europe and access markets where cybersecurity certification is expected.
  • Support CRA compliance: Demonstrate alignment with security requirements introduced through the Cyber Resilience Act.
  • Enable NATO opportunities: Certified products can become eligible for inclusion in recognised catalogues used in NATO-related procurement processes.
  • Reduce customer risk concerns: A recognised certificate provides assurance to buyers evaluating critical technologies.
  • Differentiate from competitors: Stand out in markets where security and trust directly influence purchasing decisions.

Want to learn more about Common Criteria and EUCC, and how we can support your certification and evaluation needs? Contact us!

Questions and answers

What authorisations and accreditations does Combitech hold?

arrow_drop_down

    Combitech operates as both an accredited Certification Center and an accredited Information Technology Security Evaluation Facility (ITSEF). Our activities are conducted in accordance with applicable requirements, the EU Cybersecurity Act, the European Cybersecurity Certification Scheme (EUCC), and the Common Criteria Recognition Arrangement (CCRA). 

What is accreditation and why is it important?

arrow_drop_down

    Accreditation is an independent confirmation that a conformity assessment body has the competence, impartiality and processes required to perform certification and evaluation activities. For customers, accreditation provides confidence that assessments are performed according to recognised international standards and accepted methodologies.

    Read more: Combitech AB, accreditation 1914 | Swedac

What are notified bodies?

arrow_drop_down

    A notified body is an organisation that has been formally designated by a member state and recognised by the European Commission to carry out conformity assessment activities under specific regulatory frameworks. Within cybersecurity certification, notified bodies play an important role in ensuring that products are assessed consistently and according to applicable European requirements.

    Read more: EUROPA – European Commission – Growth – Regulatory policy - SMCS

What certificates has Combitech issued?

arrow_drop_down

    Combitech maintains a public register of certificates issued through the Certification Center. The register provides information about certified products and issued certificates, allowing customers, authorities and stakeholders to verify certification status.

    Read more:

Why are issued certificates publicly available?

arrow_drop_down

    Public availability increases transparency and confidence in the certification process. It allows purchasers, system integrators and regulators to verify that products have successfully completed an independent assessment. 

Which certifications are currently in progress?

arrow_drop_down

    Combitech publishes information about ongoing certification activities where publication is permitted by the certificate applicant. The overview provides visibility into current certification projects and product categories undergoing assessment.

    Read more: Current Certifications

Why publish ongoing certifications?

arrow_drop_down

    Visibility into ongoing certifications demonstrates industry activity and helps stakeholders understand which product categories are currently being evaluated under recognised certification frameworks.

Where can I find certification documents and guidance?

arrow_drop_down

    Our document library contains information relevant to applicants, vendors and stakeholders. These documents help organisations prepare for a successful certification process.

    Read more:

When should I review the available documentation?

arrow_drop_down

    We recommend reviewing the relevant documentation as early as possible. Early preparation helps reduce delays and ensures that product documentation, development processes and security evidence align with certification requirements.

What services does the Certification Center provide?

arrow_drop_down

    The Certification Center provides: 

    • EUCC certification services 
    • CCRA certification activities 
    • Certification according to SS-EN ISO/IEC 17065 
    • Certification oversight and verification 
    • Certificate issuance and maintenance 

    The Certification Center independently reviews evaluation results and verifies compliance with applicable certification requirements before issuing certificates. 

How does the Certification Center support product vendors?

arrow_drop_down

    We guide applicants through the certification process, explain requirements, coordinate activities when needed and ensure that certification activities are performed according to recognised standards and schemes. We can also support the development of required documentation by our Evaluation Center.

What services does the Evaluation Center provide?

arrow_drop_down

    Our Evaluation Center provides:

    • Common Criteria evaluations (EUCC and CCRA) 
    • Development of evaluation evidence 
    • Security testing 
    • Vulnerability assessments 
    • Technical consulting 
    • Training services 

    The Evaluation Center performs the technical assessment of products and produces the evidence required for certification. 

What happens during an evaluation?

arrow_drop_down

    An evaluation typically includes: 

    • Review of security documentation 
    • Analysis of security functionality 
    • Verification of lifecycle management processes 
    • Security testing 
    • Vulnerability analysis 

    The resulting evaluation report is then reviewed by the Certification Center as part of the certification process. 

Want to learn more about Common Criteria and EUCC? Contact us!

Peter Döös

Business Unit Manager

peter.doos@combitech.com

+46 (0)734-46 92 65