Common Criteria and EUCC
We support your certification and evaluation needs.
We support your certification and evaluation needs.
Customers, regulators, and procurement authorities increasingly expect independent evidence that digital products can withstand cyber threats. New regulations such as the EU Cyber Resilience Act (CRA) and the European Cybersecurity Act (CSA) are raising the bar for cybersecurity assurance.
Without recognised certification, organisations may face:
For many manufacturers and software providers, demonstrating trust has become just as important as building secure technology.
As a Conformity Assessment Body (CAB) and a Notified Body (NB), Combitech operates both a Certification Center and an Evaluation Center, providing a complete pathway to Common Criteria and EUCC certification.
We support organisations throughout the certification process, including:
Our experts assess products against internationally recognised requirements and verify security functionality, documentation, lifecycle management, and resilience against cyber threats.
Since 2007, our Evaluation Center has contributed to nearly 100 internationally recognised certifications across product categories including network equipment, printers, databases, PKI systems, applications, and KVM switches.
Certification is more than a compliance exercise. It creates tangible business value.
By obtaining Common Criteria certification, you can:
Want to learn more about Common Criteria and EUCC, and how we can support your certification and evaluation needs? Contact us!
Combitech operates as both an accredited Certification Center and an accredited Information Technology Security Evaluation Facility (ITSEF). Our activities are conducted in accordance with applicable requirements, the EU Cybersecurity Act, the European Cybersecurity Certification Scheme (EUCC), and the Common Criteria Recognition Arrangement (CCRA).
Accreditation is an independent confirmation that a conformity assessment body has the competence, impartiality and processes required to perform certification and evaluation activities. For customers, accreditation provides confidence that assessments are performed according to recognised international standards and accepted methodologies.
Read more: Combitech AB, accreditation 1914 | Swedac
A notified body is an organisation that has been formally designated by a member state and recognised by the European Commission to carry out conformity assessment activities under specific regulatory frameworks. Within cybersecurity certification, notified bodies play an important role in ensuring that products are assessed consistently and according to applicable European requirements.
Read more: EUROPA – European Commission – Growth – Regulatory policy - SMCS
Combitech maintains a public register of certificates issued through the Certification Center. The register provides information about certified products and issued certificates, allowing customers, authorities and stakeholders to verify certification status.
Read more:
Public availability increases transparency and confidence in the certification process. It allows purchasers, system integrators and regulators to verify that products have successfully completed an independent assessment.
Combitech publishes information about ongoing certification activities where publication is permitted by the certificate applicant. The overview provides visibility into current certification projects and product categories undergoing assessment.
Read more: Current Certifications
Visibility into ongoing certifications demonstrates industry activity and helps stakeholders understand which product categories are currently being evaluated under recognised certification frameworks.
Our document library contains information relevant to applicants, vendors and stakeholders. These documents help organisations prepare for a successful certification process.
Read more:
We recommend reviewing the relevant documentation as early as possible. Early preparation helps reduce delays and ensures that product documentation, development processes and security evidence align with certification requirements.
The Certification Center provides:
The Certification Center independently reviews evaluation results and verifies compliance with applicable certification requirements before issuing certificates.
We guide applicants through the certification process, explain requirements, coordinate activities when needed and ensure that certification activities are performed according to recognised standards and schemes. We can also support the development of required documentation by our Evaluation Center.
Our Evaluation Center provides:
The Evaluation Center performs the technical assessment of products and produces the evidence required for certification.
An evaluation typically includes:
The resulting evaluation report is then reviewed by the Certification Center as part of the certification process.