Overview
EN ISO/IEC 15408-3:2026 is a key international standard developed by CEN, focusing on information security, cybersecurity, and privacy protection. As Part 3 of the ISO/IEC 15408 series (commonly known as the Common Criteria for Information Technology Security Evaluation), this document specifies the security assurance components used in the evaluation of IT security. It details the individual assurance components that form the basis for Evaluation Assurance Levels (EALs) and other security assurance packages referenced in ISO/IEC 15408-5.
This standard provides criteria for the evaluation of Protection Profiles (PPs), PP-Configurations, PP-Modules, and Security Targets (STs) - foundational elements in formal IT security evaluations for a broad range of digital assets.
Key Topics
-
Security Assurance Components
The standard defines assurance components that measure how thoroughly a system or product’s security requirements are specified, designed, and tested. These components are structured into classes, families, and individual elements.
-
Evaluation Assurance Level (EAL) Foundation
EN ISO/IEC 15408-3:2026 outlines the building blocks from which EALs are constructed. These EALs are widely used to communicate the rigor of security evaluations to stakeholders and customers.
-
Criteria for Protection Profiles and Security Targets
The standard sets out the methodology and criteria for developing and evaluating PPs, PP-Modules, PP-Configurations, and STs. This ensures a consistent approach to specifying and assessing security in IT products and systems.
-
Component Structure & Dependencies
Assurance components are systematically organized, with clear descriptions, objectives, application notes, and dependencies, supporting modular evaluation and efficient reuse of security specifications.
Applications
-
IT Product Certification
Product developers use the standard to define and demonstrate the security assurance of software, hardware, and embedded systems during product certification processes under recognized Common Criteria schemes.
-
Risk Management
Organizations and IT professionals rely on assurance components to select products and solutions that meet specific risk management and regulatory requirements regarding cybersecurity and privacy.
-
Procurement and Compliance
Government and regulated industries reference security assurance levels and Protection Profiles defined using EN ISO/IEC 15408-3 in procurement specifications, ensuring products meet rigorous security expectations.
-
Development of Protection Profiles (PPs)
Security architects and analysts use the criteria when drafting PPs for families of products, promoting standardization, comparability, and transparency across the IT security landscape.
-
Security Target (ST) Preparation
Vendors and solution providers utilize the detailed criteria for constructing Security Targets, tailoring assurance arguments to particular products and operational environments.
Related Standards
-
EN ISO/IEC 15408-1: Information security - Evaluation criteria for IT security - Part 1: Introduction and general model
Outlines the general principles and model underlying the security evaluation process.
-
EN ISO/IEC 15408-2: Information security - Evaluation criteria for IT security - Part 2: Security functional components
Specifies the requirements for security functionality in IT systems.
-
EN ISO/IEC 15408-5: Information security - Evaluation criteria for IT security - Part 5: Pre-defined packages
Provides ready-to-use packages of functional and assurance requirements.
-
ISO/IEC 18045: Information security techniques - Methodology for IT security evaluation
Details the processes and activities for conducting security evaluations in line with the ISO/IEC 15408 series.
By providing a consistent and internationally recognized framework for specifying and assessing security assurance, EN ISO/IEC 15408-3:2026 enables organizations to improve IT security, demonstrate compliance, and gain customer trust within ever-evolving threat landscapes. For those involved in product development, assurance certification, or procurement, aligning with this standard is essential for demonstrating robust information security, cybersecurity, and privacy protection.