Common Criteria


Common Criteria is an ISO standard (ISO 15408) that describes a certification program for technology products and services.

  • outlines an approach for certifying a cloud solution
    • security requirements
    • assigning an assurance level
    • and approving it for operations
  • mostly used in government agencies
  • mostly applies to hardware and software products
    • as opposed to services

Evaluation Assurance Level (EAL)

Evaluation assurance level (EAL) is a numerical rating that indicates the depth and rigor of evaluation from level 1 (basic) to level 7 (most stringent).

  • EAL1
  • EAL2
    • applies when the system has been structurally tested
  • EAL3
  • EAL4
  • EAL5
  • EAL6
  • EAL7
    • applies when a system has been formally verified, designed, and tested