The Canadian Centre for Cyber Security recently released its updated Common Criteria (CC) Program Instructions which state that they will consider accepting EAL3 and EAL4 evaluations on a case by case basis. Evaluations were previously restricted to those claiming an approved Protection Profile (PP) or EAL2.
Based on the updated instructions it’s clear that the Canadians want to make sure that there is a good business case for why they should deploy valuable resources to support a given EAL3/4 evaluation. This will include factors such as where the request for evaluation is coming from (i.e. Government of Canada, a Canadian critical infrastructure sector, or from another country), whether there is an applicable PP and whether the technology / evaluation will provide value to Canada.
Read More