ISO/IEC 15408-1:2022 is part of the internationally recognized Common Criteria (CC) framework for evaluating the security of IT products and systems. This standard provides the foundational introduction and general model for the series, offering a conceptual structure for defining, assessing, and verifying IT security properties.

Common Criteria (CC), formalized through the ISO/IEC 15408 series, enables product developers to speak a common language for cybersecurity assurance. Part 1 introduces key concepts like security targets (STs), protection profiles (PPs), evaluation assurance levels (EALs) and functional and assurance requirements.
Whether you’re developing secure software, embedded systems or cryptographic modules, ISO/IEC 15408-1 provides the essential model for achieving verifiable, comparable, and repeatable IT security evaluations.
Looking to align your cybersecurity products with ISO evaluations? Contact support@demo.pacificcert.com.
ISO/IEC 15408-1:2022 provides the structural framework and foundational terminology for evaluating the security properties of IT systems, products, and components using a standardized approach. It applies to:
The standard supports evaluations at varying degrees of rigor (through EALs) and enables cross-recognition of certifications across countries through schemes like the Common Criteria Recognition Arrangement (CCRA).
Clause | Title | Key Content |
Clause 1 | Scope | Defines applicability to IT product/system evaluation |
Clause 2 | Normative References | Identifies ISO/IEC 15408-2 and 15408-3 as core parts of the Common Criteria set |
Clause 3 | Terms and Definitions | Introduces CC-specific terminology and references ISO/IEC 18045 |
Clause 4 | Abbreviated Terms | Definitions of CC-related acronyms (e.g., TOE, ST, PP, EAL) |
Clause 5 | General Concepts | Explains key CC concepts and rationale for security evaluation |
Clause 6 | The Evaluation Model | Introduces the relationship between PPs, STs, assurance, and evaluation roles |
Clause 7 | Evaluation Context and Stakeholders | Identifies roles of developers, evaluators, consumers, and certifiers |
Clause 8 | TOE Lifecycle Considerations | Discusses TOE development, maintenance, and operational use |
This structure sets the foundation for the more technical criteria in ISO/IEC 15408-2 (functional requirements) and ISO/IEC 15408-3 (assurance requirements).

Looking to map your cybersecurity controls to ISO requirements? Contact support@demo.pacificcert.com.
To align with ISO/IEC 15408-1 and prepare for evaluation, organizations should maintain:
ISO/IEC 15408 remains the most widely accepted international framework for IT security product evaluation. In the era of zero-trust architectures and embedded AI systems, stakeholders are demanding independently evaluated security assurances before procurement or integration. Below are the benefits of implementing:

Governments, financial institutions, and multinational corporations are increasingly requiring Common Criteria evaluations for devices like firewalls, VPNs, smart cards, cryptographic modules, medical devices, and IoT endpoints. ISO/IEC 15408-1 plays a foundational role by defining the common language and high-level framework to scope, plan, and manage security evaluations across jurisdictions.
With cybersecurity product liability and AI governance regulations emerging globally, It is also evolving to support evaluation of autonomous systems, privacy-enhancing technologies, and cross-border compliance.
Pacific Certifications provides audit and certification services aligned with ISO/IEC 27001, ISO 9001, and other management system standards that intersect with ISO/IEC 15408 implementation.
For ISO/IEC 15408-1 our role includes:
To align your cybersecurity strategy with ISO assurance requirements, contact support@demo.pacificcert.com.
It is part of a framework for product evaluation and provides the foundational model. Certification applies to the product, not the organization.
A Protection Profile is a reusable template for a category of products. A Security Target is specific to the product being evaluated.
Evaluation Assurance Levels (EAL1–EAL7) define the depth and rigor of the evaluation process. Higher EALs require more evidence and testing.
ISO/IEC 27001 can include ISO/IEC 15408-aligned processes for secure system development and procurement within its risk and control framework.
We certify management systems that support ISO/IEC 15408 alignment but do not certify IT products directly. Evaluation labs handle product-level CC certification.
Contact Pacific Certifications to begin your certification journey today!
Suggested Certifications –
Read more: Pacific Blogs

Get a rough Estimate for your Required Certification by entering your basic details.
This will close in 0 seconds
Get in touch!
This will close in 0 seconds