Common Criteria EAL4+ Certification for a Trusted Platform Module

Author
Regulations

Common Criteria

Protection Profile TPM

A TPM manufacturer produces Trusted Platform Modules — developing both the hardware and the integrated software for secure computing environments. A TPM is a critical security component: it handles secure key storage, platform integrity, cryptographic operations, and trust anchoring for the device. To meet a key Microsoft requirement and get ahead of tightening European cybersecurity expectations, the company built a new, higher-assurance TPM and set out to certify it to Common Criteria EAL4+ in France. This was a strategic certification, not a product test — it meant aligning the product, the development process, the manufacturing chain, the documentation, the evaluation lab, and the certification authority.
Client / Project Need

Objectives & drivers

The company needed a high-assurance certification that would do several jobs at once: satisfy Microsoft’s TPM security requirement, demonstrate strong product assurance, build trust with demanding customers and partners, get ahead of European cybersecurity regulation, and position the TPM competitively in security-sensitive markets — all within a market-relevant timeline. The added constraint: the team had no prior experience with Common Criteria or high-assurance certification. Internet of Trust had to supply both the technical certification expertise and the operational guidance to run the full lifecycle.
Challenge

Key hurdles

Bringing a combined hardware/software security component to Common Criteria EAL4+ takes far more than documentation. It reaches into product architecture, vulnerability analysis, development methodology, configuration management, testing, manufacturing controls, lifecycle security, and audit preparation — several of which had to move in parallel. Because the product combined hardware and software, any design weakness could force remediation by the client’s R&D teams, with knock-on effects on schedule and scope. EAL4+ also demands deep evidence: the evaluator must be able to trace how the product is specified, designed, developed, tested, manufactured, delivered, and maintained. The manufacturer, Internet of Trust, the evaluation laboratory, and the certification body also had to coordinate their work. With client teams new to Common Criteria, every function from R&D to supply chain had to understand how its work fed the final result. This was a cross-functional project, not a purely technical one.
Approach

What we did

01

Baseline and gap analysis. Assessed the product against EAL4+ expectations to identify the main workstreams, documentation needs, likely weaknesses, and certification risks.

02

Structured action plan. Defined the route to the target assurance level, covering the product, the Security Target, documentation, evaluation interactions, internal training, audits, and remediation cycles.

03

Security Target. Prepared the ~100-page Security Target defining the product scope, security problem, objectives, functional requirements, and assurance requirements — the reference point shared by client, lab, and certification authority.

04

Cross-functional training. Trained 10 staff members across R&D, product development, product management, manufacturing, and supply chain, so every team understood the EAL4+ process, the evidence required, and its own responsibilities — because high-assurance certification can’t be carried by a certification manager alone.

05

Evaluation documentation package. Wrote the full kit: 25 documents, each typically 20–50 pages, covering development process, architecture, security functions, test plans, lifecycle, configuration management, manufacturing, delivery, and vulnerability handling — the basis for evaluation and certification reviews.

06

Stakeholder coordination. Managed structured exchanges with the certification body and evaluation laboratory, keeping questions, evidence requests, and evaluation issues moving.

07

Site audit preparation. Prepared the client’s R&D and manufacturing sites for security audits, aligning processes and operational practice with Common Criteria expectations.

08

Remediation support. When hardware and software vulnerabilities surfaced during evaluation, structured the certification impact analysis, evaluation follow-up, and evidence updates. The full process ran roughly two years, from preparation to certificate.

Key outcomes

Impact delivered

Lessons learned

What we took away

High-assurance certification depends on clear ownership across the company. Training helps each team understand its evidence responsibilities, while early discussions with the laboratory and certification body clarify expectations. For products combining hardware and software, planning for remediation from the outset helps teams manage changes without losing control of scope and schedule.

Related materials

Keep exploring

ODSI: A Building-Block Approach to Secure Isolation

Read case study →

2IdO: Securing the Industrial Internet of Things

Read case study →

SECREDAS

SECREDAS: Building Trustworthy Automated Systems Across Critical Industries

Read case study →

Contact us

Request this document

We’ll send you access by email.