Network Security

What Is Common Criteria, and Why Does It Matter for Firewall Security in 2026?

by Georgy Thadathil

Understanding ISO/IEC 15408, NIAP Validation, and What a Certificate Really Proves for IT Buyers

When a vendor states that a security product is "secure," a reasonable question follows: Who verified that claim? Government agencies, regulated enterprises, and procurement teams cannot rely on marketing language alone. For them, the answer often comes down to a single internationally recognized standard: Common Criteria.

What Common Criteria Is

Common Criteria (CC) is an international standard, formally published as ISO/IEC 15408, used to independently evaluate the security of information technology products. Rather than a vendor testing its own product and publishing the results, Common Criteria requires evaluation by an accredited, third-party laboratory against a defined set of security requirements. When the evaluation succeeds, a national certification body issues a certificate confirming that the product performs its claimed security functions and withstands the specified level of scrutiny.

The value proposition is trust through independence. A Common Criteria certificate tells a buyer that a neutral expert, not the manufacturer, verified the product's security behavior. This is why the standard is widely required across government, defense, and enterprise environments worldwide.

How the Standard Is Structured

Two concepts sit at the heart of Common Criteria: the Protection Profile and the Evaluation Assurance Level.

A Protection Profile (PP) defines the security requirements for a product category, such as network devices, firewalls, or VPN gateways. It specifies what the product must do to counter the threats typical of that category. In North America, the National Information Assurance Partnership (NIAP) drives evaluation through these Protection Profiles, including the collaborative Protection Profile for Network Devices (NDcPP) and add-on modules for firewalls, VPN gateways, and intrusion prevention systems.

Evaluation Assurance Levels (EAL) run from EAL1, the most basic, to EAL7, the most rigorous. They describe how deeply a product was examined, not how many features it has. Since 2014, the Common Criteria community has shifted its emphasis away from broad EAL ratings and toward more precise, threat-driven Protection Profiles. That is why North American certifications center on PP conformance rather than a headline EAL number.

Global Recognition

Common Criteria is backed by the Common Criteria Recognition Arrangement (CCRA), under which a certificate issued in one member nation is recognized across the others. Membership has evolved over time as authorizing and consuming nations join or change status, and the current roster is published on the Common Criteria Portal. In practice, this mutual recognition allows a vendor to evaluate a product once and have the result accepted internationally, saving time for global organizations and making Common Criteria the default benchmark for government procurement.

The current version of the standard is CC:2022, aligned with ISO/IEC 15408:2022; new certification applications have been required to use CC:2022 since 1 July 2024. The community also keeps its Protection Profiles current. The Network Device Protection Profile, for example, advanced to NDcPP v4.0, approved in December 2025, with new evaluations required to move to v4.0 as the transition from the prior version (NDcPP v3.0e) completes during 2026.

Scope Matters: Product, Not Just the Cryptographic Module

A crucial distinction for buyers is scope. Common Criteria evaluates the whole product as a defined "Target of Evaluation," assessing how the product's security functions behave together against a Protection Profile. This differs from FIPS 140-3, which validates only the cryptographic module inside a product. The two are complementary, and mature security programs frequently require both.

Common_Criteria_vs_FIPS_Comparison.png

 

 

Figure 1: Common Criteria vs. FIPS 140-3 at a Glance

What This Means for SonicWall Customers

SonicWall's next-generation firewalls are Common Criteria certified. The certification spans the TZ, NSa, NSsp, and NSv appliance families running SonicOS/X 7.0.1, with NIAP validation dated 8 January 2025. The evaluation covered the Collaborative Protection Profile for Network Devices (NDcPP v2.2e), the PP-Module for Stateful Traffic Filter Firewalls (MOD_FW v1.4e), the PP-Module for VPN Gateways (v1.3), and the PP-Module for Intrusion Prevention Systems (v1.0). In practical terms, the firewall's core security functions, not just its cryptography, were independently assessed. The same platform is also listed on the NSA's Commercial Solutions for Classified (CSfC) Components List, which requires Common Criteria evaluation as a prerequisite.

Certificates carry issue and review dates, and their scope is specific to named products and firmware versions. Before relying on a certificate for a procurement decision, always confirm the exact model, version, and certificate on the NIAP Product Compliant List. Do not assume an entire product line is covered.

Practical Actions for IT Buyers and Procurement Teams

Organizations evaluating security products for regulated or government-adjacent environments should:

  • Confirm the specific product model and firmware version named on the certificate, not just the product family.
  • Check the certificate's issue and review dates on the NIAP Product Compliant List or Common Criteria Portal.
  • Identify which Protection Profile and modules were evaluated (for example, Network Device, Firewall, VPN Gateway, or IPS).
  • Determine whether FIPS 140-3 validation is also required alongside Common Criteria for the deployment.
  • Track Protection Profile transitions, such as the move to NDcPP v4.0, that may affect future procurement cycles.

The Bottom Line

Common Criteria answers the "who verified this?" question with independent, internationally recognized validation. For IT managers, security administrators, and procurement teams, a current certificate is practical evidence that a product's security has been tested by a qualified third party against a rigorous, threat-based standard. That evidence reduces risk, supports compliance requirements, and simplifies purchasing decisions across borders.

SonicWall_Independently_Verified_Security_Callout.png

 

Frequently Asked Questions

QuestionAnswer
What is Common Criteria, and why does it matter? Common Criteria (ISO/IEC 15408) is an international standard for independently evaluating IT security products. It matters because it replaces vendor self-assurance with third-party validation, which is required or preferred across government, defense, and many regulated industries.
How does Common Criteria differ from FIPS 140-3?Common Criteria evaluates the whole product, its security functions working together against a Protection Profile. FIPS 140-3 validates only the cryptographic module inside a product. The two standards are complementary, and mature security programs often require both.
What is a Protection Profile in Common Criteria?A Protection Profile (PP) defines the security requirements for a category of product, such as network devices, firewalls, or VPN gateways. In North America, NIAP drives evaluation through Protection Profiles such as the collaborative Protection Profile for Network Devices (NDcPP).
What do Evaluation Assurance Levels (EAL) mean?EALs range from EAL1 (most basic) to EAL7 (most rigorous) and describe how deeply a product was examined. Since 2014, the industry has shifted emphasis toward Protection Profile conformance rather than a headline EAL rating.
Is SonicWall Common Criteria certified, and what does that cover?Yes. SonicWall's TZ, NSa, NSsp, and NSv firewalls running SonicOS/X 7.0.1 hold Common Criteria certification, with NIAP validation dated 8 January 2025, covering the Network Device, Firewall, VPN Gateway, and Intrusion Prevention Protection Profile modules.

 

References 

SourcePublisherURL
SonicWall Common Criteria page (Government Federal Certifications)SonicWall Officialsonicwall.com/solutions/certifications/common-criteria
NIAP SonicWall Firewall product record (ST_VID11473)NIAPniap-ccevs.org/products/11473
Sonicwall SonicOS/X v7.0.1 Security Target (TZ, NSa, NSsp, NSv)Common Criteria Portalcommoncriteriaportal.org (epfiles/st_vid11473-st.pdf)
Common Criteria Portal, Certified Products ListCommon Criteria Portalcommoncriteriaportal.org/products
NDcPP v4.0 Endorsement Statement and transition timelineCommon Criteria Portal / Lightship Securitycommoncriteriaportal.org; lightshipsec.com
CCRA membership roster (authorizing and consuming nations)Common Criteria Portalcommoncriteriaportal.org/ccra

 

Share This Article

An Article By

Georgy Thadathil

Product Manager
Georgy Thadathil is Product Manager for SonicWall security products. He has 13 years' combined experience in product management, engineering and customer service. He specializes in helping customers find the best cybersecurity solutions to protect their infrastructure by understanding their unique challenges and use cases.

Related Articles

  • FIPS 140-3 Validation: The Difference Between Proven and Assumed
    Read More
  • The Why and What of FIPS 140-3 Validation in Modern Cybersecurity
    Read More