
When a vendor states that a security product is "secure," a reasonable question follows: Who verified that claim? Government agencies, regulated enterprises, and procurement teams cannot rely on marketing language alone. For them, the answer often comes down to a single internationally recognized standard: Common Criteria.
Common Criteria (CC) is an international standard, formally published as ISO/IEC 15408, used to independently evaluate the security of information technology products. Rather than a vendor testing its own product and publishing the results, Common Criteria requires evaluation by an accredited, third-party laboratory against a defined set of security requirements. When the evaluation succeeds, a national certification body issues a certificate confirming that the product performs its claimed security functions and withstands the specified level of scrutiny.
The value proposition is trust through independence. A Common Criteria certificate tells a buyer that a neutral expert, not the manufacturer, verified the product's security behavior. This is why the standard is widely required across government, defense, and enterprise environments worldwide.
Two concepts sit at the heart of Common Criteria: the Protection Profile and the Evaluation Assurance Level.
A Protection Profile (PP) defines the security requirements for a product category, such as network devices, firewalls, or VPN gateways. It specifies what the product must do to counter the threats typical of that category. In North America, the National Information Assurance Partnership (NIAP) drives evaluation through these Protection Profiles, including the collaborative Protection Profile for Network Devices (NDcPP) and add-on modules for firewalls, VPN gateways, and intrusion prevention systems.
Evaluation Assurance Levels (EAL) run from EAL1, the most basic, to EAL7, the most rigorous. They describe how deeply a product was examined, not how many features it has. Since 2014, the Common Criteria community has shifted its emphasis away from broad EAL ratings and toward more precise, threat-driven Protection Profiles. That is why North American certifications center on PP conformance rather than a headline EAL number.
Common Criteria is backed by the Common Criteria Recognition Arrangement (CCRA), under which a certificate issued in one member nation is recognized across the others. Membership has evolved over time as authorizing and consuming nations join or change status, and the current roster is published on the Common Criteria Portal. In practice, this mutual recognition allows a vendor to evaluate a product once and have the result accepted internationally, saving time for global organizations and making Common Criteria the default benchmark for government procurement.
The current version of the standard is CC:2022, aligned with ISO/IEC 15408:2022; new certification applications have been required to use CC:2022 since 1 July 2024. The community also keeps its Protection Profiles current. The Network Device Protection Profile, for example, advanced to NDcPP v4.0, approved in December 2025, with new evaluations required to move to v4.0 as the transition from the prior version (NDcPP v3.0e) completes during 2026.
A crucial distinction for buyers is scope. Common Criteria evaluates the whole product as a defined "Target of Evaluation," assessing how the product's security functions behave together against a Protection Profile. This differs from FIPS 140-3, which validates only the cryptographic module inside a product. The two are complementary, and mature security programs frequently require both.

Figure 1: Common Criteria vs. FIPS 140-3 at a Glance
SonicWall's next-generation firewalls are Common Criteria certified. The certification spans the TZ, NSa, NSsp, and NSv appliance families running SonicOS/X 7.0.1, with NIAP validation dated 8 January 2025. The evaluation covered the Collaborative Protection Profile for Network Devices (NDcPP v2.2e), the PP-Module for Stateful Traffic Filter Firewalls (MOD_FW v1.4e), the PP-Module for VPN Gateways (v1.3), and the PP-Module for Intrusion Prevention Systems (v1.0). In practical terms, the firewall's core security functions, not just its cryptography, were independently assessed. The same platform is also listed on the NSA's Commercial Solutions for Classified (CSfC) Components List, which requires Common Criteria evaluation as a prerequisite.
Certificates carry issue and review dates, and their scope is specific to named products and firmware versions. Before relying on a certificate for a procurement decision, always confirm the exact model, version, and certificate on the NIAP Product Compliant List. Do not assume an entire product line is covered.
Organizations evaluating security products for regulated or government-adjacent environments should:
Common Criteria answers the "who verified this?" question with independent, internationally recognized validation. For IT managers, security administrators, and procurement teams, a current certificate is practical evidence that a product's security has been tested by a qualified third party against a rigorous, threat-based standard. That evidence reduces risk, supports compliance requirements, and simplifies purchasing decisions across borders.
| Question | Answer |
| What is Common Criteria, and why does it matter? | Common Criteria (ISO/IEC 15408) is an international standard for independently evaluating IT security products. It matters because it replaces vendor self-assurance with third-party validation, which is required or preferred across government, defense, and many regulated industries. |
| How does Common Criteria differ from FIPS 140-3? | Common Criteria evaluates the whole product, its security functions working together against a Protection Profile. FIPS 140-3 validates only the cryptographic module inside a product. The two standards are complementary, and mature security programs often require both. |
| What is a Protection Profile in Common Criteria? | A Protection Profile (PP) defines the security requirements for a category of product, such as network devices, firewalls, or VPN gateways. In North America, NIAP drives evaluation through Protection Profiles such as the collaborative Protection Profile for Network Devices (NDcPP). |
| What do Evaluation Assurance Levels (EAL) mean? | EALs range from EAL1 (most basic) to EAL7 (most rigorous) and describe how deeply a product was examined. Since 2014, the industry has shifted emphasis toward Protection Profile conformance rather than a headline EAL rating. |
| Is SonicWall Common Criteria certified, and what does that cover? | Yes. SonicWall's TZ, NSa, NSsp, and NSv firewalls running SonicOS/X 7.0.1 hold Common Criteria certification, with NIAP validation dated 8 January 2025, covering the Network Device, Firewall, VPN Gateway, and Intrusion Prevention Protection Profile modules. |
| Source | Publisher | URL |
| SonicWall Common Criteria page (Government Federal Certifications) | SonicWall Official | sonicwall.com/solutions/certifications/common-criteria |
| NIAP SonicWall Firewall product record (ST_VID11473) | NIAP | niap-ccevs.org/products/11473 |
| Sonicwall SonicOS/X v7.0.1 Security Target (TZ, NSa, NSsp, NSv) | Common Criteria Portal | commoncriteriaportal.org (epfiles/st_vid11473-st.pdf) |
| Common Criteria Portal, Certified Products List | Common Criteria Portal | commoncriteriaportal.org/products |
| NDcPP v4.0 Endorsement Statement and transition timeline | Common Criteria Portal / Lightship Security | commoncriteriaportal.org; lightshipsec.com |
| CCRA membership roster (authorizing and consuming nations) | Common Criteria Portal | commoncriteriaportal.org/ccra |
Share This Article

An Article By
An Article By
Georgy Thadathil
Georgy Thadathil