Home
Corporate
About TUGAY Certificates Partners Careers
Services
Penetration Testing Source Code Analysis Training References Contact Startup Application
Get a Quote

What Are Common Criteria and EAL Levels?

Common Criteria (CC) is an international standard (ISO/IEC 15408) for evaluating IT security products and systems. The Evaluation Assurance Level (EAL) expresses the degree to which a product's security functions have been verified, and is defined across seven levels from 1 to 7.

At TUGAY, we provide evaluation services at every level from EAL1 through EAL7. We deliver specialized CC evaluation support for organizations operating in sectors that demand high assurance, such as public institutions, the defense industry, and financial services.

Request an EAL Evaluation
7
EAL Levels
ISO
15408 Standard
CC
Common Criteria
100%
Technical Expertise

Assurance Levels from EAL1 to EAL7

Each level contains more comprehensive assurance requirements than the one before it.

EAL 1

Functionally Tested

The most basic assurance level. It verifies that the product's security functions operate in accordance with its design. Suitable for low-risk products requiring independent security analysis.

EAL 2

Structurally Tested

Security testing is conducted using design information. Can be applied without access to the developer's development process; widely used for legacy systems.

EAL 3

Methodically Tested and Checked

Confirms systematic application of security engineering practices. The development environment and lifecycle controls are audited.

EAL 4

Methodically Designed, Tested, and Reviewed

The most common level for commercial products. Includes comprehensive design description, independent testing, and vulnerability analysis.

EAL 5

Semiformally Designed and Tested

Requires semiformal design and policy modeling. An advanced assurance level for environments with serious security threats.

EAL 6

Semiformally Verified Design and Tested

Structured development environment, comprehensive penetration testing, and semiformal implementation verification. For products protecting high-value assets.

EAL 7

Formally Verified Design and Tested

The highest assurance level. Requires formal mathematical proof methods to verify both design and implementation. Applied for defense and critical infrastructure systems.

Why Does EAL Evaluation Matter?

Security certification delivers institutional trust and competitive advantage.

Public Procurement Advantage

For products and systems targeting public institutions and the defense sector, CC certification is frequently a mandatory or preferred criterion.

International Recognition

Products evaluated under the Common Criteria Recognition Arrangement (CCRA) are mutually recognized across 31 signatory countries.

Security Assurance

Independent evaluation verifies your product's security claims in a neutral framework, providing genuine security assurance to your customers.

Startup Program

Secure your product
before it hits the market.

Security isn't just for large enterprises. Every startup needs a solid foundation from day one. Let us find the vulnerabilities before attackers do. For free.

Apply for Startup Program

Application is free. No commitment required.

Assessment scope

  • Initial security assessment by an expert
  • Critical vulnerability and weakness identification
  • Prioritized findings summary report
  • GDPR preliminary compliance assessment
  • Expert feedback within 48 hours
Completely free & non-binding
Free Assessment Request Pentest Startup Application