Enhancing information security
Last Updated:Dec 2, 2024
Scheme documentation is regularly revised by JISEC.
Note that the latest versions of the forms should be used (CCM-02-A, CCM-03-A).
It is important to understand the contents of the latest Scheme documentation for your application procedures.
In order to improve the operation of this Scheme, the related procedures and guidance have been partially revised with the aim of complying with the CCRA documents as follows. This revision came into effect on December 15, 2023.
1. Scheme documents and guidance, etc., for revision
・IT Security Evaluation and Certification Scheme Document (CCS-01)
・Organization and Operational Manual for IT Security Certification Body (CCM-01)
・Requirements for IT Security Certification (CCM-02)
・Operating Procedure for IT Security Certification Services (CCM-01-A)
・Guidance on IT Security Certification (CCM-02-A)
2. Changes to applications for Certificate Validity
On September 30, 2021、the CCRA document “Certificate Validity: Operating Procedures v1.0” has been issued, which prescribes the requirements in related to the Certificate Validity. Based on this CCRA document, the validity period will be written down on the Certificate (certification date plus 5 years).
As a transitional measure, when the product area is “Hardware (smart cards, etc.)” and the certified TOE had been certified prior to September 30, 2021, on which this CCRA document was issued, then September 30, 2026 (i.e., 5 years after the certification date) shall be set as the certificate validity date.
3. Changes to extending the Certificate Validity
The CCRA document “Assurance Continuity: CCRA Requirements v3.0” has been issued, which prescribes the Assurance Continuity paradigm. Based on this CCRA document, Assurance Continuity is defined as “a paradigm that defines Maintenance and Re-assessment and recognizes the previous evaluation in order to reuse the applicable previous evaluation results in the case a certified TOE or its environments are changed.” The term “Assurance Continuity” under the current Scheme had been changed to “Maintenance.” At the same time, the deadline of a maintenance application had been changed from “two years after the certification date” to “three months prior to the certification validity date.”
In addition, based on this CCRA document, the “Re-assessment” procedure had been introduced. Re-assessment means to confirm that the certified TOE has not been changed, but changes in the attacks landscape need to be assessed to check if the TOE still reaches the same level of resistance as initially certified. The certificate validity can be extended by using the Re-assessment procedure.
4. Changes to the Application documents <Forms (CCM-02-A)>
In accordance with the partial revision of the Scheme Documentation, the following application documents have been changed, and the Application for Re-assessment form has been added.
・Application for Maintenance:(CCM-02-A) Form 2
・Request for Withdrawal of Application:(CCM-02-A) Form 7
・Request for Reissuing Certificate, etc.:(CCM-02-A) Form 9
・Request for Publication of English Version of Certification Report and ST:(CCM-02-A) Form 18
・Request for Preliminary Review of Maintenance:(CCM-02-A) Form 20
・Application for Re-assessment:(CCM-02-A) Form 23
In order to improve the operation of this Scheme, the related procedures and guidance have been partially revised with the aim of promoting the digitization of procedures as follows. This revision came into effect on November 1, 2023.
1. Procedures and guidance for revision
・Operating Procedure for IT Security Certification Services (CCM-01-A)
・Guidance on IT Security Certification (CCM-02-A)
・Guidance on Approval of IT Security Evaluation Facility (CCM-03-A)
2. Changes to application procedures
Regarding the submission of application documents, the applicant and Evaluation Facility may submit the documents in electronic form (Note 1), and paper documents are not required (Note 2).
Note 1: A digital signature using a digital certificate under the organization’s name issued by a public Certification Authority is required.
Note 2: “The documentation indicating the corporate entity” shall still be submitted in original.
3. Changes to issuing a Certificate, etc.
A Certificate, etc., will be issued as electronic data with a digital signature. Issuing a Certificate, etc., in writing as before is available upon request.
4. Changes to concluding a contract
The contract method of a Non-Disclosure Agreement to be concluded with the applicant has became an electronic contract introduced by IPA. If it is difficult for the applicant to conclude an electronic contract, it is still possible to conclude a contract in writing.
The following documents explain the Scheme Document, Organization and Operational Manual, Requirements for the applicant, Guidance on application procedures and Operating procedures in this Scheme.
The following procedures explain the items needed for the certification application. The applicants are required to understand and follow the notes and instructions below when submitting application forms.
For further inquiries on the Scheme Documentation, please contact to the following:
JISEC Administrative staff, IT Security Center,
Information-technology Promotion Agency, Japan
Dec 2, 2024
CCM-01-A: The effective versions of the external documents has been listed.
Jun 24, 2024
"Guideline for Certification Application with HCD-PP Conformance" has been updated.
May 30, 2024
Apr 30, 2024