HOME >> IT Security >> JISEC Home >> Scheme Documentation

Scheme Documentation (Basics)

Last Updated 2017-05-23

Scheme documentation is regularly revised by JISEC.
Note that the latest versions of the forms should be used (CCM-02-A, CCM-03-A).
It is important to understand the contents of the latest Scheme documentation for your application procedures.

IT Security Evaluation and Certification Scheme Documentation

The following documents explain the Scheme Document, Organization and Operational Manual, Requirements for the applicant, Guidance on application procedures and Operating procedures in this Scheme.
In the case that the product area is "hardware (smart cards, etc.)," refer to the "Hardware" page on the Web.


icon For all relevant parties under this Scheme

Document
/ Overview
CCS-01
IT Security Evaluation and Certification Scheme Document pdf (363KB)
Updated 2015-06-01

This Scheme Document prescribes "IT Security Evaluation and Certification Scheme" and basic matters related to this Scheme that need to be complied with by suppliers and users of IT products and systems as well as personnel engaged in the operation of this Scheme.
Contents
  • Purpose of the Scheme
  • Definition of Terms
  • Structure of the Scheme
  • Overview of Evaluation and Certification
  • Overview of Evaluation and ST Confirmation
  • Rights and Obligations of Applicants
  • Suspension or Revocation of Certification and ST Confirmation
  • Miscellaneous Provisions

icon For applicants, Evaluation Facility

Document
/ Overview
CCM-02
Updated 2015-10-01

The purpose of the Requirements is to prescribe the matters that applicants must comply with when making a certification application and maintain its certification.
CCM-02-A
Updated 2016-10-13

Forms and sample forms for CCM-02-A can be obtained from "Forms to be downloaded (for Certification Application)."

This Guidance explains the necessary procedures that applicants conduct to acquire and maintain certification under IT Security Evaluation and Certification Scheme.
Contents
  • Certification Application Preparations
  • Procedures for a Certification Application and Corrections during Application
  • Overview of Evaluation and Certification
  • Assurance Continuity
  • Suspensions and Revocations of Certification
  • Miscellaneous Procedures after Acquiring Certification
  • Succession of Certification
  • Handling Complaints about a Certified Product
  • Use for the "Certification Mark"

icon For Evaluation Facility

Document
/ Overview
CCM-03
Updated 2015-10-01

The Requirements for Evaluation Facility prescribe the necessary matters for Evaluation Facilities to obtain approval from the Certification Body as well as the necessary matters for Evaluation Facilities that have obtained approval to maintain the approval under IT Security Evaluation and Certification Scheme.
CCM-03-A
Updated 2016-04-01

Forms and sample forms for CCM-03-A can be obtained from "Forms to be downloaded (for Evaluation Facility)."

This Guidance explains the procedures that Evaluation Facilities shall take to apply for obtaining approval and to maintain the approval under IT Security Evaluation and Certification Scheme.
Contents
  • Approval of Evaluation Facility
  • Approval of Evaluator Qualification

icon For Certification Body

Document
/ Overview
CCM-01
Updated 2015-06-01

This Operational Manual prescribes policies and procedures for operating organization and certification services as the Certification Body under the IT Security Evaluation and Certification Scheme in accordance with ISO/IEC 17065 "Conformity assessment-Requirements for bodies certifying products, processes and services (JIS Q 17065)."
Contents
  • Matters that Need to be Complied with by Personnel Engaged in the Operation of Certification Services
  • Advisory boards for the operation of certification services (Management Committee, Technical Committee, Certification Committee, and Hardware Certification Committee)
  • Certification Services
  • ST Confirmation Services
  • Internal Audit
Document
/ Overview
CCM-01-A
Updated 2017-05-23

This Operating Procedure prescribes the necessary operating procedure for services of certification and ST confirmation as the Certification Body under the Japan IT Security Evaluation and Certification Scheme.
Contents
  • Handling services for Reception and Acceptance of Certification Application / Certification / Assurance Continuity / Changing Records
  • Suspension or Revocation of Certification and ST Confirmation
  • Preparation and Publication of Standards and Guidance, etc.
  • Internal Audit / Document Management
Document
/ Overview
CCM-01-B
Updated 2015-06-01

This Operating Procedure prescribes the necessary operating procedure to approve Evaluation Facilities and Evaluator Qualification as the Certification Body under the IT Security Evaluation and Certification Scheme.
Contents
  • Operating Procedure for Reception and Acceptance of Application
  • Operating Procedure for Approval of Evaluator Qualification and Changes
  • Operating Procedure for Approval of IT Security Evaluation Facility and Changes
Document
/ Overview
CCM-01-C
Updated 2016-04-01

This Operating Procedure prescribes the personnel and committees that are required for the operation of the IT Security Evaluation and Certification Scheme as the Certification Body.
Contents
  • Appointment of a Technical Manager, etc.
  • Qualification Standards, Procedure for Registration, Management, Education and Training Programs of Certifiers, and Committees

icon Procedures for Certification Application and Relevant Documents

The following procedures explain the items needed for the certification application. The applicants are required to understand and follow the notes and instructions below when submitting application forms.

Contact

For further inquiries on the Scheme Documentation, please contact to the following:

JISEC Administrative staff, IT Security Center,
Information-technology Promotion Agency, Japan
TEL: +81-3-5978-7538 FAX: +81-3-5978-7548
E-mail: 

The Previous Scheme Documentation

The previous version of the Scheme Documentation published before October 2016 is as follows.

The Previous Scheme Documentation