Skip to searchSkip to main content
  • Event

    International Common Criteria Conference 2026

Start Date

28 September, 2026

End Date

1 October, 2026

Location

Rome, Italy

Get your ticket

Date

28 September - 1 October, 2026

Location

Rome, Italy

Get your ticket

Meet Brightsight at the International Common Criteria Conference 2026

We are pleased to be a silver sponsor of the 25th edition of the International Common Criteria Conference (ICCC), 
the leading global forum for professionals involved in cybersecurity certification and assurance. With a strong focus on Common Criteria (CC), the conference brings together certification bodies, evaluation laboratories, industry representatives, regulators, and technology providers to discuss the evolving cybersecurity certification landscape, including developments in EUCC and other emerging frameworks.

Explore Brightsight's Conference Sessions

28 September, Monday

 11:30 | W01A
Gavin Duan

Fabrice Heiser

COO Asia, Brightsight

About the session

Explore the points where real projects go off the rails: bad TOE scope, unrealistic timelines, poor ownership of evidence, misunderstandings with labs, and failure to account for country-specific or scheme-specific constraints.
14:00 | W02B
Gavin Duan

Augusto Velasco

Fellow CC Evaluator, Brightsight

About the session

Discover what can change without breaking the certification strategy; when to use assurance continuity, when delta evaluation makes sense; and how to plan patch handling without creating a compliance freeze.

29 September, Tuesday

11:45 | P11C
Gavin Duan

Rob Kemper

Director of the Certification Body, Brightsight

About the session

Explore lessons learned from the transition to EUCC, how certification bodies, ITSEFs and vendors are building predictability in a changing environment, and where further alignment may be needed to support a consistent and workable scheme.
14:15 | B12B
Gavin Duan

Bill Yang

Fellow Security Evaluator, Brightsight

About the session

How can CRA risk assessment requirements be aligned with EUCC certification? This session explores a practical approach to linking product risk management with ASE_SPD, helping bridge CRA obligations and EUCC requirements.
14:45 | B12C
Gavin Duan

Enea Zhulati

Fellow CC Evaluator, Brightsight

About the session

This presentation shares lessons learned from a CRA-EUCC pilot project, identifying gaps for Important Class I and II products and proposing an approach to bridge EUCC certification and CRA requirements.

Interested in our cybersecurity evaluation services for the Cyber Resilience Act (CRA)? 

Complete the form below and one of our experts will ​contact you to ​discuss your needs.