Why NATO requires cybersecurity assurance and certification
Common Criteria (ISO/IEC 15408)
Information Assurance requirements defined by NCIA
National certification schemes within NATO member states
Common Criteria as the foundation for NATO Information Assurance
Common Criteria is the recognised evaluation framework that serves as the foundation for NATO Information Assurance requirements.
The NATO Information Assurance Product Catalogue (NIAPC)
Accessing NATO environments is complex. Certification is mandatory.
Secure
Meeting rigorous Information Assurance requirements, including Common Criteria
Independently evaluated
Trusted
By national authorities within NATO member nations
I
Without the right expertise, navigating Common Criteria–based evaluation and NATO requirements can be slow, costly, and high‑risk.
We guide you from concept to NATO-aligned security evaluation
Accredited Common Criteria ITSEF
Internationally recognised evaluation facility for IT security products
Beyond testing — independent evaluation
Through recognised international evaluation frameworks, including Common Criteria
Is this relevant to your product?
Cryptographic products
● Secure communication modules
● Cryptographic libraries
Requirements:
● Compliance with NATO cryptographic policies
● High assurance levels (EAL4+ and above)
Non-cryptographic cybersecurity products
Products that support cybersecurity functions without directly implementing cryptography are also subject to independent evaluation.
● Monitoring systems
● Secure routers
Requirements:
Secure Hardware & Components
● Microcontrollers
● Hardware root-of-trust
Requirements:
I
How the evaluation process works
01
Define your security scope
02
Prepare certification documentation
03
Run independent evaluation
04
Obtain certification decision from the relevant authority
05
Support consideration for NATO procurement
We guide you at every step.
How the evaluation process works
01
Define your security scope
02
Prepare certification documentation
03
Run independent evaluation
04
Obtain certification decision from the relevant authority
05
Support consideration for NATO procurement
We guide you at every step.
Why companies choose Brightsight
Proven experience in defense and space
Experts cleared for SECRET-level projects
Accredited secure laboratories
Deep expertise in cryptography, hardware and secure systems
I
Accredited secure facilities
What we do
PHASE 1
De-risk early
PHASE 2
Deep technical testing
PHASE 3


