WG 03 - CLC/TC 47X/WG 03
The activities will be focused on the harmonization with the Cyber Resilience Act (CRA) of the Common Criteria Protection Profiles(PPs) addressing the smart card/secure element platforms, i.e. the high end tamper resistant hardware of a smart card/secure element and the generic software like cryptographic libraries and optional Operating Systems running on it. These PPs are the defacto worldwide reference standards in the area of smart card security. Prominent examples are the Eurosmart Secure IC PP 0084, the Oracle Java Card PP 0099 and PP 0101 TCG TPM PP to cite some. As a first step WG3 will identify all such relevant PPs in the context of the CRA. An essential part of the work will be the identification and filling in the gaps between the essential cybersecurity CRA requirements (CRA, Annex I of the CRA draft proposal text). Reporting obligations of manufacturers in case of security incidents (CRA, Article 11 of the CRA draft proposal text) should be also covered as part of the work.
CLC/TC 47X/WG 03
The activities will be focused on the harmonization with the Cyber Resilience Act (CRA) of the Common Criteria Protection Profiles(PPs) addressing the smart card/secure element platforms, i.e. the high end tamper resistant hardware of a smart card/secure element and the generic software like cryptographic libraries and optional Operating Systems running on it. These PPs are the defacto worldwide reference standards in the area of smart card security. Prominent examples are the Eurosmart Secure IC PP 0084, the Oracle Java Card PP 0099 and PP 0101 TCG TPM PP to cite some. As a first step WG3 will identify all such relevant PPs in the context of the CRA. An essential part of the work will be the identification and filling in the gaps between the essential cybersecurity CRA requirements (CRA, Annex I of the CRA draft proposal text). Reporting obligations of manufacturers in case of security incidents (CRA, Article 11 of the CRA draft proposal text) should be also covered as part of the work.
General Information
Frequently Asked Questions
WG 03 is a Technical Committee within CLC. It is named "CLC/TC 47X/WG 03" and is responsible for: The activities will be focused on the harmonization with the Cyber Resilience Act (CRA) of the Common Criteria Protection Profiles(PPs) addressing the smart card/secure element platforms, i.e. the high end tamper resistant hardware of a smart card/secure element and the generic software like cryptographic libraries and optional Operating Systems running on it. These PPs are the defacto worldwide reference standards in the area of smart card security. Prominent examples are the Eurosmart Secure IC PP 0084, the Oracle Java Card PP 0099 and PP 0101 TCG TPM PP to cite some. As a first step WG3 will identify all such relevant PPs in the context of the CRA. An essential part of the work will be the identification and filling in the gaps between the essential cybersecurity CRA requirements (CRA, Annex I of the CRA draft proposal text). Reporting obligations of manufacturers in case of security incidents (CRA, Article 11 of the CRA draft proposal text) should be also covered as part of the work. This committee has published 1 standards.
WG 03 develops CLC standards in the area of Information technology. The scope of work includes: The activities will be focused on the harmonization with the Cyber Resilience Act (CRA) of the Common Criteria Protection Profiles(PPs) addressing the smart card/secure element platforms, i.e. the high end tamper resistant hardware of a smart card/secure element and the generic software like cryptographic libraries and optional Operating Systems running on it. These PPs are the defacto worldwide reference standards in the area of smart card security. Prominent examples are the Eurosmart Secure IC PP 0084, the Oracle Java Card PP 0099 and PP 0101 TCG TPM PP to cite some. As a first step WG3 will identify all such relevant PPs in the context of the CRA. An essential part of the work will be the identification and filling in the gaps between the essential cybersecurity CRA requirements (CRA, Annex I of the CRA draft proposal text). Reporting obligations of manufacturers in case of security incidents (CRA, Article 11 of the CRA draft proposal text) should be also covered as part of the work. Currently, there are 1 published standards from this technical committee.
CLC is a standardization organization that develops and publishes standards to support industry, commerce, and regulatory requirements.
A Technical Committee (TC) in CLC is a group of experts responsible for developing international standards in a specific technical area. TCs are composed of national member body delegates and work through consensus to create standards that meet global industry needs. Each TC may have subcommittees (SCs) and working groups (WGs) for specialized topics.
The products with digital elements in the scope of this document are the platforms of smartcards and similar devices including secure elements, which consist of a tamper-resistant MCU/MPU and optionally an application environment or operating system. Platforms are designed to store and process sensitive data, and to protect it against physical and logical attacks by attackers with significant resources and skills, at AVA_VAN.4 (moderate attack potential) or AVA_VAN.5 (high attack potential) levels. Although platforms do not delegate data processing to remote entities, these can be involved in operations such as software update, configuration or key provisioning. The platform ensures the authentication of the remote entities before receiving/sending sensitive information and ensures this information is protected during the exchange. Platforms are intended for final products including, but not limited to, electronic identity cards, removable UICCs, eUICC, payment cards, physical access cards, digital tachograph cards or wrist bands with integrated payment secure elements, trust anchors in connected digital products and critical IT systems. This document defines technical requirements for platforms, which meet the essential requirements defined in Regulation (EU) 2024/2847 to the extent described in Annex ZZ. It also defines the methods for assessing the technical requirements. The expression of the technical requirements and the assessment methods use the Common Criteria (CC) formalism defined in the EN ISO/IEC 15408 series and EN ISO/IEC 18045:2023 supplemented by the EUCC state-of-the-art documents for the technical domain smart cards and similar devices. This document covers platforms conformant with the Protection Profiles (PPs) PP0084, PP0117, PP0104 and PP TPM, and identifies the gaps of these specifications against the CRA essential requirements. In this document, PP0104 also refers to the PP0104-based PP-Configuration 0107. The evaluation of platforms against PP0084, PP0117, PP0104 or PP TPM plus the applicable additional technical requirements which cover their gaps allow to demonstrate conformance with the CRA essential requirements. The technical requirements and the mappings against PP0084, PP0117, PP0104 and PP TPM are defined in Clause 7 and Annex B, respectively. This document also covers platforms consisting of a hardware layer and either an application environment, e.g. Java Card platform, or firmware/software. Annex C contains an informative mapping of Java Card platforms towards PP0099. Platforms can have discrete, integrated or embedded form factors, and employ technologies such as integrated circuits, programmable macros or system-in-package or system-on-chip. These do not affect the requirements or the assessment methods. Unless specified, clauses apply to all platforms, from pure hardware to platforms consisting of hardware, firmware and/or software. Platforms are accompanied by guidance which contains all the requirements and recommendations for the secure integration of the platform into further intermediate or final products and the secure usage of the platform by the external entities. The guidance covers all the non-platform aspects which can impact the security of the platform assets. The applications stored and/or running on the platforms, which are an integral part of the final products, are outside the scope of this document. prEN 18330:2026 applies to products composed of a platform and a set of applications.
- Draft144 pagesEnglish languagee-Library read for1 day