Overview
EN ISO/IEC 15408-4:2026 is an international standard developed by the European Committee for Standardization (CEN) under the ISO/IEC 15408 series for information security, cybersecurity, and privacy protection. This part specifies a standardized framework for the specification of evaluation methods and evaluation activities. It supports organizations and evaluation authorities in defining objective, repeatable, and reproducible processes for IT security assessments.
The document provides foundational requirements and a structural model for how evaluation methods and activities should be described, ensuring comparability, transparency, and alignment with broader assurance frameworks. EN ISO/IEC 15408-4:2026 does not dictate how to perform, adopt, or maintain evaluation methods - these choices are left to those developing the methods for specific technological or regulatory needs.
Key Topics
- Framework Specification: Outlines how to structure the definition of IT security evaluation methods and activities so that results are credible and reproducible.
- Terminology Alignment: Ensures consistent use of terminology by referencing ISO/IEC 15408-1, 15408-2, 15408-3, and ISO/IEC 18045.
- Modular Approach: Supports tailoring of evaluation activities for specific technologies, products or security requirements, promoting reuse and scalability.
- Objective and Repeatable Results: Emphasizes the importance of defined methods and activities being objective and allowing for reproducible outcomes.
- Separation of Specification and Practice: Focuses solely on the framework for specification, not on implementation or assessment techniques.
Applications
EN ISO/IEC 15408-4:2026 is designed for a broad range of stakeholders involved in cybersecurity and IT security evaluation contexts, including:
- Standards Developers & Evaluation Authorities: As a foundation for developing new evaluation methods for emerging technologies such as cloud services, IoT devices, or AI systems.
- IT Product Vendors: To align security evaluation documentation with international best practice, facilitating acceptance in global markets.
- Conformance Assessment Bodies: For structuring how evaluation activities are mandated and reported in protection profiles (PPs), security targets (STs), or specific evaluation contexts.
- Regulators & Government Agencies: To reference a consistent approach for specifying security evaluation requirements in procurement or certification schemes.
- Cybersecurity Consultants: As a guideline for advising clients in the preparation of repeatable and transparent evaluation activities for IT security certification.
Practical uses range from the development of protection profiles requiring specific evaluation activities, through bespoke security assurance for technology deployments, to consistent reporting and audit processes for compliance verification.
Related Standards
EN ISO/IEC 15408-4:2026 is part of an internationally recognized series for IT security evaluation. Key related standards include:
- ISO/IEC 15408-1: Introduction and general model - establishes principles and structure for IT security evaluation.
- ISO/IEC 15408-2: Security functional components - outlines standardized security functions for IT products.
- ISO/IEC 15408-3: Security assurance components - details assurance requirements and classes.
- ISO/IEC 18045: Methodology for IT security evaluation - provides companion methodology for many assurance requirements defined in the 15408 series.
- ISO/IEC 15408-5: Extended components definitions - for extended sets of security requirements where needed.
These standards work together to form the Common Criteria framework, widely adopted for global IT security certification and evaluation.
By adhering to EN ISO/IEC 15408-4:2026, organizations can ensure their IT security evaluation methods are robust, standardized, and recognized internationally, supporting interoperability, transparency, and improved assurance in cybersecurity and privacy protection.