The Missing Methodology: Applying Common Criteria to Give the Cyber Trust Mark Real Teeth (T02a)
The Cyber Trust Mark identifies the appropriate IoT security properties but lacks evaluation rigor because NIST IR 8425 specifies requirements without defining how products are tested, creating inconsistency across evaluations. Common Criteria Protection Profiles with defined evaluation activities provide this missing structure, ensuring consistent results regardless of who performs the testing and allowing assurance to scale appropriately for consumer IoT products. A PP-based approach may also unlock CCRA mutual recognition, allowing a single evaluation to satisfy multiple regional requirements.
