NIAP: Common Criteria Testing Laboratories (CCTL)
  NIAP  »»  Resources  »»  Common Criteria Testing Laboratories (CCTL)  
Common Criteria Testing Laboratories (CCTL)

NIAP-approved Common Criteria Testing Laboratories (CCTLs) are IT security testing laboratories that are accredited by the NIST National Voluntary Laboratory Accreditation Program (NVLAP) and meet CCEVS-specific requirements to conduct IT security evaluations for conformance to the Common Criteria for Information Technology Security Evaluation, International Standard ISO/IEC 15408. 

Click the link to see Candidate CCTLs currently in the approval process. 

9 Common Criteria Testing Laboratories
Lab Name Lab POC  NVLAP Lab Code  Test Methods
This list was generated on Monday, May 27, 2024, at 2:41 PM
Acumen Security
2400 Research Blvd. #395 
Rockville, MD 20850
Mr. Shaunak Shah
703-375-9820 (phone)
201029-0 APE, ASE, EAL 1, PP/cPP
Advanced Data Security
1933 O'Toole Avenue 
San Jose, CA 95131
Mr. Eugene Polulyakh
408-433-9448 (phone)
408-433-9665 (fax)
200968-0 APE, ASE, EAL 1, PP/cPP
atsec information security corporation
4516 Seton Center Parkway 
Suite 250
Austin, TX 78759
Ms. Trang Huynh
512-615-7318 (phone)
512-615-7301 (fax)
200658-0 APE, ASE, EAL1, PP/cPP
Booz Allen Hamilton Common Criteria Testing Laboratory
1100 West Street 
Laurel, MD 20707
Mr. Chris Gugel
240-547-5104 (phone)
301-953-2368 (fax)
200423-0 APE, ASE, EAL1, PP/cPP
DEKRA Cybersecurity Certification Laboratory
405 Glenn Drive 
Suite #12
Sterling, VA 20164
Nithya Rachamadugu
703-216-3978 (phone)
600319 APE, ASE, EAL 1, PP/cPP
Gossamer Security Solutions
9176 Red Branch Rd. 
Suite L
Columbia, MD 21045
Ms. Tammy Compton
240-994-9770 (phone)
410.788.5064 (fax)
200997-0 APE, ASE, EAL1, PP/cPP
Leidos Common Criteria Testing Laboratory
6841 Benjamin Franklin Drive 
Suite 400
Columbia, MD 21046
Mr. Justin Fisher
443-367-7407 (phone)
200427-0 APE, ASE, EAL1, PP/cPP
Lightship Security USA, Inc.
3600 O’Donnell Street 
Grain Building Suite 2
Baltimore, MD 21224
+1 (512) 362-6594
Mr. Kevin Steiner
512-362-6594 ext. 726 (phone)
600262-0 APE, ASE, EAL1, PP/cPP
UL Verification Services Inc. (Formerly InfoGard)
709 Fiero Lane 
Suite 25
San Luis Obispo, CA 93401
Mr. Oleg Andrianov
805-783-0810 (phone)
805-783-0889 (fax)
100432-0 APE, ASE, EAL1, PP/cPP

These laboratories must meet the requirements of:

  • NIST Handbook 150, NVLAP Procedures and General Requirements;
  • NIST Handbook 150-20, NVLAP Information Technology Security Testing - Common Criteria;
  • Specific criteria for IT security evaluations and other requirements of the scheme as defined by the NIAP Validation Body.

CCTLs enter into contractual agreements with sponsors to conduct security evaluations of IT products and protection profiles using NIAP-approved test methods derived from the Common Criteria, Common Methodology and other technology-based sources. The IT security evaluations are carried out in accordance with the policies and procedures of the scheme. CCTLs must observe the highest standards of impartiality, integrity, and commercial confidentiality, and operate within the guidelines established by the scheme.

To become a CCTL, a testing laboratory must go through a series of steps that involve both the NIAP Validation Body and NVLAP. Accreditation by NVLAP is the primary requirement for achieving CCTL status. Scheme requirements that cannot be satisfied by NVLAP accreditation are addressed by the NIAP Validation Body. At present, there are only three scheme-specific requirements imposed by the Validation Body. NIAP approved CCTLs:

  • must reside within the U.S. and be a legal entity, duly organized and incorporated, validly existing, and in good standing under the laws of the state where the laboratory intends to do business;
  • must agree to accept U.S. Government technical oversight and validation of evaluation-related activities in accordance with the policies and procedures established by the NIAP Common Criteria Scheme;
  • must agree to accept U.S. Government participants in selected Common Criteria evaluations conducted by the laboratory in accordance with the policies and procedures established by the NIAP Common Criteria Scheme.

A testing laboratory becomes a CCTL when the laboratory is approved by the Validation Body and is listed on the NIAP Approved Laboratories List.

To avoid unnecessary expense and delay in becoming a NIAP-approved testing laboratory, it is strongly recommended that prospective CCTLs ensure that they are able to satisfy the scheme-specific requirements prior to seeking accreditation from NVLAP. This can be accomplished by sending a letter of interest to the NIAP Validation Body prior to entering the NVLAP process.

Additional laboratory-related information can be found in Scheme Publication #1 Common Criteria Evaluation and Validation Scheme for Information Technology Security -- Organization, Management, and Concept of Operations and Scheme Publication #4 Common Criteria Evaluation and Validation Scheme for Information Technology Security -- Guidance to Common Criteria Testing Laboratories.

Site Map              Contact Us              Home