📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Governance, risk & compliance

CCCS Common Criteria Program (Product Certification) Program Instructions v2.3 (May 2025)

Canadian Common Criteria Program, run by the Canadian Centre for Cyber Security as Canada's Certification Body under the Common Criteria Recognition Arrangement (CCRA).

A product vendor has an accredited lab (in Canada, EWA-Canada or Lightship Security) evaluate an IT product against the Common Criteria and its evaluation methodology (ISO/IEC 15408 and 18045), usually against a collaborative Protection Profile; the Cyber Centre oversees the evaluation and issues the certificate, which CCRA members recognize. The program prioritizes collaborative Protection Profiles; EAL-based evaluations are accepted up to EAL2, with EAL3 or EAL4 case by case.

An evaluation passes four gates (Security Target, design and entropy, testing, final) and should finish within six months of the Products in Evaluation listing. Certified products must use cryptography approved in ITSP.

40. 111 with CAVP-validated implementations where the Protection Profile requires it, and must have no known unmitigated vulnerabilities at certification.

Certificates carry a default five-year administrative validity (CCRA procedure CCDB-012). The Government of Canada recommends buying certified products and individual tenders often require them.

This framework is for vendors preparing a product for certification; it is not about an organization's own security program.

How Lavawall® helps you get to CCCS Common Criteria Program (Product Certification) compliance

Most of CCCS Common Criteria Program (Product Certification) comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to CCCS Common Criteria Program (Product Certification), and tracks your posture continuously instead of once a year at audit time.

  • Assess your current state against CCCS Common Criteria Program (Product Certification) in the Lavawall GRC module, with the questionnaire and control set built in.
  • Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
  • Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.

Related

Lavawall® supports CCCS Common Criteria Program (Product Certification) as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.

At a glance

Framework
CCCS Common Criteria Program (Product Certification) Program Instructions v2.3 (May 2025)
Category
Security
Region
Canada

Official source →


Map this framework freeTalk to our team