India Nominated Chair of Common Criteria Development Board 2026-28
Why in the news
India took up the chair of the global board that sets technical rules for evaluating IT security products, for a two-year term.
Key facts
- Term: April 2026 to April 2028.
- Parent arrangement: CCRA, an international treaty with 38 member nations that accept each other’s IT security certificates without retesting.
- India’s channel: the STQC Directorate working with MeitY.
- India’s rank: holds Certificate Authorizing Nation standing from 2013, so Indian certificates are honoured across members.
- Standards handled: Common Criteria (ISO/IEC 15408) plus the evaluation method CEM.
What the CCDB does
| Role | Detail |
|---|---|
| Technical management | Runs the international work programme on ISO/IEC 15408 and CEM |
| Standard setting | Defines evaluation criteria for products such as firewalls, operating systems and smart cards |
| Portal upkeep | Maintains the Common Criteria Portal, the global list of certified products |
| Mutual recognition | Keeps a certificate from one member valid in all 38 |
| Working groups | Covers newer areas: cloud, IoT, AI, biometrics and mobile |
Background
- Common Criteria is the international standard to evaluate and certify IT product security, built on Protection Profiles, Security Targets and a seven-step scale of assurance levels (EAL 1 to EAL 7).
- EAL examples: EAL 1 means functionally tested; EAL 4 suits most commercial products (methodical design, test and review); EAL 7 is for defence-grade assurance with a formally verified design.
- Products certified: firewalls, operating systems, smart cards, smartphones, biometric devices, cryptographic modules and cloud security tools.
- STQC is an attached office of MeitY giving third-party testing and certification in IT and electronics, and runs India’s Common Criteria scheme.
- CERT-In works under Section 70B of the IT Act, 2000, and handles cyber incident response after deployment; STQC does pre-deployment evaluation.
- MRA: an agreement under which economies recognise each other’s testing or certification; CCRA is one for IT security.
- Chain of rules: CCRA gives the political framework, CCDB drafts the technical rules, and ISO/IEC 15408 is the resulting rulebook.
Significance
- India shifts from following to shaping global IT-security standards.
- It lifts cyber diplomacy and the export appeal of Indian IT and cybersecurity products.
- It builds India’s image as a trusted tech hub, complementing Digital India, India Stack exports and Cyber Surakshit Bharat.
- Many governments demand certified products for critical infrastructure, defence, banking and identity systems.
Exam angle
- Numbers: 38 members, 2013, a term of April 2026 to April 2028, EAL 1-7.
- Nodal ministry: MeitY; implementing body: STQC Directorate.
- Do not confuse STQC (certification) with CERT-In (incident response).