Qualified products
These are products and services for sensitive information in systems subject to ENS. The entry indicates the maximum category in which they can be used: HIGH, MEDIUM or BASIC.
What the CCN-STIC 105 guide contains, how to interpret the CPSTIC Catalogue, and why it matters.
CCN-STIC 105 is the STIC Products and Services Catalogue. It is the public catalogue reference used in the CPSTIC context: it shows which products and services have been recognised by the CCN, under which category they appear, and under which conditions they can be used.
Being in the CPSTIC Catalogue does not only demonstrate the security of the product or service. It is also a requirement for it to be used by ENS-regulated entities, including public administrations.
What it contains
Approved products, qualified products or services, and conformity and governance solutions.
Who it applies to
Manufacturers, providers and consumers that need to interpret the catalogue.
What it clarifies
ENS category, version, family, usage conditions, validity review and exclusion.
What to read too
CCN-STIC 106, CCN-STIC 140, LINCE or CICLON depending on the product type.
These are products and services for sensitive information in systems subject to ENS. The entry indicates the maximum category in which they can be used: HIGH, MEDIUM or BASIC.
These are aimed at handling Spanish classified information. In these cases, the catalogue entry indicates the maximum classification level for which the product is approved.
This category groups solutions for compliance, risk, audit, incident management, intelligence, training or security governance.
CPSTIC inclusion is not always prepared through the same route. Before starting, it is worth confirming the product type, delivery model, catalogue family and target category.
For on-prem products, software, hardware or IoT-related solutions, LINCE is the recommended entry route. If the product is delivered as a cloud service, CICLON is the recommended entry route.
If the product already has a Common Criteria or EUCC certification, it may be used for CPSTIC entry when it covers the necessary requirements. If there are remaining requirements, a complementary STIC may be needed to evaluate those points.
For solutions in this category, inclusion is carried out through a pentest following a CCN-specific evaluation methodology based on OWASP Top 10.
The CPSTIC Catalogue is not just a list of products and services. Royal Decree 311/2022, which regulates the Spanish ENS expressly refers to the catalogue in measures op.pl.5.1 and op.pl.5.2.
When a company selects third-party security products or services, CPSTIC must be used as the reference if the system is subject to ENS. It is not enough for the platform providing the service to be ENS certified: the service itself must have been evaluated and included in the CPSTIC Catalogue where applicable.
Appearing in the catalogue can be the difference between offering the product to ENS-regulated organisations or being excluded from Spanish public-sector tenders.
Each catalogue entry helps interpret the status of a specific product or service.
A product being qualified for one family does not automatically mean it is qualified for every family where it might functionally fit. Products appear only in the evaluated families, so qualified use is tied to the purposes and conditions that were evaluated.
The catalogue is updated monthly and reflects new inclusions, validity reviews, version changes and possible exclusions.
The CCN provides both a web version of the catalogue and a PDF version. The web version is the most useful reference for checking the current status of a product or service.
We help you enter the CPSTIC Catalogue through a coherent route for your product or service: fit, applicable family, target category, documentation, evaluation and support through to inclusion.
We analyse your product, confirm the right route and handle the documentation, evaluation and CPSTIC Catalogue inclusion process.