CPSTIC guide

CCN-STIC 105: CPSTIC Catalogue explained

What the CCN-STIC 105 guide contains, how to interpret the CPSTIC Catalogue, and why it matters.

What CCN-STIC 105 is

CCN-STIC 105 is the STIC Products and Services Catalogue. It is the public catalogue reference used in the CPSTIC context: it shows which products and services have been recognised by the CCN, under which category they appear, and under which conditions they can be used.

Practical criterion

Being in the CPSTIC Catalogue does not only demonstrate the security of the product or service. It is also a requirement for it to be used by ENS-regulated entities, including public administrations.

Quick reading

What it contains

Approved products, qualified products or services, and conformity and governance solutions.

Who it applies to

Manufacturers, providers and consumers that need to interpret the catalogue.

What it clarifies

ENS category, version, family, usage conditions, validity review and exclusion.

What to read too

CCN-STIC 106, CCN-STIC 140, LINCE or CICLON depending on the product type.

Qualified products

These are products and services for sensitive information in systems subject to ENS. The entry indicates the maximum category in which they can be used: HIGH, MEDIUM or BASIC.

Approved products

These are aimed at handling Spanish classified information. In these cases, the catalogue entry indicates the maximum classification level for which the product is approved.

Conformity and governance

This category groups solutions for compliance, risk, audit, incident management, intelligence, training or security governance.

How to enter the CPSTIC Catalogue

CPSTIC inclusion is not always prepared through the same route. Before starting, it is worth confirming the product type, delivery model, catalogue family and target category.

LINCE or CICLON

For on-prem products, software, hardware or IoT-related solutions, LINCE is the recommended entry route. If the product is delivered as a cloud service, CICLON is the recommended entry route.

Already certified products

If the product already has a Common Criteria or EUCC certification, it may be used for CPSTIC entry when it covers the necessary requirements. If there are remaining requirements, a complementary STIC may be needed to evaluate those points.

Conformity and governance

For solutions in this category, inclusion is carried out through a pentest following a CCN-specific evaluation methodology based on OWASP Top 10.

Why it matters under ENS

The CPSTIC Catalogue is not just a list of products and services. Royal Decree 311/2022, which regulates the Spanish ENS expressly refers to the catalogue in measures op.pl.5.1 and op.pl.5.2.

When a company selects third-party security products or services, CPSTIC must be used as the reference if the system is subject to ENS. It is not enough for the platform providing the service to be ENS certified: the service itself must have been evaluated and included in the CPSTIC Catalogue where applicable.

Practical impact

Appearing in the catalogue can be the difference between offering the product to ENS-regulated organisations or being excluded from Spanish public-sector tenders.

What the catalogue shows

Each catalogue entry helps interpret the status of a specific product or service.

Product or service name
Qualified or approved version
Manufacturer
Family or functional category
Product or service type
ENS category where applicable
Inclusion date
Validity review date
Associated secure usage procedure

Evaluated families and allowed use

A product being qualified for one family does not automatically mean it is qualified for every family where it might functionally fit. Products appear only in the evaluated families, so qualified use is tied to the purposes and conditions that were evaluated.

Monthly update

The catalogue is updated monthly and reflects new inclusions, validity reviews, version changes and possible exclusions.

Validity review

  • Keeping certifications valid.
  • Addressing changes in RFS.
  • Correcting relevant vulnerabilities.
  • Keeping consistency between the qualified version and the version actually offered.
  • Preparing renewals when required.

Reasons for exclusion

  • Expiry of the certificate or lack of a new inclusion request.
  • Revocation or expiry of required certifications.
  • Loss of exceptional-route conditions.
  • Failure to meet current RFS.
  • Uncorrected critical vulnerabilities.

Official sources

The CCN provides both a web version of the catalogue and a PDF version. The web version is the most useful reference for checking the current status of a product or service.

How CYBSER helps

We help you enter the CPSTIC Catalogue through a coherent route for your product or service: fit, applicable family, target category, documentation, evaluation and support through to inclusion.

Do you want to enter the CPSTIC Catalogue?

We analyse your product, confirm the right route and handle the documentation, evaluation and CPSTIC Catalogue inclusion process.