What the laboratory really reviews
The work is not limited to testing the service. The methodology requires review of the Security Target, the architecture declared in the DAS, SBOM traceability, real access to the environment and the robustness of communications, in addition to functional testing and penetration testing.
Evaluation result
The final verdict is expressed through the Composite Assurance Percentage (PGC), which integrates evaluation and monitoring. If non-conformities appear during the process, the verdict becomes FAIL and the PGC is 0. The vendor must resolve the non-conformities, and the laboratory verifies against the corrected version that the identified issues have been resolved.