The evaluation process
Before testing, the applicant must engage an authorised laboratory, prepare the DS and environment, obtain favourable DS validation from CPSTIC and submit the application. Formal evaluation starts when the CCN accepts it.
- Stage 1: analysis of the Security Declaration and of the applicability matrix applied to it.
- Stage 2: access to and configuration of the test environment for the declared version.
- Stage 3: verification of each applicable SFR through functional, adversarial or penetration testing.
- Stage 4: additional penetration testing, with a minimum of three person-days, using at least the OWASP AI Testing Guide.
- Stage 5: generation of the Technical Evaluation Report (ITE) per Annex B.
Three person-days is the minimum effort for additional penetration testing, not the total project duration. All applicable SFRs must also be verified. Effort depends on architecture, interfaces, AI components and configurations.
Evaluation result
Each applicable SFR gets a PASS or FAIL result. The overall verdict is PASS only if all applicable SFRs pass, no non-conformity is recorded and the additional penetration testing does not identify AI-specific vulnerabilities that compromise the product's security. The laboratory records the verdict in the ITE and the CCN reviews the report and issues the final result.