CCN-STIC 2001
Explains the LINCE certification framework and helps manufacturers understand when this route applies to on-prem software, hardware and IoT.
See CCN-STIC 2001 guide →We manage the entire process to get your product listed in the CPSTIC Catalogue, the de facto requirement for selling to the Spanish government and strategic companies.

The CPSTIC (ICT Security Product Catalogue), officially defined in the CCN-STIC 105 document, is the official portfolio of cybersecurity products and services approved for use within the Spanish Public Administration and entities governed by the National Security Framework (ENS).
For all practical purposes, being listed is the non-negotiable entry ticket for public sector procurement. It is the official proof that a product meets Spain’s rigorous security standards, making it the default choice for government buyers.

An essential requirement for contracting with the Public Administration.
For on-prem software, hardware and IoT products, LINCE is often the direct route towards CPSTIC inclusion. These guides explain the framework and methodology behind that decision.
Explains the LINCE certification framework and helps manufacturers understand when this route applies to on-prem software, hardware and IoT.
See CCN-STIC 2001 guide →Details the LINCE evaluation methodology, minimum evidence and the technical preparation expected from the vendor.
See CCN-STIC 2002 guide →Choose the right certification path according to how your product is deployed.
The right fit for cloud-native products that need to prove security in SaaS, PaaS or IaaS environments.
The better fit for products deployed on customer infrastructure, installed on-premises or delivered outside a cloud service model.
We help you choose the route that fits your product’s maturity, target category, and timelines.

Agile, cost-effective evaluation designed for software, hardware and other on-prem products seeking CPSTIC inclusion.

The primary route for cloud products and services such as SaaS, PaaS and IaaS when your goal is CPSTIC inclusion in Spain.

For products that are already certified and only need to cover specific additional gaps required for CPSTIC inclusion.

Internationally recognized certification. From EAL2 upwards, with conformance to the family’s Security Functional Requirements (SFR) for CPSTIC.
Your product and goals determine the most efficient route. Here’s how the main paths compare for CPSTIC Catalogue inclusion.
LINCE | CICLON | Complementary STIC | Common Criteria / EUCC | |
|---|---|---|---|---|
| Your Goal Is | You need fast, direct CPSTIC entry for software, hardware or other on-prem products. | You need CPSTIC access for a cloud product or service. | You already have a certified product and only need to close specific gaps. | Products requiring the highest assurance for global markets. |
| Core Focus | Functional analysis and penetration testing. | Cloud evaluation, web/cloud pentesting and continuous monitoring. | Targeted closure of remaining gaps in already certified products. | Exhaustive formal documentation and process verification. |
| Time & Effort | Low | Variable according to cloud scope | Focused | High (Months/Years) |
| Cost | Most Affordable | Adapted to architecture and monitoring scope | Adjusted to the pending gaps only | Significant Investment |
We combine deep regulatory knowledge with strategic project management to deliver results, not just reports.
We don’t just follow a checklist. We analyze your product and goals to find the fastest, most cost-effective route to inclusion.
From initial scoping to final submission and CCN liaison, we manage the entire lifecycle, freeing up your team to focus on your product.
Our team possesses deep, hands-on experience with the different CPSTIC families and taxonomies, as well as the nuances of the CCN’s processes.
We handle the complexity, you get the result. Our process adapts to your product's unique needs, ensuring the most efficient path to inclusion.
We start with a free analysis of your product and goals. We then determine the most efficient path for you: LINCE for on-premises software, products with a hardware component and other on-prem products, CICLON for cloud, or Complementary STIC when an already certified product only needs to close specific gaps.
We manage the creation of all required documentation, including the Security Target and support for manuals, ensuring it meets the CCN’s rigorous standards so you don’t have to worry about the paperwork.
If testing is required, we perform the evaluation with no waiting queues. If issues are found, we work with your team to resolve them. Throughout the process, we act as your single technical point of contact, managing all queries to ensure a smooth process.
We prepare and submit the complete package to the CCN, proactively managing all communications and follow-ups to ensure a smooth and timely review for CPSTIC inclusion.
Your product is officially included in the CPSTIC Catalogue. We then generate the mandatory Secure Usage Procedure (PES) document to finalize your listing.
Schedule a free, no-obligation consultation to analyze your product and get a clear roadmap for CPSTIC inclusion.