Product characterisation
We analyse the product and document its AI architecture: interfaces, models, data, services and tools, and how they relate to each other.
We assess how AI could expose data, manipulate decisions or trigger unauthorised actions in your product. We prepare the documentation and manage the ESP-IA process, from defining the scope to CCN review of the results.

Does your product embed AI capabilities?
Request an evaluationWhen it applies
ESP-IA applies to products whose security is affected by AI-specific mechanisms: inference, learning, adaptation, context or state, learned representation, or actions mediated by an AI capability. If replacing AI with conventional software leaves essentially the same vulnerability and testing procedure, it generally falls outside ESP-IA's specific scope. It may still require assessment under another applicable methodology, such as LINCE or CICLON.
CCN-STIC 2011 defines the threats (evasion, injection, extraction, membership, inversion, poisoning, disclosure, agency and resource exhaustion) and the human oversight and traceability policies verified through specific security requirements and penetration testing.
End-to-end service
We start from the technical knowledge of your product and take care of structuring the documentation, preparing the test environment with the access your team enables and managing the process through to the CCN result.
We analyse the product and document its AI architecture: interfaces, models, data, services and tools, and how they relate to each other.
We write the Security Declaration with the necessary technical detail and manage its validation by CPSTIC.
We apply the matrix to the product architecture and capabilities to identify all applicable threats, policies and requirements. Existing controls are tested, they do not remove applicable requirements.
We define and set up the test environment: access to the product, logs and the evidence needed to verify each requirement.
We perform AI-specific penetration testing, using at least the OWASP AI Testing Guide and state-of-the-art attack techniques as the reference.
We help interpret findings, prepare documentary corrections and verify the product changes that your team needs to make.
Formal process
We follow the process defined in the CCN-STIC 2011 guide and keep traceability between the declared architecture, the applicable requirements, the tests executed and the result obtained.
We describe the architecture and AI capabilities and scope the evaluation and the applicable requirements.
We draft the Security Declaration, manage its validation by CPSTIC and file the evaluation request with the CCN. Formal evaluation starts when the CCN accepts the application.
We verify each applicable requirement and perform additional AI testing. We document the evidence and follow-up for the declared version.
We document findings and verified corrections in the Technical Evaluation Report. The CCN reviews the report and issues the evaluation result.
Each applicable requirement gets a PASS or FAIL result. The overall verdict is PASS only if all applicable requirements pass, no non-conformity is recorded and the penetration testing does not identify AI-specific vulnerabilities that compromise the product's security. The CCN reviews the laboratory's technical evaluation report and issues the result.
You do not need to have everything prepared before we start. We do need access to the people who know the AI implementation and the ability to prepare an evaluable environment and fix any non-conformities that appear.
Documentation and results
The technical documentation is complete and verified, and results are sent to the CCN in the technical evaluation report for validation.
Declared architecture, product characterisation and applicable requirements with their justification.
A complete Security Declaration, consistent with the product documentation and validated by the CPSTIC team.
PASS or FAIL results per requirement and traceability of the AI-specific penetration testing executed.
We coordinate verification of corrections and record the outcomes, including any unresolved findings.
We handle the analysis, document preparation, testing and evaluation report. You work directly with the team evaluating your product, with one point of contact throughout the process.
We take care of the ESP-IA evaluation so your team can stay focused on the product.
We manage the ESP-IA process end to end so your team can stay focused on the product.