Scope and level
We inventory mechanisms, protocols, parameters and dependencies to define the scope and determine the applicable level: CL1, CL2 or CL3.
We evaluate the cryptography implemented in your product: mechanisms and protocols, parameterisation, conformity testing, implementation pitfalls and the evidence required for the applicable CL1, CL2 or CL3 level.
Do you need to evaluate your product's cryptography?
Request an evaluationWhen it applies
MEMeC is used when a product's cryptographic mechanisms need to be assessed in depth during a certification or CPSTIC inclusion process. The methodology covers products under Common Criteria, LINCE or STIC. MEMeC is performed as a separate evaluation in parallel with the main process. It must not be confused with MEC, the cryptographic module integrated into LINCE. The work goes beyond checking a list of algorithms: it examines how they are configured, how the product uses them and whether the implementation returns conformant results.
Before testing starts, we identify the mechanisms in scope, the libraries and components implementing them, the required level and the interfaces available to exercise them.
CCN-STIC 221 sets out the cryptographic mechanisms and parameters accepted by the CCN. MEMeC verifies that the product implements and uses them correctly with the declared parameterisation.
End-to-end service
We start from your team's technical knowledge and handle the documentation structure, test preparation and traceability through remediation verification.
We inventory mechanisms, protocols, parameters and dependencies to define the scope and determine the applicable level: CL1, CL2 or CL3.
We work with your team to complete the Vendor Questionnaire (VQ), its Lite version or the random number generation questionnaire.
We review the interfaces, test harness and instructions needed to reach the primitives and reproduce the tests.
We run the test vectors and analyse the response files produced by the mechanisms included in scope to verify that they return the expected results.
We check parameterisation, library use and the evidence needed to rule out implementation pitfalls.
We report the non-conformities so your team can resolve them. We then verify against the corrected version that the identified issues have been resolved.
Formal process
We follow the process defined in the CCN-STIC 2100 guide and maintain traceability between the declared mechanisms, applicable tasks, performed tests and the resulting outcome.
We review the inventory, questionnaires, version, interfaces and evidence to establish the scope and level.
We identify mandatory tasks and those that depend on functionality implemented by the product.
We assess requirements, CCN-STIC 221, conformity, self-tests, sensitive parameters and implementation pitfalls.
We report non-conformities, verify against the corrected version that the identified issues have been resolved and document the outcome with full traceability.
The outcome maintains traceability between the performed tasks, reviewed evidence, tests and verified remediation throughout the evaluation.
You do not need to have all the information prepared before we start. We do need access to the people who understand the implementation, as well as the ability to prepare an evaluable build and remediate any non-conformities.
Documentation and results
The technical documentation is complete and verified, and the results are submitted to the CCN through the corresponding evaluation reports.
An inventory of mechanisms, the applied level, the evaluated version and traceability to the interfaces and evidence used.
Completed MEMeC documentation supported by the technical information needed to substantiate each response.
Conformity results and traceability of the checks performed on the cryptographic mechanisms included in scope.
We verify against the corrected version that the issues identified during the evaluation have been resolved.
We handle the analysis, documentation preparation, testing and remediation verification. The same team coordinates the work throughout to preserve the technical context between phases.
We handle the MEMeC evaluation so your team can stay focused on the product.
We handle the security evaluation and MEMeC from start to finish so your team can stay focused on the product.