The Common Criteria has long had two halves: the criteria that say what a secure IT product should be, and the methodology that says how to test it. What was missing was a clean, structured way to connect the two. ISO/IEC 15408-4:2022 fills that gap.
This page explains what ISO/IEC 15408-4:2022 is, why it matters, how it sits alongside the rest of the Common Criteria, and where it connects to the work of an inspection body. TNV Inspection Division is a UAF accredited inspection body operating under ISO/IEC 17020:2012, and protecting the information we handle is part of how we work.
What Is ISO/IEC 15408-4:2022?
ISO/IEC 15408 is the Common Criteria, the international framework for evaluating the security of IT products. Its full title is Information security, cybersecurity and privacy protection — Evaluation criteria for IT security. The 2022 edition restructured the standard into five parts, and Part 4 is one of the additions.
Part 4 provides a framework for specifying evaluation methods and activities. In plain terms, it is the bridge between the criteria and the methodology, letting evaluation activities be derived in a defined way from ISO/IEC 18045 rather than improvised.
Why Does ISO/IEC 15408-4 Matter for Your Business?
Consistency is the whole point of the Common Criteria. An evaluation is only worth something if it would come out the same way in another lab or another country. Before the 2022 edition, deriving consistent evaluation activities from the methodology was left largely to interpretation, which left room for results to drift.
Part 4 closes that gap. By giving evaluation methods a shared framework, it strengthens the consistency that makes evaluations comparable and internationally recognised. For a vendor, that means an evaluation result that holds its value across markets. For a buyer, it means more confidence that two evaluations mean the same thing.
What Is the Scope of ISO/IEC 15408-4?
Part 4 is aimed at the people who build and run evaluations: the authors of evaluation requirements, the schemes that oversee them, and the laboratories that carry them out. It lets evaluation activities and methods be developed in a structured way from the methodology in ISO/IEC 18045, so the people writing the requirements and the people doing the work are aligned on the same approach. It is a framework for specifying methods, not a methodology you apply directly on its own.
Differences Between ISO/IEC 15408-4 and Other Related Standards
The Common Criteria is a family, and Part 4 is the connecting piece. A few quick relationships:
- ISO/IEC 15408-1 introduces the concepts and the general model.
- ISO/IEC 15408-2 and 15408-3 hold the catalogues of security functional and assurance requirements.
- ISO/IEC 15408-4 provides the framework for turning those criteria into evaluation methods and activities.
- ISO/IEC 18045 is the methodology that says how an evaluation is actually carried out, and the source Part 4 derives activities from.
Read on its own, Part 4 is incomplete. It earns its place as the structural link in the set.
ISO/IEC 15408-4 and Information Security in Inspection
The lines are worth drawing clearly. A formal Common Criteria evaluation is specialised work, carried out by accredited evaluation laboratories under national schemes. That is a distinct activity from inspection.
What inspection shares with Part 4 is the value at its heart: consistency. An evaluation, or an inspection, is only worth something if it would come out the same way done by another competent party. Part 4 exists to make evaluation methods consistent. Inspection bodies rely on the same idea, working to defined methods so results are repeatable rather than down to who happened to do the job. When our teams inspect IT and information-security-relevant systems, that disciplined, method-driven approach is exactly how we work, and we handle the information involved with the care an ISO 17020 inspection body is required to.
Who Should Use ISO/IEC 15408-4?
The standard is built for:
- Evaluators and laboratories working within the Common Criteria framework.
- Schemes and authors who specify evaluation requirements.
- IT product vendors preparing for an evaluation who want to understand how methods are specified.
- Security and compliance professionals who need to understand the rigour behind an evaluation.
Our UAF Accreditation Explained
This is what separates a real inspection body from a general service provider, so it is worth a moment.
TNV Global Limited (TNV) is accredited by the United Accreditation Foundation (UAF) for inspection, under ISO/IEC 17020:2012 – Conformity assessment – Requirements for bodies providing various types of inspection. We hold that accreditation now, and we keep it through regular surveillance and witnessed inspections.
There are two reasons this matters to you. UAF is a signatory of the IAF MLA and the APAC MRA, the international recognition arrangements that let a report carry weight outside the country it was written in. And our accreditation covers work across most of Europe, the Americas, the Middle East, Africa, and Asia. So “internationally recognised” is something we can show you, not just say.
What Our Accreditation Means for You
In practice, it gives you a few things. Your reports travel, because UAF and those recognition arrangements mean our results are accepted across borders. You get real independence, because ISO/IEC 17020 keeps us impartial and clear of any tie to the people we inspect, so what we report is simply what we found. And you always know the boundaries of the job: the field we inspect, the point at which we inspect, the methods we use, and the standard we measure against are all set out before we start.
How an ISO Standard Plays a Crucial Role in Inspection
An inspection is only as good as the benchmark behind it. Take the standard away, and “passed” or “failed” turns into one inspector’s opinion on the day. The standard fixes that. It spells out what good actually means, so the same yardstick is used every time instead of a line that shifts from one job to the next.
That is the part the standard plays in our work. Every inspection is tied to one, and we check your product, system, or process against it. The standard says what is required. We are the independent set of eyes confirming, on the evidence, that you meet it. This is also where inspection parts ways with certification and formal evaluation. We are checking your work against a defined standard and telling you where it stands, and where a full Common Criteria evaluation is what you need, we point you to an accredited evaluation lab.
How to Apply for Inspection with TNV Inspection Division
The process follows our ISO/IEC 17020:2012 framework and stays simple from your side.
- Share your requirement. Reach us by website, email, phone, or WhatsApp and tell us what needs inspecting. We review the scope, the sector, and the standards that apply, then send a clear proposal covering method, timeline, and cost. Once you approve it, we sign a short agreement.
- Pre-inspection planning. We review the relevant documents and records, build the inspection plan, decide how information will be handled and protected, and assign inspectors whose experience fits the job.
- On-site inspection. Our team evaluates, measures, and records, keeping any sensitive information protected throughout. You stay informed on progress and early findings.
- Reporting and analysis. We compile the findings and recommendations, review the report internally for accuracy, and deliver it within the agreed timeframe.
- Follow-up and support. We answer questions, help you act on the findings, and point you to an accredited evaluation lab where a full Common Criteria evaluation is what you need.
Why Choose TNV Inspection Division?
TNV Inspection Division is an independent, UAF accredited inspection body working under ISO/IEC 17020:2012. Independence, impartiality, and defined methods are built into how we operate, which is the same quality any credible security check depends on. You get an outside party with recognised accreditation, qualified inspectors, and reports you can rely on, plus honest guidance on where inspection fits and where formal Common Criteria evaluation takes over.