A set of security criteria is only useful if there is an agreed way to test against it. Otherwise two evaluators could look at the same product and reach different conclusions, and the whole point of independent evaluation falls apart. ISO/IEC 18045:2022 is the standard that prevents that.
This page explains what ISO/IEC 18045:2022 is, why it matters, how it sits alongside the Common Criteria, and where it connects to the work of an inspection body. TNV Inspection Division is a UAF accredited inspection body operating under ISO/IEC 17020:2012, and protecting the information we handle is part of how we work.
What Is ISO/IEC 18045:2022?
ISO/IEC 18045 is the companion to the Common Criteria (ISO/IEC 15408). It is usually called the Common Evaluation Methodology, or CEM. Its full title is Information security, cybersecurity and privacy protection — Methodology for IT security evaluation.
Where ISO/IEC 15408 says what to evaluate and against what criteria, ISO/IEC 18045 says how to do the evaluation. It defines the minimum actions an evaluator performs when assessing a product against the Common Criteria.
Why Does ISO/IEC 18045 Matter for Your Business?
The value of an evaluation comes from its repeatability. A result that depends on which evaluator happened to do the work is not worth much. A result produced by a defined, shared methodology is one that buyers, regulators, and other countries can rely on.
ISO/IEC 18045 is what delivers that. By setting out the actions every evaluator must perform, it makes evaluations consistent, which in turn underpins the mutual recognition that lets a Common Criteria evaluation carried out in one country be accepted in another. For a vendor selling across borders, that is exactly what makes the effort worthwhile.
What Is the Scope of ISO/IEC 18045?
The standard applies to evaluators and the laboratories that carry out Common Criteria evaluations, and it is relevant to anyone who needs to understand how an evaluation is conducted. It specifies the minimum evaluator actions for an evaluation under ISO/IEC 15408, so the work is carried out the same way regardless of who performs it. It is the practical, on-the-ground half of the framework.
Differences Between ISO/IEC 18045 and Other Related Standards
It is easy to confuse the methodology with the criteria, so here is the clean split:
- ISO/IEC 15408-1 introduces the concepts and the general model.
- ISO/IEC 15408-4 provides the framework for turning criteria into evaluation activities.
- ISO/IEC 18045 supplies the methodology evaluators actually follow.
In short, ISO/IEC 15408 is what to evaluate and against what; ISO/IEC 18045 is how. The criteria describe the destination; the CEM is the route. An evaluation uses them together.
ISO/IEC 18045 and Information Security in Inspection
The distinction is worth stating plainly. A formal Common Criteria evaluation under ISO/IEC 18045 is specialised work, carried out by accredited evaluation laboratories under national schemes. That is a distinct activity from inspection.
What inspection shares with the CEM is the principle behind it: a defined, repeatable method applied by a competent, independent party, so the result does not depend on who carried it out. That is the foundation of inspection too. When our teams inspect IT and information-security-relevant systems in data-sensitive industries, we work to defined methods for the same reason the CEM exists, to make findings consistent and dependable, and we handle the information involved with the care an ISO 17020 inspection body is required to.
Who Should Use ISO/IEC 18045?
The standard is built for:
- Evaluators and laboratories carrying out Common Criteria evaluations.
- IT product vendors preparing for an evaluation who want to understand how it will be conducted.
- Security and compliance professionals who need to understand the rigour behind an evaluation result.
- Procurement teams that rely on consistent, comparable evaluation outcomes.
Our UAF Accreditation Explained
This is what separates a real inspection body from a general service provider, so it is worth a moment.
TNV Global Limited (TNV) is accredited by the United Accreditation Foundation (UAF) for inspection, under ISO/IEC 17020:2012 – Conformity assessment – Requirements for bodies providing various types of inspection. We hold that accreditation now, and we keep it through regular surveillance and witnessed inspections.
There are two reasons this matters to you. UAF is a signatory of the IAF MLA and the APAC MRA, the international recognition arrangements that let a report carry weight outside the country it was written in. And our accreditation covers work across most of Europe, the Americas, the Middle East, Africa, and Asia. So “internationally recognised” is something we can show you, not just say.
What Our Accreditation Means for You
In practice, it gives you a few things. Your reports travel, because UAF and those recognition arrangements mean our results are accepted across borders. You get real independence, because ISO/IEC 17020 keeps us impartial and clear of any tie to the people we inspect, so what we report is simply what we found. And you always know the boundaries of the job: the field we inspect, the point at which we inspect, the methods we use, and the standard we measure against are all set out before we start.
How an ISO Standard Plays a Crucial Role in Inspection
An inspection is only as good as the benchmark behind it. Take the standard away, and “passed” or “failed” turns into one inspector’s opinion on the day. The standard fixes that. It spells out what good actually means, so the same yardstick is used every time instead of a line that shifts from one job to the next.
That is the part the standard plays in our work. Every inspection is tied to one, and we check your product, system, or process against it. The standard says what is required. We are the independent set of eyes confirming, on the evidence, that you meet it. This is also where inspection parts ways with certification and formal evaluation. We are checking your work against a defined standard and telling you where it stands, and where a full Common Criteria evaluation is what you need, we point you to an accredited evaluation lab.
How to Apply for Inspection with TNV Inspection Division
The process follows our ISO/IEC 17020:2012 framework and stays simple from your side.
- Share your requirement. Reach us by website, email, phone, or WhatsApp and tell us what needs inspecting. We review the scope, the sector, and the standards that apply, then send a clear proposal covering method, timeline, and cost. Once you approve it, we sign a short agreement.
- Pre-inspection planning. We review the relevant documents and records, build the inspection plan, decide how information will be handled and protected, and assign inspectors whose experience fits the job.
- On-site inspection. Our team evaluates, measures, and records, keeping any sensitive information protected throughout. You stay informed on progress and early findings.
- Reporting and analysis. We compile the findings and recommendations, review the report internally for accuracy, and deliver it within the agreed timeframe.
- Follow-up and support. We answer questions, help you act on the findings, and point you to an accredited evaluation lab where a full Common Criteria evaluation is what you need.
Why Choose TNV Inspection Division?
TNV Inspection Division is an independent, UAF accredited inspection body working under ISO/IEC 17020:2012. Independence, impartiality, and defined methods are built into how we operate, which is the same quality any credible security check depends on. You get an outside party with recognised accreditation, qualified inspectors, and reports you can rely on, plus honest guidance on where inspection fits and where formal Common Criteria evaluation takes over.
Frequently Asked Questions(FAQ)
Talk to TNV Inspection Division
Need an independent, accredited partner for inspection of IT and information-security-relevant systems? Contact TNV Inspection Division for a clear scope and a free quote.