
1
min reading time
The new PP was developed and published in November 2019 by Ad-Hoc Group Privacy & Security of the CEN/CENELEC/ETSI Coordination Group on Smart Meters.
The latest PP document is available on the Common Criteria Portal.
As the number of IoT and specifically smart metering products have been increasing recently all over the world, it will be a great help for factories, producers and also for clients who intend to use these kinds of products in the future. The PP includes a detailed description of all the minimum security requirements which should be met by any smart metering product available on the market.
Why do we like it so much?
CCLAB has great experience in CC evaluations and smart metering devices.
With the clear Protection Profile CCLAB will keep on providing the most effective and shortest possible evaluation projects on the highest professional level for its clients.


Get your FREE A-Z supporting material for smart meter security standards. Learn more about the Swiss METAS data security evaluation projects of smart metering devices.


This downloadable infographics introduces you to the Swiss Smart Metering data security pre-assessment process of METAS certification.


This downloadable infographics introduces you to Swiss Smart Metering data security evaluation process of METAS certification.

This article provides a strategic guide to the new EUCC assurance levels, explaining what "Substantial" and "High" certifications actually mean for your market access. It demystifies the critical shift from simple EAL numbers to risk-based vulnerability analysis (AVA_VAN), detailing exactly which products require advanced penetration testing versus basic surveys. You will learn how to map your device to the correct assurance category, navigate the new mandatory lifecycle and patching requirements, and avoid the costly trap of over-engineering your compliance strategy.
5
min reading time

This is a comprehensive overview of the transition to EUCC (European Common Criteria-based cybersecurity certification scheme). It effectively highlights the shift from the old, fragmented SOG-IS approach to a unified, risk-based framework under the Cybersecurity Act.
8
min reading time

As the 11 September 2026 reporting deadline approaches, understanding the Cyber Resilience Act (CRA) is essential for all manufacturers of digital products. This blog post explores the key differences and overlaps between the CRA and the EUCC certification scheme, providing a clear roadmap for compliance, risk categorization, and long-term market access.
9
min reading time