2020 Statistics Report. Is the industry surviving to lockdown?

Javier Tallón
Javier TallónSecurity Expert at jtsec Beyond IT Security
2020 Statistics Report. Is the industry surviving to lockdown?
2020 Statistics Report. Is the industry surviving to lockdown?
 CC data collection with CCScraper
 CC statistics for 2020
 CC Statistics for 5 years
 Some historical CC statistics
 Conclusions
Contents
2020 Statistics Report. Is the industry surviving to lockdown?
 Web scraper written in Python. Created in 2018 by jtsec.
 CCScraper collects data about certified products from commoncriteriaportal.org
and from the websites of the Certification Body.
 Tons of interesting data collected: date of certification, EAL, PP, Product
Category, certification lab, etc. and even SFRs used or technical terms in the ST!
 Data is interpreted and organized / merged into a list of unique certified
products. We generate the statistics from that data.
What is CCScraper
 CCScraper v1.0 was first presented here in the ICCC in 2018.
 Only data from commoncriteriaportal.org was collected.
 CCScraper v2.0 was presented in ICCC 2019.
 Main feature: add information from CB websites and merge into
unique products
 CCScraper v2.1 presented today in ICCC 2020.
 Efficiency dramatically improved: 18 hours vs 5 days of execution.
 Nothing is perfect… so we implemented logging and email alert logic in
case we find errors / uncontemplated cases.
CCScraper history
 New laboratories found!… we had to review our parsing logic and reports!
 CSEC website changed it structure during this year: we had to re-code its
scraper.
 NSCIB started to upload Site Security Certifications and dates were
removed from the product listing.
 The scraper run an OK test in September but… in November the Australian
CB ACSC website had entirely changed!
Latest challenges for CCScraper
 With the statistics generated, we publish CC statistics reports in jtsec
webpage, at least once per year.
CCscraper reports
 https://www.jtsec.es/blog-entry/25/common-criteria-
statistics-report-for-2018
 https://www.jtsec.es/blog-entry/44/common-criteria-
statistics-report-for-2019
2020 Statistics Report. Is the industry surviving to lockdown?
Statistics – 2020 (10 months)
 315 products certified during 2020 (data from 05/11/2020)
 Top certifier schemes in 2020
Statistics – 2020 (10 months)
Statistics – 2020 (10 months)
 The top 3 schemes add up to 55% of the certifications!
 Certified products compliance in 2020
Statistics – 2020 (10 months)
 Product assurance level per country during 2020
Statistics – 2020 (10 months)
 Top 10 Laboratories (2020)
Statistics – 2020 (10 months)
Statistics – 2020 (10 months)
 Protection Profile certifications
Statistics – 2020 (10 months)
 PP and cPP compliant certifications in 2020
 Top 5 manufacturers of certified products (2020)
Statistics – 2020 (10 months)
 Top product categories (2020) and their evolution
Statistics – 2020 (10 months)
 Products uploaded to CC Portal vs products only in CB websites
Statistics – 2020 (10 months)
2020 Statistics Report. Is the industry surviving to lockdown?
 Number of certifications
in the last 5 years
 Will 2020 be the worst
year of the last five?
Statistics – 5 years trend
 Compliance with EAL or PP of certified products (5 year)
Statistics – 5 years trend
 High vs Low assurance in five years
Statistics – 5 year trend
 Certifications per country scheme in the last 5 years
Statistics – 5 year trend
Statistics – 5 year trend
Top-certifier countries (6th to 10th)
 Evolution of top 5 laboratories
Statistics – 5 year trend
 Evolution of top product categories (five years)
Statistics – 5 year trend
 Product publication: commoncriteriaportal.org vs CBs sites
Statistics – 5 year trend
2020 Statistics Report. Is the industry surviving to lockdown?
 Number of certifications per country, historical (archived included)
Statistics – Historical Trends
 Number of certifications per year
Statistics – Historical Trends
INITIAL GROWING
TRENDS (until 2007)
Stabilization
2008-2010
Sustained growth
2011-2016
Decay?
2017-2020
 Technological terms found in Security Targets
Statistics – Historical Trends
2020 Statistics Report. Is the industry surviving to lockdown?
Conclusions for 2020
 PP compliant certifications and High-assurance certifications (EAL5+EAL4)
predominated. EAL5 slightly > than EAL5 in 2020.
 2020 brought new winners to the scene:
 A new top vendor
 A new top evaluation lab
 A new top certifying scheme in the top-3
 CPP_ND was the most used CPP; PP084 was the most used regular PP.
 ICs & Smartcards were the most certified category, followed by Network Devices.
Has the lockdown affected the industry?
 2020 currently has less certifications than 2016, 2017, 2018 an 2019. And
65 certifications below 2019.
 The top certifying schemes lowered their number of certifications, except
Netherlands.
 Most of the top certification laboratories certified significatively less
products in 2020.
Has the lockdown affected the industry?
 No noticeable variations between Q1, and Q2-Q3 of 2020 (when lockdown).
 Unfortunately, we don’t collect data about products under evaluation and:
 Usually the whole CC process until certification takes between 6 and 12 months.
 EAL4 and higher require a site audit, the lockdown possibly delayed them.
 We think that many evaluations were started in 2019: labs and certifiers tried not
to stop them due to lockdown and we saw numbers in 2020 related to those
certifications.
 In our opinion, the COVID could have delayed evaluations starting in 2020.
 Hence, we expect the same decreasing trend in 2021… with worst numbers?
jtsec: Beyond IT Security
Granada & Madrid – Spain
hello@jtsec.es
@jtsecES
www.jtsec.es
Contact
“Any fool can make something complicated. It takes a
genius to make it simple.”
Woody Guthrie
1 of 38

Recommended

Spanish catalogue of qualified products - a new way of using CC for procurement by
Spanish catalogue of qualified products - a new way of using CC for procurementSpanish catalogue of qualified products - a new way of using CC for procurement
Spanish catalogue of qualified products - a new way of using CC for procurementJavier Tallón
362 views37 slides
Bolt IoT Platform: How to build IoT products and prototypes easily. by
Bolt IoT Platform: How to build IoT products and prototypes easily.Bolt IoT Platform: How to build IoT products and prototypes easily.
Bolt IoT Platform: How to build IoT products and prototypes easily.Pranav Pai Vernekar
3.3K views11 slides
IEA DSM ExCo presentation Task XXIV by
IEA DSM ExCo presentation Task XXIVIEA DSM ExCo presentation Task XXIV
IEA DSM ExCo presentation Task XXIVSEA - Sustainable Energy Advice Ltd
1.1K views19 slides
apidays LIVE Paris 2021 - Reference Guide for Sustainable IT, What’s in & How... by
apidays LIVE Paris 2021 - Reference Guide for Sustainable IT, What’s in & How...apidays LIVE Paris 2021 - Reference Guide for Sustainable IT, What’s in & How...
apidays LIVE Paris 2021 - Reference Guide for Sustainable IT, What’s in & How...apidays
321 views28 slides
Bio-Graphy pitch by
Bio-Graphy pitchBio-Graphy pitch
Bio-Graphy pitchpolotecnologicopv
180 views11 slides
Projects to Impact- Operationalizing Work from the Center by
Projects to Impact- Operationalizing Work from the CenterProjects to Impact- Operationalizing Work from the Center
Projects to Impact- Operationalizing Work from the CenterMITRE ATT&CK
630 views16 slides

More Related Content

What's hot

Vicinity glo tsummit yajuan guan by
Vicinity glo tsummit yajuan guanVicinity glo tsummit yajuan guan
Vicinity glo tsummit yajuan guanJuan C. Vasquez
1.9K views43 slides
[Webinar] Why Security Certification is Crucial for IoT Success by
[Webinar] Why Security Certification is Crucial for IoT Success[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT SuccessElectric Imp
1K views35 slides
Open Source IoT- Timm McShane by
Open Source IoT- Timm McShaneOpen Source IoT- Timm McShane
Open Source IoT- Timm McShaneInman News
74 views50 slides
Developing Enterprise-Level IoT Solutions by Fariz Saracevic by
Developing Enterprise-Level IoT Solutions by Fariz SaracevicDeveloping Enterprise-Level IoT Solutions by Fariz Saracevic
Developing Enterprise-Level IoT Solutions by Fariz SaracevicBosnia Agile
208 views11 slides
Reliable Engineering for Insurance by
Reliable Engineering for InsuranceReliable Engineering for Insurance
Reliable Engineering for InsuranceFortifier. IT Company
97 views9 slides
Fundamental Best Practices in Secure IoT Product Development by
Fundamental Best Practices in Secure IoT Product DevelopmentFundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product DevelopmentMark Szewczul, CISSP
116 views49 slides

What's hot(20)

[Webinar] Why Security Certification is Crucial for IoT Success by Electric Imp
[Webinar] Why Security Certification is Crucial for IoT Success[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success
Electric Imp1K views
Open Source IoT- Timm McShane by Inman News
Open Source IoT- Timm McShaneOpen Source IoT- Timm McShane
Open Source IoT- Timm McShane
Inman News74 views
Developing Enterprise-Level IoT Solutions by Fariz Saracevic by Bosnia Agile
Developing Enterprise-Level IoT Solutions by Fariz SaracevicDeveloping Enterprise-Level IoT Solutions by Fariz Saracevic
Developing Enterprise-Level IoT Solutions by Fariz Saracevic
Bosnia Agile208 views
Fundamental Best Practices in Secure IoT Product Development by Mark Szewczul, CISSP
Fundamental Best Practices in Secure IoT Product DevelopmentFundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product Development
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp... by Bosnia Agile
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Bosnia Agile720 views
InfoStretch & Peloton - Putting IoT to work by Infostretch
InfoStretch & Peloton - Putting IoT to workInfoStretch & Peloton - Putting IoT to work
InfoStretch & Peloton - Putting IoT to work
Infostretch490 views
IoT Developer Survey 2017 by Eclipse IoT
IoT Developer Survey 2017IoT Developer Survey 2017
IoT Developer Survey 2017
Eclipse IoT 735 views
Digital Security by Design Vision by KTN
Digital Security by Design VisionDigital Security by Design Vision
Digital Security by Design Vision
KTN171 views
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi... by apidays
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays251 views
call for papers - International Conference on Networks & IOT (NeTIOT 2020) by ijassn
call for papers - International Conference on Networks & IOT (NeTIOT 2020)call for papers - International Conference on Networks & IOT (NeTIOT 2020)
call for papers - International Conference on Networks & IOT (NeTIOT 2020)
ijassn7 views
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets by ATMOSPHERE .
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsSemantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
ATMOSPHERE .96 views
Integrators list brochure1 by Jo Thorgen
Integrators list brochure1Integrators list brochure1
Integrators list brochure1
Jo Thorgen149 views
Open source IoT by IoT613
Open source IoTOpen source IoT
Open source IoT
IoT613357 views
Security Research Day Summary of Input by IoTUK
Security Research Day Summary of InputSecurity Research Day Summary of Input
Security Research Day Summary of Input
IoTUK231 views
IoT Developer Survey 2016 by Eclipse IoT
IoT Developer Survey 2016IoT Developer Survey 2016
IoT Developer Survey 2016
Eclipse IoT 858 views
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets by ATMOSPHERE .
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsSemantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
ATMOSPHERE .50 views

Similar to 2020 Statistics Report. Is the industry surviving to lockdown?

2022 CC Statistics report: will this year beat last year's record number of c... by
2022 CC Statistics report: will this year beat last year's record number of c...2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...Javier Tallón
58 views30 slides
ICCC2023 Statistics Report, has Common Criteria reached its peak? by
ICCC2023 Statistics Report, has Common Criteria reached its peak?ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?Javier Tallón
27 views29 slides
ICCC21 2021 statistics report by
ICCC21 2021 statistics reportICCC21 2021 statistics report
ICCC21 2021 statistics reportJavier Tallón
71 views35 slides
CAW Newsletter Including ISO & Legislation Updates by
CAW Newsletter Including ISO & Legislation Updates CAW Newsletter Including ISO & Legislation Updates
CAW Newsletter Including ISO & Legislation Updates Craig Willetts ISO Expert
665 views12 slides
Ip Action Plan by
Ip Action PlanIp Action Plan
Ip Action Plangiri77
642 views28 slides
The State of Open Source for Software Alliance Germany 2023-04-14 by
The State of Open Source for Software Alliance Germany 2023-04-14The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14Shane Coughlan
59 views26 slides

Similar to 2020 Statistics Report. Is the industry surviving to lockdown?(20)

2022 CC Statistics report: will this year beat last year's record number of c... by Javier Tallón
2022 CC Statistics report: will this year beat last year's record number of c...2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...
Javier Tallón58 views
ICCC2023 Statistics Report, has Common Criteria reached its peak? by Javier Tallón
ICCC2023 Statistics Report, has Common Criteria reached its peak?ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?
Javier Tallón27 views
Ip Action Plan by giri77
Ip Action PlanIp Action Plan
Ip Action Plan
giri77642 views
The State of Open Source for Software Alliance Germany 2023-04-14 by Shane Coughlan
The State of Open Source for Software Alliance Germany 2023-04-14The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14
Shane Coughlan59 views
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success by Harold van Heeringen
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization successISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
ODSC May 2019 - The DataOps Manifesto by DataKitchen
ODSC May 2019 - The DataOps ManifestoODSC May 2019 - The DataOps Manifesto
ODSC May 2019 - The DataOps Manifesto
DataKitchen1.8K views
Assocham global conference audit data standards - 28.10.2020 by Vinod Kashyap
Assocham global conference   audit data standards - 28.10.2020Assocham global conference   audit data standards - 28.10.2020
Assocham global conference audit data standards - 28.10.2020
Vinod Kashyap105 views
The programmable RegTech Eco System by Liv Apneseth Watson by Workiva
The programmable RegTech Eco System by Liv Apneseth WatsonThe programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth Watson
Workiva572 views
Smart Health Devices looking for distribution partners by John Niz
Smart Health Devices looking for distribution partnersSmart Health Devices looking for distribution partners
Smart Health Devices looking for distribution partners
John Niz313 views
Charles Farina - Analytics Pros (All Things Data 2015) by Shuki Mann
Charles Farina - Analytics Pros (All Things Data 2015)Charles Farina - Analytics Pros (All Things Data 2015)
Charles Farina - Analytics Pros (All Things Data 2015)
Shuki Mann611 views
Cross Device Measurement - All Things Data Conference by Charles Farina
Cross Device Measurement - All Things Data ConferenceCross Device Measurement - All Things Data Conference
Cross Device Measurement - All Things Data Conference
Charles Farina554 views
IoT digital disruption and new IoT business models by IoTAnalytics
IoT digital disruption and new IoT business modelsIoT digital disruption and new IoT business models
IoT digital disruption and new IoT business models
IoTAnalytics1.3K views

More from Javier Tallón

ICCC23 -The new cryptographic evaluation methodology created by CCN by
ICCC23 -The new cryptographic evaluation methodology created by CCNICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCNJavier Tallón
5 views44 slides
Experiences evaluating cloud services and products by
Experiences evaluating cloud services and productsExperiences evaluating cloud services and products
Experiences evaluating cloud services and productsJavier Tallón
10 views26 slides
TAICS - Cybersecurity Certification for European Market.pptx by
TAICS - Cybersecurity Certification for European Market.pptxTAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptxJavier Tallón
74 views31 slides
La ventaja de implementar una solución de ciberseguridad certificada por el C... by
La ventaja de implementar una solución de ciberseguridad certificada por el C...La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...Javier Tallón
9 views24 slides
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf by
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfEUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfJavier Tallón
14 views41 slides
Hacking your jeta.pdf by
Hacking your jeta.pdfHacking your jeta.pdf
Hacking your jeta.pdfJavier Tallón
13 views43 slides

More from Javier Tallón(20)

ICCC23 -The new cryptographic evaluation methodology created by CCN by Javier Tallón
ICCC23 -The new cryptographic evaluation methodology created by CCNICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCN
Javier Tallón5 views
Experiences evaluating cloud services and products by Javier Tallón
Experiences evaluating cloud services and productsExperiences evaluating cloud services and products
Experiences evaluating cloud services and products
Javier Tallón10 views
TAICS - Cybersecurity Certification for European Market.pptx by Javier Tallón
TAICS - Cybersecurity Certification for European Market.pptxTAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptx
Javier Tallón74 views
La ventaja de implementar una solución de ciberseguridad certificada por el C... by Javier Tallón
La ventaja de implementar una solución de ciberseguridad certificada por el C...La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...
Javier Tallón9 views
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf by Javier Tallón
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfEUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
Javier Tallón14 views
Evolucionado la evaluación Criptográfica by Javier Tallón
Evolucionado la evaluación CriptográficaEvolucionado la evaluación Criptográfica
Evolucionado la evaluación Criptográfica
Javier Tallón22 views
España y CCN como referentes en la evaluación de ciberseguridad de soluciones... by Javier Tallón
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
Javier Tallón8 views
EUCA22 Panel Discussion: Differences between lightweight certification schemes by Javier Tallón
EUCA22 Panel Discussion: Differences between lightweight certification schemesEUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemes
Javier Tallón16 views
EUCA22 - Patch Management ISO_IEC 15408 & 18045 by Javier Tallón
EUCA22 - Patch Management ISO_IEC 15408 & 18045EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045
Javier Tallón22 views
Cross standard and scheme composition - A needed cornerstone for the European... by Javier Tallón
Cross standard and scheme composition - A needed cornerstone for the European...Cross standard and scheme composition - A needed cornerstone for the European...
Cross standard and scheme composition - A needed cornerstone for the European...
Javier Tallón16 views
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)? by Javier Tallón
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
Javier Tallón35 views
Is Automation Necessary for the CC Survival? by Javier Tallón
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?
Javier Tallón10 views
CCCAB tool - Making CABs life easy - Chapter 2 by Javier Tallón
CCCAB tool - Making CABs life easy - Chapter 2CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2
Javier Tallón10 views
CCCAB, la apuesta europea por la automatización de los Organismos de Certific... by Javier Tallón
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
Javier Tallón59 views
Automating Common Criteria by Javier Tallón
Automating Common Criteria Automating Common Criteria
Automating Common Criteria
Javier Tallón127 views
jtsec Arqus Alliance presentation by Javier Tallón
jtsec Arqus Alliance presentationjtsec Arqus Alliance presentation
jtsec Arqus Alliance presentation
Javier Tallón102 views
III Encuentro del ENS- Usando el CPSTIC/ENECSTI en la administración - Herram... by Javier Tallón
III Encuentro del ENS- Usando el CPSTIC/ENECSTI en la administración - Herram...III Encuentro del ENS- Usando el CPSTIC/ENECSTI en la administración - Herram...
III Encuentro del ENS- Usando el CPSTIC/ENECSTI en la administración - Herram...
Javier Tallón112 views
Demostrando la ciberseguridad de tus productos y sistemas mediante auditoría ... by Javier Tallón
Demostrando la ciberseguridad de tus productos y sistemas mediante auditoría ...Demostrando la ciberseguridad de tus productos y sistemas mediante auditoría ...
Demostrando la ciberseguridad de tus productos y sistemas mediante auditoría ...
Javier Tallón127 views

Recently uploaded

Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue by
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlueElevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlueShapeBlue
224 views7 slides
DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti... by
DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti...DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti...
DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti...ShapeBlue
141 views29 slides
Business Analyst Series 2023 - Week 4 Session 7 by
Business Analyst Series 2023 -  Week 4 Session 7Business Analyst Series 2023 -  Week 4 Session 7
Business Analyst Series 2023 - Week 4 Session 7DianaGray10
146 views31 slides
LLMs in Production: Tooling, Process, and Team Structure by
LLMs in Production: Tooling, Process, and Team StructureLLMs in Production: Tooling, Process, and Team Structure
LLMs in Production: Tooling, Process, and Team StructureAggregage
57 views77 slides
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT by
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITUpdates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITShapeBlue
208 views8 slides
Enabling DPU Hardware Accelerators in XCP-ng Cloud Platform Environment - And... by
Enabling DPU Hardware Accelerators in XCP-ng Cloud Platform Environment - And...Enabling DPU Hardware Accelerators in XCP-ng Cloud Platform Environment - And...
Enabling DPU Hardware Accelerators in XCP-ng Cloud Platform Environment - And...ShapeBlue
108 views12 slides

Recently uploaded(20)

Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue by ShapeBlue
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlueElevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue
ShapeBlue224 views
DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti... by ShapeBlue
DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti...DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti...
DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti...
ShapeBlue141 views
Business Analyst Series 2023 - Week 4 Session 7 by DianaGray10
Business Analyst Series 2023 -  Week 4 Session 7Business Analyst Series 2023 -  Week 4 Session 7
Business Analyst Series 2023 - Week 4 Session 7
DianaGray10146 views
LLMs in Production: Tooling, Process, and Team Structure by Aggregage
LLMs in Production: Tooling, Process, and Team StructureLLMs in Production: Tooling, Process, and Team Structure
LLMs in Production: Tooling, Process, and Team Structure
Aggregage57 views
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT by ShapeBlue
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITUpdates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
ShapeBlue208 views
Enabling DPU Hardware Accelerators in XCP-ng Cloud Platform Environment - And... by ShapeBlue
Enabling DPU Hardware Accelerators in XCP-ng Cloud Platform Environment - And...Enabling DPU Hardware Accelerators in XCP-ng Cloud Platform Environment - And...
Enabling DPU Hardware Accelerators in XCP-ng Cloud Platform Environment - And...
ShapeBlue108 views
Transcript: Redefining the book supply chain: A glimpse into the future - Tec... by BookNet Canada
Transcript: Redefining the book supply chain: A glimpse into the future - Tec...Transcript: Redefining the book supply chain: A glimpse into the future - Tec...
Transcript: Redefining the book supply chain: A glimpse into the future - Tec...
BookNet Canada41 views
Why and How CloudStack at weSystems - Stephan Bienek - weSystems by ShapeBlue
Why and How CloudStack at weSystems - Stephan Bienek - weSystemsWhy and How CloudStack at weSystems - Stephan Bienek - weSystems
Why and How CloudStack at weSystems - Stephan Bienek - weSystems
ShapeBlue247 views
The Power of Generative AI in Accelerating No Code Adoption.pdf by Saeed Al Dhaheri
The Power of Generative AI in Accelerating No Code Adoption.pdfThe Power of Generative AI in Accelerating No Code Adoption.pdf
The Power of Generative AI in Accelerating No Code Adoption.pdf
Saeed Al Dhaheri39 views
Don’t Make A Human Do A Robot’s Job! : 6 Reasons Why AI Will Save Us & Not De... by Moses Kemibaro
Don’t Make A Human Do A Robot’s Job! : 6 Reasons Why AI Will Save Us & Not De...Don’t Make A Human Do A Robot’s Job! : 6 Reasons Why AI Will Save Us & Not De...
Don’t Make A Human Do A Robot’s Job! : 6 Reasons Why AI Will Save Us & Not De...
Moses Kemibaro35 views
Business Analyst Series 2023 - Week 4 Session 8 by DianaGray10
Business Analyst Series 2023 -  Week 4 Session 8Business Analyst Series 2023 -  Week 4 Session 8
Business Analyst Series 2023 - Week 4 Session 8
DianaGray10145 views
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit... by ShapeBlue
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...
ShapeBlue162 views
"Running students' code in isolation. The hard way", Yurii Holiuk by Fwdays
"Running students' code in isolation. The hard way", Yurii Holiuk "Running students' code in isolation. The hard way", Yurii Holiuk
"Running students' code in isolation. The hard way", Yurii Holiuk
Fwdays36 views
State of the Union - Rohit Yadav - Apache CloudStack by ShapeBlue
State of the Union - Rohit Yadav - Apache CloudStackState of the Union - Rohit Yadav - Apache CloudStack
State of the Union - Rohit Yadav - Apache CloudStack
ShapeBlue303 views
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ... by ShapeBlue
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...
ShapeBlue120 views

2020 Statistics Report. Is the industry surviving to lockdown?

  • 3.  CC data collection with CCScraper  CC statistics for 2020  CC Statistics for 5 years  Some historical CC statistics  Conclusions Contents
  • 5.  Web scraper written in Python. Created in 2018 by jtsec.  CCScraper collects data about certified products from commoncriteriaportal.org and from the websites of the Certification Body.  Tons of interesting data collected: date of certification, EAL, PP, Product Category, certification lab, etc. and even SFRs used or technical terms in the ST!  Data is interpreted and organized / merged into a list of unique certified products. We generate the statistics from that data. What is CCScraper
  • 6.  CCScraper v1.0 was first presented here in the ICCC in 2018.  Only data from commoncriteriaportal.org was collected.  CCScraper v2.0 was presented in ICCC 2019.  Main feature: add information from CB websites and merge into unique products  CCScraper v2.1 presented today in ICCC 2020.  Efficiency dramatically improved: 18 hours vs 5 days of execution.  Nothing is perfect… so we implemented logging and email alert logic in case we find errors / uncontemplated cases. CCScraper history
  • 7.  New laboratories found!… we had to review our parsing logic and reports!  CSEC website changed it structure during this year: we had to re-code its scraper.  NSCIB started to upload Site Security Certifications and dates were removed from the product listing.  The scraper run an OK test in September but… in November the Australian CB ACSC website had entirely changed! Latest challenges for CCScraper
  • 8.  With the statistics generated, we publish CC statistics reports in jtsec webpage, at least once per year. CCscraper reports  https://www.jtsec.es/blog-entry/25/common-criteria- statistics-report-for-2018  https://www.jtsec.es/blog-entry/44/common-criteria- statistics-report-for-2019
  • 10. Statistics – 2020 (10 months)  315 products certified during 2020 (data from 05/11/2020)
  • 11.  Top certifier schemes in 2020 Statistics – 2020 (10 months)
  • 12. Statistics – 2020 (10 months)  The top 3 schemes add up to 55% of the certifications!
  • 13.  Certified products compliance in 2020 Statistics – 2020 (10 months)
  • 14.  Product assurance level per country during 2020 Statistics – 2020 (10 months)
  • 15.  Top 10 Laboratories (2020) Statistics – 2020 (10 months)
  • 16. Statistics – 2020 (10 months)  Protection Profile certifications
  • 17. Statistics – 2020 (10 months)  PP and cPP compliant certifications in 2020
  • 18.  Top 5 manufacturers of certified products (2020) Statistics – 2020 (10 months)
  • 19.  Top product categories (2020) and their evolution Statistics – 2020 (10 months)
  • 20.  Products uploaded to CC Portal vs products only in CB websites Statistics – 2020 (10 months)
  • 22.  Number of certifications in the last 5 years  Will 2020 be the worst year of the last five? Statistics – 5 years trend
  • 23.  Compliance with EAL or PP of certified products (5 year) Statistics – 5 years trend
  • 24.  High vs Low assurance in five years Statistics – 5 year trend
  • 25.  Certifications per country scheme in the last 5 years Statistics – 5 year trend
  • 26. Statistics – 5 year trend Top-certifier countries (6th to 10th)
  • 27.  Evolution of top 5 laboratories Statistics – 5 year trend
  • 28.  Evolution of top product categories (five years) Statistics – 5 year trend
  • 29.  Product publication: commoncriteriaportal.org vs CBs sites Statistics – 5 year trend
  • 31.  Number of certifications per country, historical (archived included) Statistics – Historical Trends
  • 32.  Number of certifications per year Statistics – Historical Trends INITIAL GROWING TRENDS (until 2007) Stabilization 2008-2010 Sustained growth 2011-2016 Decay? 2017-2020
  • 33.  Technological terms found in Security Targets Statistics – Historical Trends
  • 35. Conclusions for 2020  PP compliant certifications and High-assurance certifications (EAL5+EAL4) predominated. EAL5 slightly > than EAL5 in 2020.  2020 brought new winners to the scene:  A new top vendor  A new top evaluation lab  A new top certifying scheme in the top-3  CPP_ND was the most used CPP; PP084 was the most used regular PP.  ICs & Smartcards were the most certified category, followed by Network Devices.
  • 36. Has the lockdown affected the industry?  2020 currently has less certifications than 2016, 2017, 2018 an 2019. And 65 certifications below 2019.  The top certifying schemes lowered their number of certifications, except Netherlands.  Most of the top certification laboratories certified significatively less products in 2020.
  • 37. Has the lockdown affected the industry?  No noticeable variations between Q1, and Q2-Q3 of 2020 (when lockdown).  Unfortunately, we don’t collect data about products under evaluation and:  Usually the whole CC process until certification takes between 6 and 12 months.  EAL4 and higher require a site audit, the lockdown possibly delayed them.  We think that many evaluations were started in 2019: labs and certifiers tried not to stop them due to lockdown and we saw numbers in 2020 related to those certifications.  In our opinion, the COVID could have delayed evaluations starting in 2020.  Hence, we expect the same decreasing trend in 2021… with worst numbers?
  • 38. jtsec: Beyond IT Security Granada & Madrid – Spain hello@jtsec.es @jtsecES www.jtsec.es Contact “Any fool can make something complicated. It takes a genius to make it simple.” Woody Guthrie