SlideShare a Scribd company logo
 CC data collection with CCScraper
 CC statistics for 2020
 CC Statistics for 5 years
 Some historical CC statistics
 Conclusions
Contents
 Web scraper written in Python. Created in 2018 by jtsec.
 CCScraper collects data about certified products from commoncriteriaportal.org
and from the websites of the Certification Body.
 Tons of interesting data collected: date of certification, EAL, PP, Product
Category, certification lab, etc. and even SFRs used or technical terms in the ST!
 Data is interpreted and organized / merged into a list of unique certified
products. We generate the statistics from that data.
What is CCScraper
 CCScraper v1.0 was first presented here in the ICCC in 2018.
 Only data from commoncriteriaportal.org was collected.
 CCScraper v2.0 was presented in ICCC 2019.
 Main feature: add information from CB websites and merge into
unique products
 CCScraper v2.1 presented today in ICCC 2020.
 Efficiency dramatically improved: 18 hours vs 5 days of execution.
 Nothing is perfect… so we implemented logging and email alert logic in
case we find errors / uncontemplated cases.
CCScraper history
 New laboratories found!… we had to review our parsing logic and reports!
 CSEC website changed it structure during this year: we had to re-code its
scraper.
 NSCIB started to upload Site Security Certifications and dates were
removed from the product listing.
 The scraper run an OK test in September but… in November the Australian
CB ACSC website had entirely changed!
Latest challenges for CCScraper
 With the statistics generated, we publish CC statistics reports in jtsec
webpage, at least once per year.
CCscraper reports
 https://www.jtsec.es/blog-entry/25/common-criteria-
statistics-report-for-2018
 https://www.jtsec.es/blog-entry/44/common-criteria-
statistics-report-for-2019
Statistics – 2020 (10 months)
 315 products certified during 2020 (data from 05/11/2020)
 Top certifier schemes in 2020
Statistics – 2020 (10 months)
Statistics – 2020 (10 months)
 The top 3 schemes add up to 55% of the certifications!
 Certified products compliance in 2020
Statistics – 2020 (10 months)
 Product assurance level per country during 2020
Statistics – 2020 (10 months)
 Top 10 Laboratories (2020)
Statistics – 2020 (10 months)
Statistics – 2020 (10 months)
 Protection Profile certifications
Statistics – 2020 (10 months)
 PP and cPP compliant certifications in 2020
 Top 5 manufacturers of certified products (2020)
Statistics – 2020 (10 months)
 Top product categories (2020) and their evolution
Statistics – 2020 (10 months)
 Products uploaded to CC Portal vs products only in CB websites
Statistics – 2020 (10 months)
 Number of certifications
in the last 5 years
 Will 2020 be the worst
year of the last five?
Statistics – 5 years trend
 Compliance with EAL or PP of certified products (5 year)
Statistics – 5 years trend
 High vs Low assurance in five years
Statistics – 5 year trend
 Certifications per country scheme in the last 5 years
Statistics – 5 year trend
Statistics – 5 year trend
Top-certifier countries (6th to 10th)
 Evolution of top 5 laboratories
Statistics – 5 year trend
 Evolution of top product categories (five years)
Statistics – 5 year trend
 Product publication: commoncriteriaportal.org vs CBs sites
Statistics – 5 year trend
 Number of certifications per country, historical (archived included)
Statistics – Historical Trends
 Number of certifications per year
Statistics – Historical Trends
INITIAL GROWING
TRENDS (until 2007)
Stabilization
2008-2010
Sustained growth
2011-2016
Decay?
2017-2020
 Technological terms found in Security Targets
Statistics – Historical Trends
Conclusions for 2020
 PP compliant certifications and High-assurance certifications (EAL5+EAL4)
predominated. EAL5 slightly > than EAL5 in 2020.
 2020 brought new winners to the scene:
 A new top vendor
 A new top evaluation lab
 A new top certifying scheme in the top-3
 CPP_ND was the most used CPP; PP084 was the most used regular PP.
 ICs & Smartcards were the most certified category, followed by Network Devices.
Has the lockdown affected the industry?
 2020 currently has less certifications than 2016, 2017, 2018 an 2019. And
65 certifications below 2019.
 The top certifying schemes lowered their number of certifications, except
Netherlands.
 Most of the top certification laboratories certified significatively less
products in 2020.
Has the lockdown affected the industry?
 No noticeable variations between Q1, and Q2-Q3 of 2020 (when lockdown).
 Unfortunately, we don’t collect data about products under evaluation and:
 Usually the whole CC process until certification takes between 6 and 12 months.
 EAL4 and higher require a site audit, the lockdown possibly delayed them.
 We think that many evaluations were started in 2019: labs and certifiers tried not
to stop them due to lockdown and we saw numbers in 2020 related to those
certifications.
 In our opinion, the COVID could have delayed evaluations starting in 2020.
 Hence, we expect the same decreasing trend in 2021… with worst numbers?
jtsec: Beyond IT Security
Granada & Madrid – Spain
hello@jtsec.es
@jtsecES
www.jtsec.es
Contact
“Any fool can make something complicated. It takes a
genius to make it simple.”
Woody Guthrie

More Related Content

What's hot

Vicinity glo tsummit yajuan guan
Vicinity glo tsummit yajuan guanVicinity glo tsummit yajuan guan
Vicinity glo tsummit yajuan guan
Juan C. Vasquez
 
[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success
Electric Imp
 
Open Source IoT- Timm McShane
Open Source IoT- Timm McShaneOpen Source IoT- Timm McShane
Open Source IoT- Timm McShane
Inman News
 
Developing Enterprise-Level IoT Solutions by Fariz Saracevic
Developing Enterprise-Level IoT Solutions by Fariz SaracevicDeveloping Enterprise-Level IoT Solutions by Fariz Saracevic
Developing Enterprise-Level IoT Solutions by Fariz Saracevic
Bosnia Agile
 
Reliable Engineering for Insurance
Reliable Engineering for InsuranceReliable Engineering for Insurance
Reliable Engineering for Insurance
Fortifier. IT Company
 
Fundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product DevelopmentFundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product Development
Mark Szewczul, CISSP
 
Quality 4.0 and reimagining quality
Quality 4.0 and reimagining qualityQuality 4.0 and reimagining quality
Quality 4.0 and reimagining quality
Dr. Anish Cheriyan (PhD)
 
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Bosnia Agile
 
InfoStretch & Peloton - Putting IoT to work
InfoStretch & Peloton - Putting IoT to workInfoStretch & Peloton - Putting IoT to work
InfoStretch & Peloton - Putting IoT to work
Infostretch
 
IoT Developer Survey 2017
IoT Developer Survey 2017IoT Developer Survey 2017
IoT Developer Survey 2017
Eclipse IoT
 
Digital Security by Design Vision
Digital Security by Design VisionDigital Security by Design Vision
Digital Security by Design Vision
KTN
 
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays
 
Pitch Deck
Pitch DeckPitch Deck
Pitch Deck
Pete Wassell
 
call for papers - International Conference on Networks & IOT (NeTIOT 2020)
call for papers - International Conference on Networks & IOT (NeTIOT 2020)call for papers - International Conference on Networks & IOT (NeTIOT 2020)
call for papers - International Conference on Networks & IOT (NeTIOT 2020)
ijassn
 
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsSemantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
ATMOSPHERE .
 
Integrators list brochure1
Integrators list brochure1Integrators list brochure1
Integrators list brochure1
Jo Thorgen
 
Open source IoT
Open source IoTOpen source IoT
Open source IoT
IoT613
 
Security Research Day Summary of Input
Security Research Day Summary of InputSecurity Research Day Summary of Input
Security Research Day Summary of Input
IoTUK
 
IoT Developer Survey 2016
IoT Developer Survey 2016IoT Developer Survey 2016
IoT Developer Survey 2016
Eclipse IoT
 
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsSemantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
ATMOSPHERE .
 

What's hot (20)

Vicinity glo tsummit yajuan guan
Vicinity glo tsummit yajuan guanVicinity glo tsummit yajuan guan
Vicinity glo tsummit yajuan guan
 
[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success
 
Open Source IoT- Timm McShane
Open Source IoT- Timm McShaneOpen Source IoT- Timm McShane
Open Source IoT- Timm McShane
 
Developing Enterprise-Level IoT Solutions by Fariz Saracevic
Developing Enterprise-Level IoT Solutions by Fariz SaracevicDeveloping Enterprise-Level IoT Solutions by Fariz Saracevic
Developing Enterprise-Level IoT Solutions by Fariz Saracevic
 
Reliable Engineering for Insurance
Reliable Engineering for InsuranceReliable Engineering for Insurance
Reliable Engineering for Insurance
 
Fundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product DevelopmentFundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product Development
 
Quality 4.0 and reimagining quality
Quality 4.0 and reimagining qualityQuality 4.0 and reimagining quality
Quality 4.0 and reimagining quality
 
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
 
InfoStretch & Peloton - Putting IoT to work
InfoStretch & Peloton - Putting IoT to workInfoStretch & Peloton - Putting IoT to work
InfoStretch & Peloton - Putting IoT to work
 
IoT Developer Survey 2017
IoT Developer Survey 2017IoT Developer Survey 2017
IoT Developer Survey 2017
 
Digital Security by Design Vision
Digital Security by Design VisionDigital Security by Design Vision
Digital Security by Design Vision
 
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
 
Pitch Deck
Pitch DeckPitch Deck
Pitch Deck
 
call for papers - International Conference on Networks & IOT (NeTIOT 2020)
call for papers - International Conference on Networks & IOT (NeTIOT 2020)call for papers - International Conference on Networks & IOT (NeTIOT 2020)
call for papers - International Conference on Networks & IOT (NeTIOT 2020)
 
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsSemantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
 
Integrators list brochure1
Integrators list brochure1Integrators list brochure1
Integrators list brochure1
 
Open source IoT
Open source IoTOpen source IoT
Open source IoT
 
Security Research Day Summary of Input
Security Research Day Summary of InputSecurity Research Day Summary of Input
Security Research Day Summary of Input
 
IoT Developer Survey 2016
IoT Developer Survey 2016IoT Developer Survey 2016
IoT Developer Survey 2016
 
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsSemantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
 

Similar to 2020 Statistics Report. Is the industry surviving to lockdown?

2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...
Javier Tallón
 
ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?
Javier Tallón
 
ICCC21 2021 statistics report
ICCC21 2021 statistics reportICCC21 2021 statistics report
ICCC21 2021 statistics report
Javier Tallón
 
CAW Newsletter Including ISO & Legislation Updates
CAW Newsletter Including ISO & Legislation Updates CAW Newsletter Including ISO & Legislation Updates
CAW Newsletter Including ISO & Legislation Updates
Craig Willetts ISO Expert
 
Ip Action Plan
Ip Action PlanIp Action Plan
Ip Action Plan
giri77
 
The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14
Shane Coughlan
 
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization successISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
Harold van Heeringen
 
ODSC May 2019 - The DataOps Manifesto
ODSC May 2019 - The DataOps ManifestoODSC May 2019 - The DataOps Manifesto
ODSC May 2019 - The DataOps Manifesto
DataKitchen
 
2023-06-classic
2023-06-classic2023-06-classic
2023-06-classic
Shane Coughlan
 
2023-06-cute
2023-06-cute2023-06-cute
2023-06-cute
Shane Coughlan
 
Assocham global conference audit data standards - 28.10.2020
Assocham global conference   audit data standards - 28.10.2020Assocham global conference   audit data standards - 28.10.2020
Assocham global conference audit data standards - 28.10.2020
Vinod Kashyap
 
INGENIUS_XIMB_Iron and Steel
INGENIUS_XIMB_Iron and SteelINGENIUS_XIMB_Iron and Steel
INGENIUS_XIMB_Iron and Steel
Chetan Anand Aulla
 
2023-06-corporate
2023-06-corporate2023-06-corporate
2023-06-corporate
Shane Coughlan
 
The programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth WatsonThe programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth Watson
Workiva
 
Simmethod growth and value creation sales index
Simmethod growth and value creation sales indexSimmethod growth and value creation sales index
Simmethod growth and value creation sales index
SIMMETHOD: Converting Information Into Assets
 
Smart Health Devices looking for distribution partners
Smart Health Devices looking for distribution partnersSmart Health Devices looking for distribution partners
Smart Health Devices looking for distribution partners
John Niz
 
Performance Measurement and Management in Industry 4.0
Performance Measurement and Management in Industry 4.0Performance Measurement and Management in Industry 4.0
Performance Measurement and Management in Industry 4.0
CAREL Industries S.p.A
 
Charles Farina - Analytics Pros (All Things Data 2015)
Charles Farina - Analytics Pros (All Things Data 2015)Charles Farina - Analytics Pros (All Things Data 2015)
Charles Farina - Analytics Pros (All Things Data 2015)
Shuki Mann
 
Cross Device Measurement - All Things Data Conference
Cross Device Measurement - All Things Data ConferenceCross Device Measurement - All Things Data Conference
Cross Device Measurement - All Things Data Conference
Charles Farina
 
IoT digital disruption and new IoT business models
IoT digital disruption and new IoT business modelsIoT digital disruption and new IoT business models
IoT digital disruption and new IoT business models
IoTAnalytics
 

Similar to 2020 Statistics Report. Is the industry surviving to lockdown? (20)

2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...
 
ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?
 
ICCC21 2021 statistics report
ICCC21 2021 statistics reportICCC21 2021 statistics report
ICCC21 2021 statistics report
 
CAW Newsletter Including ISO & Legislation Updates
CAW Newsletter Including ISO & Legislation Updates CAW Newsletter Including ISO & Legislation Updates
CAW Newsletter Including ISO & Legislation Updates
 
Ip Action Plan
Ip Action PlanIp Action Plan
Ip Action Plan
 
The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14
 
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization successISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
 
ODSC May 2019 - The DataOps Manifesto
ODSC May 2019 - The DataOps ManifestoODSC May 2019 - The DataOps Manifesto
ODSC May 2019 - The DataOps Manifesto
 
2023-06-classic
2023-06-classic2023-06-classic
2023-06-classic
 
2023-06-cute
2023-06-cute2023-06-cute
2023-06-cute
 
Assocham global conference audit data standards - 28.10.2020
Assocham global conference   audit data standards - 28.10.2020Assocham global conference   audit data standards - 28.10.2020
Assocham global conference audit data standards - 28.10.2020
 
INGENIUS_XIMB_Iron and Steel
INGENIUS_XIMB_Iron and SteelINGENIUS_XIMB_Iron and Steel
INGENIUS_XIMB_Iron and Steel
 
2023-06-corporate
2023-06-corporate2023-06-corporate
2023-06-corporate
 
The programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth WatsonThe programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth Watson
 
Simmethod growth and value creation sales index
Simmethod growth and value creation sales indexSimmethod growth and value creation sales index
Simmethod growth and value creation sales index
 
Smart Health Devices looking for distribution partners
Smart Health Devices looking for distribution partnersSmart Health Devices looking for distribution partners
Smart Health Devices looking for distribution partners
 
Performance Measurement and Management in Industry 4.0
Performance Measurement and Management in Industry 4.0Performance Measurement and Management in Industry 4.0
Performance Measurement and Management in Industry 4.0
 
Charles Farina - Analytics Pros (All Things Data 2015)
Charles Farina - Analytics Pros (All Things Data 2015)Charles Farina - Analytics Pros (All Things Data 2015)
Charles Farina - Analytics Pros (All Things Data 2015)
 
Cross Device Measurement - All Things Data Conference
Cross Device Measurement - All Things Data ConferenceCross Device Measurement - All Things Data Conference
Cross Device Measurement - All Things Data Conference
 
IoT digital disruption and new IoT business models
IoT digital disruption and new IoT business modelsIoT digital disruption and new IoT business models
IoT digital disruption and new IoT business models
 

More from Javier Tallón

Evolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio IIEvolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio II
Javier Tallón
 
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Javier Tallón
 
ICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCNICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCN
Javier Tallón
 
Experiences evaluating cloud services and products
Experiences evaluating cloud services and productsExperiences evaluating cloud services and products
Experiences evaluating cloud services and products
Javier Tallón
 
TAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptxTAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptx
Javier Tallón
 
La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...
Javier Tallón
 
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfEUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
Javier Tallón
 
Hacking your jeta.pdf
Hacking your jeta.pdfHacking your jeta.pdf
Hacking your jeta.pdf
Javier Tallón
 
Evolucionado la evaluación Criptográfica
Evolucionado la evaluación CriptográficaEvolucionado la evaluación Criptográfica
Evolucionado la evaluación Criptográfica
Javier Tallón
 
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
Javier Tallón
 
EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896
Javier Tallón
 
EUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemesEUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemes
Javier Tallón
 
EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045
Javier Tallón
 
Cross standard and scheme composition - A needed cornerstone for the European...
Cross standard and scheme composition - A needed cornerstone for the European...Cross standard and scheme composition - A needed cornerstone for the European...
Cross standard and scheme composition - A needed cornerstone for the European...
Javier Tallón
 
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
Javier Tallón
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?
Javier Tallón
 
CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2
Javier Tallón
 
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
Javier Tallón
 
Automating Common Criteria
Automating Common Criteria Automating Common Criteria
Automating Common Criteria
Javier Tallón
 
CCCAB - Making CABs life easy
CCCAB -  Making CABs life easyCCCAB -  Making CABs life easy
CCCAB - Making CABs life easy
Javier Tallón
 

More from Javier Tallón (20)

Evolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio IIEvolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio II
 
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
 
ICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCNICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCN
 
Experiences evaluating cloud services and products
Experiences evaluating cloud services and productsExperiences evaluating cloud services and products
Experiences evaluating cloud services and products
 
TAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptxTAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptx
 
La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...
 
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfEUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
 
Hacking your jeta.pdf
Hacking your jeta.pdfHacking your jeta.pdf
Hacking your jeta.pdf
 
Evolucionado la evaluación Criptográfica
Evolucionado la evaluación CriptográficaEvolucionado la evaluación Criptográfica
Evolucionado la evaluación Criptográfica
 
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
 
EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896
 
EUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemesEUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemes
 
EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045
 
Cross standard and scheme composition - A needed cornerstone for the European...
Cross standard and scheme composition - A needed cornerstone for the European...Cross standard and scheme composition - A needed cornerstone for the European...
Cross standard and scheme composition - A needed cornerstone for the European...
 
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?
 
CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2
 
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
 
Automating Common Criteria
Automating Common Criteria Automating Common Criteria
Automating Common Criteria
 
CCCAB - Making CABs life easy
CCCAB -  Making CABs life easyCCCAB -  Making CABs life easy
CCCAB - Making CABs life easy
 

Recently uploaded

Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
Zilliz
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
panagenda
 
Recommendation System using RAG Architecture
Recommendation System using RAG ArchitectureRecommendation System using RAG Architecture
Recommendation System using RAG Architecture
fredae14
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 
TrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy SurveyTrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy Survey
TrustArc
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
Zilliz
 
5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides
DanBrown980551
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
tolgahangng
 
Project Management Semester Long Project - Acuity
Project Management Semester Long Project - AcuityProject Management Semester Long Project - Acuity
Project Management Semester Long Project - Acuity
jpupo2018
 
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
名前 です男
 
Choosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptxChoosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptx
Brandon Minnick, MBA
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
akankshawande
 
OpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - AuthorizationOpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - Authorization
David Brossard
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
Jason Packer
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
Tatiana Kojar
 
Ocean lotus Threat actors project by John Sitima 2024 (1).pptx
Ocean lotus Threat actors project by John Sitima 2024 (1).pptxOcean lotus Threat actors project by John Sitima 2024 (1).pptx
Ocean lotus Threat actors project by John Sitima 2024 (1).pptx
SitimaJohn
 
How to Get CNIC Information System with Paksim Ga.pptx
How to Get CNIC Information System with Paksim Ga.pptxHow to Get CNIC Information System with Paksim Ga.pptx
How to Get CNIC Information System with Paksim Ga.pptx
danishmna97
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
kumardaparthi1024
 
Digital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying AheadDigital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying Ahead
Wask
 
Taking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdfTaking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdf
ssuserfac0301
 

Recently uploaded (20)

Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
 
Recommendation System using RAG Architecture
Recommendation System using RAG ArchitectureRecommendation System using RAG Architecture
Recommendation System using RAG Architecture
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 
TrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy SurveyTrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy Survey
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
 
5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
 
Project Management Semester Long Project - Acuity
Project Management Semester Long Project - AcuityProject Management Semester Long Project - Acuity
Project Management Semester Long Project - Acuity
 
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
 
Choosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptxChoosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptx
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
 
OpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - AuthorizationOpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - Authorization
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
 
Ocean lotus Threat actors project by John Sitima 2024 (1).pptx
Ocean lotus Threat actors project by John Sitima 2024 (1).pptxOcean lotus Threat actors project by John Sitima 2024 (1).pptx
Ocean lotus Threat actors project by John Sitima 2024 (1).pptx
 
How to Get CNIC Information System with Paksim Ga.pptx
How to Get CNIC Information System with Paksim Ga.pptxHow to Get CNIC Information System with Paksim Ga.pptx
How to Get CNIC Information System with Paksim Ga.pptx
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
 
Digital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying AheadDigital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying Ahead
 
Taking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdfTaking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdf
 

2020 Statistics Report. Is the industry surviving to lockdown?

  • 1.
  • 2.
  • 3.  CC data collection with CCScraper  CC statistics for 2020  CC Statistics for 5 years  Some historical CC statistics  Conclusions Contents
  • 4.
  • 5.  Web scraper written in Python. Created in 2018 by jtsec.  CCScraper collects data about certified products from commoncriteriaportal.org and from the websites of the Certification Body.  Tons of interesting data collected: date of certification, EAL, PP, Product Category, certification lab, etc. and even SFRs used or technical terms in the ST!  Data is interpreted and organized / merged into a list of unique certified products. We generate the statistics from that data. What is CCScraper
  • 6.  CCScraper v1.0 was first presented here in the ICCC in 2018.  Only data from commoncriteriaportal.org was collected.  CCScraper v2.0 was presented in ICCC 2019.  Main feature: add information from CB websites and merge into unique products  CCScraper v2.1 presented today in ICCC 2020.  Efficiency dramatically improved: 18 hours vs 5 days of execution.  Nothing is perfect… so we implemented logging and email alert logic in case we find errors / uncontemplated cases. CCScraper history
  • 7.  New laboratories found!… we had to review our parsing logic and reports!  CSEC website changed it structure during this year: we had to re-code its scraper.  NSCIB started to upload Site Security Certifications and dates were removed from the product listing.  The scraper run an OK test in September but… in November the Australian CB ACSC website had entirely changed! Latest challenges for CCScraper
  • 8.  With the statistics generated, we publish CC statistics reports in jtsec webpage, at least once per year. CCscraper reports  https://www.jtsec.es/blog-entry/25/common-criteria- statistics-report-for-2018  https://www.jtsec.es/blog-entry/44/common-criteria- statistics-report-for-2019
  • 9.
  • 10. Statistics – 2020 (10 months)  315 products certified during 2020 (data from 05/11/2020)
  • 11.  Top certifier schemes in 2020 Statistics – 2020 (10 months)
  • 12. Statistics – 2020 (10 months)  The top 3 schemes add up to 55% of the certifications!
  • 13.  Certified products compliance in 2020 Statistics – 2020 (10 months)
  • 14.  Product assurance level per country during 2020 Statistics – 2020 (10 months)
  • 15.  Top 10 Laboratories (2020) Statistics – 2020 (10 months)
  • 16. Statistics – 2020 (10 months)  Protection Profile certifications
  • 17. Statistics – 2020 (10 months)  PP and cPP compliant certifications in 2020
  • 18.  Top 5 manufacturers of certified products (2020) Statistics – 2020 (10 months)
  • 19.  Top product categories (2020) and their evolution Statistics – 2020 (10 months)
  • 20.  Products uploaded to CC Portal vs products only in CB websites Statistics – 2020 (10 months)
  • 21.
  • 22.  Number of certifications in the last 5 years  Will 2020 be the worst year of the last five? Statistics – 5 years trend
  • 23.  Compliance with EAL or PP of certified products (5 year) Statistics – 5 years trend
  • 24.  High vs Low assurance in five years Statistics – 5 year trend
  • 25.  Certifications per country scheme in the last 5 years Statistics – 5 year trend
  • 26. Statistics – 5 year trend Top-certifier countries (6th to 10th)
  • 27.  Evolution of top 5 laboratories Statistics – 5 year trend
  • 28.  Evolution of top product categories (five years) Statistics – 5 year trend
  • 29.  Product publication: commoncriteriaportal.org vs CBs sites Statistics – 5 year trend
  • 30.
  • 31.  Number of certifications per country, historical (archived included) Statistics – Historical Trends
  • 32.  Number of certifications per year Statistics – Historical Trends INITIAL GROWING TRENDS (until 2007) Stabilization 2008-2010 Sustained growth 2011-2016 Decay? 2017-2020
  • 33.  Technological terms found in Security Targets Statistics – Historical Trends
  • 34.
  • 35. Conclusions for 2020  PP compliant certifications and High-assurance certifications (EAL5+EAL4) predominated. EAL5 slightly > than EAL5 in 2020.  2020 brought new winners to the scene:  A new top vendor  A new top evaluation lab  A new top certifying scheme in the top-3  CPP_ND was the most used CPP; PP084 was the most used regular PP.  ICs & Smartcards were the most certified category, followed by Network Devices.
  • 36. Has the lockdown affected the industry?  2020 currently has less certifications than 2016, 2017, 2018 an 2019. And 65 certifications below 2019.  The top certifying schemes lowered their number of certifications, except Netherlands.  Most of the top certification laboratories certified significatively less products in 2020.
  • 37. Has the lockdown affected the industry?  No noticeable variations between Q1, and Q2-Q3 of 2020 (when lockdown).  Unfortunately, we don’t collect data about products under evaluation and:  Usually the whole CC process until certification takes between 6 and 12 months.  EAL4 and higher require a site audit, the lockdown possibly delayed them.  We think that many evaluations were started in 2019: labs and certifiers tried not to stop them due to lockdown and we saw numbers in 2020 related to those certifications.  In our opinion, the COVID could have delayed evaluations starting in 2020.  Hence, we expect the same decreasing trend in 2021… with worst numbers?
  • 38. jtsec: Beyond IT Security Granada & Madrid – Spain hello@jtsec.es @jtsecES www.jtsec.es Contact “Any fool can make something complicated. It takes a genius to make it simple.” Woody Guthrie