Policy Information

Intention to participate in CCRA, the International Arrangement on the Recognition of Common Criteria Certificates in the field of Information Technology Security. (June 18, 2002)

METI (Ministry of Economy, Trade and Industry) and NITE (National Institute of Technology and Evaluation, the Certification Body of the Japanese IT security evaluation/certification scheme) announce the intention to participate in CCRA (Arrangement on the Recognition of Common Criteria Certificates in the field of Information Technology Security) and have started preparations to this end.

1. Objective and Background
In order to develop a secure and reliable e-Government, it was agreed that governmental procurement of IT products should consider IT security capability and follow the "Policy to Utilize Security-Enhanced IT Products for the Procurement of Governmental Ministries", and also that the infrastructure of the IT security evaluation and certification scheme should be established, as core projects in the e-Japan Priority Policy.
To realize this objective, METI commissioned NITE to establish the Japanese IT security evaluation and certification scheme based on the international standard ISO/IEC 15408 (Information Technology -Security Techniques - Evaluation Criteria for IT security, JIS X 5070 is the Japanese version), and the scheme began operation in April, 2001.

By participating in the CCRA, IT products evaluated and certified under the Japanese scheme shall be regarded as the same as those evaluated and certified by other participating schemes.

2. Planned schedule (subject to change)
CCIMB (managing entity of CCRA) will assess the documentation of the scheme and certification procedure operated by NITE for compliance. When CCIMB determines that the scheme is compliant with CCRA, and with the consent of the other CCRA participants, the application for participation shall be accepted.

June 2002: Submission of application
Summer to fall 2002: Review of the scheme documentation
Fall to winter 2002: Shadow Certification Procedure (assessment of certification procedure)
Spring to summer 2003: Participating in CCRA

Information Policy Top
@