The International Common Criteria Conference (ICCC) 2026 is one of the leading global events for cybersecurity certification, bringing together certification bodies, ITSEFs, regulators, technology vendors and industry experts to discuss the future of trusted digital products.
As an official sponsor of ICCC 2026, Applus+ Laboratories will contribute through technical presentations, panel discussions and moderated tracks covering topics such as EUCC, the Cyber Resilience Act (CRA), cryptographic assurance, vulnerability management and the evaluation of emerging technologies.
Our strong presence at ICCC reflects the strategic position of Applus+ Laboratories within the European cybersecurity certification ecosystem. As regulatory frameworks continue to evolve, Common Criteria and EUCC play an increasingly important role in helping manufacturers demonstrate cybersecurity assurance and prepare for CRA compliance.
Together, the experts of Applus+ Laboratories, including jtsec, Lightship Security and the recently acquired Teron Labs, will share insights and real-world experience from some of the industry's most relevant certification and compliance projects.
The introduction of the EUCC scheme has transformed the European Common Criteria landscape, creating new opportunities and challenges for certification bodies, laboratories, vendors and national authorities. This panel brings together key stakeholders from across Europe to share practical lessons learned during the transition to EUCC, discuss the impact of evolving regulatory requirements and explore how the ecosystem can maintain consistency, quality and predictability while adapting to continuous change.
Based on global certification data collected through the CCScraper platform, this session presents the 2026 Common Criteria Statistics Report and explores how regulatory initiatives such as EUCC and the Cyber Resilience Act (CRA) are reshaping the certification landscape. The presentation examines certification trends, regional market dynamics, emerging compliance requirements, AI-driven technologies and other key factors influencing the future evolution of the Common Criteria ecosystem.
This session explores the evolving certification landscape for Random Bit Generators (RBGs), Entropy Source Validation (ESV) and Common Criteria evaluations. Drawing from real-world certifications and NIST SP 800-90B/90C requirements, the presentation examines entropy source validation methodologies, testing approaches and the impact of Post-Quantum Cryptography on entropy generation requirements. Attendees will gain practical insights into emerging certification expectations and future cryptographic assurance challenges.
Flaw remediation has become one of the fastest-growing assurance components within Common Criteria certifications. This session analyses certification trends and the increasing adoption of ALC_FLR, exploring what its growth reveals about changing industry expectations for vulnerability management and product maintenance. Attendees will gain practical guidance on the different ALC_FLR levels, the requirements vendors should consider before pursuing certification, and the relationship between flaw remediation and emerging patch management assurance approaches such as ALC_PAM.
This session explores how existing EUCC certifications can be leveraged as a foundation for Cyber Resilience Act (CRA) conformity. Using a real ENISA pilot project focused on network devices, the presentation examines how evaluation evidence, security assurance activities and certification artefacts can support CRA risk assessments while identifying potential gaps that may require additional technical controls or targeted testing. The session provides practical guidance for manufacturers seeking to maximize the value of certification investments and build a credible path toward CRA compliance.
This track session brings together international experts to discuss advances in Common Criteria evaluations, certification processes and practical applications. Topics include vulnerability management, evaluation methodologies and the reuse of certification activities across products and schemes.
As cryptographic assurance requirements become increasingly rigorous, Entropy Source Validation (ESV) has emerged as a critical component of Common Criteria evaluations. This session examines the transition from traditional entropy estimation methods to modern min-entropy modelling approaches and explores evolving requirements driven by international certification schemes and recent policy updates. Attendees will gain practical insights into validating complex entropy source designs, meeting emerging compliance expectations and navigating the growing regulatory scrutiny surrounding cryptographic evaluations.
This track explores how Common Criteria methodologies are evolving to address emerging technologies and new application domains. Discussions will cover innovative evaluation approaches for Artificial Intelligence systems, national proposals for certifying AI-enabled products and methodologies for assessing increasingly complex digital technologies. The session brings together leading experts from certification bodies, laboratories and regulatory organizations to discuss the future of cybersecurity assurance in rapidly changing technology environments.
Our experts will also take part in the pre-conference event, focused on how product teams manage CC certification in the real world.
This interactive panel discussion explores practical certification strategies through three real-world, anonymized case studies. Addressing different market and regulatory needs, the session examines how manufacturers can navigate certification pathways in Europe and the United States while maximizing recognition and minimizing redundant effort.
Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.
They allow the operation of the website, loading media content and its security. See the cookies we store in our Cookies Policy.
They allow us to know how you interact with the website, the number of visits in the different sections and to create statistics to improve our business practices. See the cookies we store in our Cookies Policy.
Based on your behavior on the website (where you click, how long you browse, etc.) we establish parameters and a profile for you to display ads that correspond to your interests. See the cookies we store in our Cookies Policy.