Applus+ Laboratories sponsors the ICCC 26

28/09/2026

    The International Common Criteria Conference (ICCC) 2026 is one of the leading global events for cybersecurity certification, bringing together certification bodies, ITSEFs, regulators, technology vendors and industry experts to discuss the future of trusted digital products.

    As an official sponsor of ICCC 2026, Applus+ Laboratories will contribute through technical presentations, panel discussions and moderated tracks covering topics such as EUCC, the Cyber Resilience Act (CRA), cryptographic assurance, vulnerability management and the evaluation of emerging technologies.

     

    • Date de début: 28/09/2026
    • Date de fin: 01/10/2026
    • Ville: Rome
    • Pays: Italie
    • Site web de l'événement: https://iccconference.org/

    Our strong presence at ICCC reflects the strategic position of Applus+ Laboratories within the European cybersecurity certification ecosystem. As regulatory frameworks continue to evolve, Common Criteria and EUCC play an increasingly important role in helping manufacturers demonstrate cybersecurity assurance and prepare for CRA compliance.

    Together, the experts of Applus+ Laboratories, including jtsec, Lightship Security and the recently acquired Teron Labs, will share insights and real-world experience from some of the industry's most relevant certification and compliance projects.

    Meet our experts at ICCC 2026

    Discover the sessions, panels and moderated tracks featuring our cybersecurity specialists throughout ICCC 2026.
    PANEL DISCUSSION SEP-29 · 11:45 a.m.

    EUCC Implementation, European Cybersecurity Certification and Scheme Evolution

    Panelist
    Jose Francisco Ruiz Gualda
    Cybersecurity BU Director at Applus+ Laboratories 
    Topic: CC

    The introduction of the EUCC scheme has transformed the European Common Criteria landscape, creating new opportunities and challenges for certification bodies, laboratories, vendors and national authorities. This panel brings together key stakeholders from across Europe to share practical lessons learned during the transition to EUCC, discuss the impact of evolving regulatory requirements and explore how the ecosystem can maintain consistency, quality and predictability while adapting to continuous change.

    TRACK SESSION SEP-29 · 16:45 p.m.

    Common Criteria Market Trends, EUCC, CRA and Emerging Technologies

    Speaker
    Jose Pulido
    Director at jtsec (Applus+ Laboratories) 
    Topic: CC

    Based on global certification data collected through the CCScraper platform, this session presents the 2026 Common Criteria Statistics Report and explores how regulatory initiatives such as EUCC and the Cyber Resilience Act (CRA) are reshaping the certification landscape. The presentation examines certification trends, regional market dynamics, emerging compliance requirements, AI-driven technologies and other key factors influencing the future evolution of the Common Criteria ecosystem.

    TRACK SESSION SEP-30 · 09:30 a.m.

    ESV, 90C and Common Criteria 

    Speaker
    James Ramage
    CMVP Laboratory Manager at Lightship Security (Applus+ Laboratories) 
    Topic: PQC

    This session explores the evolving certification landscape for Random Bit Generators (RBGs), Entropy Source Validation (ESV) and Common Criteria evaluations. Drawing from real-world certifications and NIST SP 800-90B/90C requirements, the presentation examines entropy source validation methodologies, testing approaches and the impact of Post-Quantum Cryptography on entropy generation requirements. Attendees will gain practical insights into emerging certification expectations and future cryptographic assurance challenges.

    TRACK SESSION SEP-30 · 11:30 a.m.

    The Rise of Flaw Remediation: What ALC_FLR's Growth Reveals About CC Certifications, and What Vendors Need to Know to Claim It

    Speaker
    Pasquale Catanzariti
    Senior Security Engineer at Teron Labs (Applus+ Laboratories) 
    Topic: CC

    Flaw remediation has become one of the fastest-growing assurance components within Common Criteria certifications. This session analyses certification trends and the increasing adoption of ALC_FLR, exploring what its growth reveals about changing industry expectations for vulnerability management and product maintenance. Attendees will gain practical guidance on the different ALC_FLR levels, the requirements vendors should consider before pursuing certification, and the relationship between flaw remediation and emerging patch management assurance approaches such as ALC_PAM.

    TRACK SESSION SEP-30· 16:30 p.m.

    From EUCC Certification to CRA Conformity: A Resilience-Oriented Path for Network Devices

    Speaker
    Jose Gabriel Marin
    Common Criteria & EUCC Certification Principal Consultant at jtsec (Applus+ Laboratories) 
    Topic: CC

    This session explores how existing EUCC certifications can be leveraged as a foundation for Cyber Resilience Act (CRA) conformity. Using a real ENISA pilot project focused on network devices, the presentation examines how evaluation evidence, security assurance activities and certification artefacts can support CRA risk assessments while identifying potential gaps that may require additional technical controls or targeted testing. The session provides practical guidance for manufacturers seeking to maximize the value of certification investments and build a credible path toward CRA compliance.

    SESSION MODERATOR OCT-01 · 09:00 a.m.

    Advances in CC Use

    Moderator
    Jose Pulido
    Director at jtsec (Applus+ Laboratories) 
    Topic: CC

    This track session brings together international experts to discuss advances in Common Criteria evaluations, certification processes and practical applications. Topics include vulnerability management, evaluation methodologies and the reuse of certification activities across products and schemes.

    TRACK SESSION OCT-01 · 10:45h a.m.

    The Importance of Entropy Source Validation in Common Criteria: Navigating the New Assurance Landscape 

    Speaker
    Marina Ibrishimova
    Principal Entropy Consultant at Lightship Security (Applus+ Laboratories) 
    Topic: CC and ESV

    As cryptographic assurance requirements become increasingly rigorous, Entropy Source Validation (ESV) has emerged as a critical component of Common Criteria evaluations. This session examines the transition from traditional entropy estimation methods to modern min-entropy modelling approaches and explores evolving requirements driven by international certification schemes and recent policy updates. Attendees will gain practical insights into validating complex entropy source designs, meeting emerging compliance expectations and navigating the growing regulatory scrutiny surrounding cryptographic evaluations.

    TRACK MODERATOR OCT-01· 10:45 a.m.

    CC in New Domains

    Moderator
    Jose Francisco Ruiz Gualda
    Cybersecurity BU Director at Applus+ Laboratories 
    Topic: CC

    This track explores how Common Criteria methodologies are evolving to address emerging technologies and new application domains. Discussions will cover innovative evaluation approaches for Artificial Intelligence systems, national proposals for certifying AI-enabled products and methodologies for assessing increasingly complex digital technologies. The session brings together leading experts from certification bodies, laboratories and regulatory organizations to discuss the future of cybersecurity assurance in rapidly changing technology environments.

    Common criteria action plan day (28 September)

    Our experts will also take part in the pre-conference event, focused on how product teams manage CC certification in the real world. 

    PANEL DISCUSSION SEP-28 · 16:00 p.m.

    Europe, the U.S., or Both: A Live Certification-Path Clinic for EUCC, CCRA, and NIAP 

    Panelist
    Shaun Gilmore
    Evaluations and Standards Lead at Lightship Security (Applus+ Laboratories) 
    Topic: CC

    This interactive panel discussion explores practical certification strategies through three real-world, anonymized case studies. Addressing different market and regulatory needs, the session examines how manufacturers can navigate certification pathways in Europe and the United States while maximizing recognition and minimizing redundant effort.

     

    Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.

    Cookie settings panel