The Malaysian Common Criteria Evaluation and Certification (MyCC) Scheme provides a systematic process for evaluating and certifying the security functionality of ICT products against defined criteria and standards. This scheme ensures that high standards of competence and impartiality are maintained, promoting consistency and reliability in security assessments. The MyCC Scheme was developed under the 9th Malaysian Plan (2006-2010) and is supported by the 2005 National Cyber Security Policy (NCSP).
The MyCC Scheme is crucial for developers, manufacturers, and organizations aiming to certify their ICT products' security functionalities and gain global recognition for their commitment to security.
Common Criteria Recognition Arrangement (CCRA):
Malaysia has been accepted as CCRA Certificate Authorizing Member on 27 September 2011.
Common Criteria Recognition Arrangement (CCRA) was established in May 2000. The CCRA allows for mutual recognition of evaluation results, which creates value for ICT product vendors by allowing them to conduct an evaluation of their ICT product in one participating country and have the result recognised across all participating countries to the CCRA. There are 2 types of CCRA membership:
The MyCC Scheme offers various services to assess and certify the security of ICT products and systems.
Supporting Services
The MyCC Scheme also provides various supporting services to ensure smooth operation and international recognition.These include managing interpretations of relevant standards, engaging with international communities, and offering training and management of resources.
Evaluation and Certification: The MyCC Scheme evaluates and certifies the security functionality of ICT products against the ISO/IEC 15408 standard, also known as Common Criteria (CC). The evaluations are conducted using the Common Evaluation Methodology (CEM), recognized as ISO/IEC 18045.
Certification Body: The MyCC Scheme is managed by the Malaysian Common Criteria Certification Body (MyCB), a department within CyberSecurity Malaysia. MyCB is responsible for carrying out certifications and overseeing the scheme’s day-to-day management and operation. Importantly, MyCB operates independently from the Evaluation Facilities to ensure impartiality.
Evaluation Facility: The scheme includes an Evaluation Facility responsible for conducting security evaluations in an independently accredited environment. The Malaysian Security Evaluation Facility (MySEF) is the designated Evaluation Facility for the MyCC Scheme. Licensed MySEF under MyCC Scheme can be referred here:
The structure of the MyCC Scheme is illustrated in the figure below:
MyCC Scheme Structure
The MyCC Scheme Certified Products Register (MyCPR) is a comprehensive listing that includes certified ICT products, systems, and Protection Profiles. It also features products currently undergoing evaluation and those recognized from other CCRA certified authorizing participants.
MyCPR serves to aid stakeholders in selecting and implementing certified ICT products and systems. However, information in MyCPR is limited to the products’ performance against assurance levels and standards specified in the Common Criteria (CC).
Certification Reports, detailing evaluation results including scope clarifications and secure usage recommendations, accompany each listing. Consumers are advised that not all security functionalities may be evaluated. Therefore, downloading and understanding the Security Target and Certification Report are encouraged to assess product suitability for their organizational security needs.
Components of MyCPR:
MyCC Scheme publications are designed to provide guidance and step-by-step instructions for MyCC Scheme stakeholders. MyCC Scheme Publications is illustrated in the figure below:
Documents
Readers should contact the MyCC Scheme via the Contact Us detail if they have specific questions in relation to the information provided in MyCC Scheme publications or in relation to the MyCC Scheme Certified Products Register (MyCPR).
MyCC Scheme Other Publications
CCRA Publications
Common Criteria (CC)
Common Evaluation Methodology (CEM)
The official version of Common Criteria (CC) and CEM is version CC:2022 Revision 1. The previous versions can be found at https://www.commoncriteriaportal.org/cc/index.cfm
Other related CCRA supporting documents can be found at https://www.commoncriteriaportal.org/cc/index.cfm
An interpretation is an expert technical judgement of the meaning or method of application of any technical aspect of the CCRA, CC, CEM, MyCC Scheme rules and MyCC Scheme publications. There are 2 classes of interpretations:
MyCB shall be the authority for managing both interpretations. Request for interpretation (RI) can be accepted from any interested parties including Sponsors, Developer, Consumers, Evaluators and Certifiers using the RI form.
The MyCC Scheme national and international interpretations process comprises of four business functions:
National Interpretation
Currently, there is no national interpretations of CC, CEM, MyCC Scheme rules or MyCC Scheme publications.
International Interpretation
Please refer to https://www.commoncriteriaportal.org/index.cfm.
MyCB recover the costs for delivery of MyCC Scheme services through a service charge fees (excluding the SST) which includes:
These fees will contribute to funding the CCRA commitment and other supporting functions such as marketing or awareness initiatives.
| Evaluation Assurance Level | Certification Assurance Fees |
| EAL1 | RM 16,000 |
| EAL2 | RM 16,000 |
| EAL3 | RM 31,000 |
| EAL4 | RM 31,000 |
| EAL5 | RM 74,000 |
| EAL6 | RM 74,000 |
| EAL7 | RM 74,000 |
For any enquiry please contact:
enquiry@cybersecurity.my
COPYRIGHT © CYBERSECURITY MALAYSIA
Warna Teks
A A A ASaiz Teks
A+ A A-