for Information Security ® ‘Common Criteria CYBERSECURITY CERTIFICATION | M 2026-0010 ae | Federal Office zZ EUCC-3087-2026-0010(*) Administration ID BSI-DSZ-CC-1162-V4-2026 Security IC with MRTD EAC/PACE Application CardOS V6.0 ID R1.2 Holder of the Certificate: Eviden Germany GmbH Otto-Hahn-Ring 6 81739 München Germany Evaluation Facility: TÜV Informationstechnik GmbH Unternehmensgruppe TÜV NORD Am TÜV 1 45307 Essen SL . Assurance Level: EUCC High with component AVA_VAN.5 Common Gilera Assurance Package: EAL 4 Recognition Arrangemen Assurance Augmentation: ALC_DVS.2, ATE_DPT.2 and AVA_VAN.5 recognition for componen PP Conformance: EN 419211-2:2013 - Protection profiles for secure signature creation device up to EAL 2 - Part 2: Device with key generation, BSI-CC-PP-0059-2009-MA-02, EN 419211-4:2013 - Protection profiles for secure signature creation device - Part 4: Extension for device with key generation and trusted channel to certificate generation application, BSI-CC-PP-0071-2012-MA-01, EN 419211-5:2013 - Protection profiles for secure signature creation device - Part 5: Extension for device with key generation and trusted channel to signature creation application, BSI-CC-PP-0072-2012-MA-01, Machine Readable Travel Document with "ICAO Application" Extended { DAKkS Access Control with PACE, Version 1.3.2, 5 December 2012, BSI-CC- Deutsche PP-0056-V2-2012-MA-02, Akkredkierungssel Common Criteria Protection Profile Machine Readable Travel Document using Standard Inspection Procedure with PACE (PACE_PP), Version 1.0, 2 November 2011, BSI-CC-PP-0068-V2-2011 valid until: 22 June 2031 The ICT Product identified in this certificate and its attached certification report has been evaluated at the above mentioned notified evaluation facility using the Common Methodology for IT Security Evaluation (CEM) in application of relevant state-of-the-art documents for the AVA_VAN components 4 and 5, as well as application notes and interpretations on advice by the Certification Body in the versions published at the time the conformity assessment was carried out. The CC and CEM used for the evaluation of the above mentioned ICT product are published as ISO/IEC 15408 and ISO/IEC 18045 or as CC:2022 and CEM:2022. (*) This certificate applies only to the specific version and release of the ICT product in its evaluated configuration and in conjunction with the complete Certification Report and Notification. For details see Certification Report part Achapter 5. The evaluation has been conducted in accordance with the provisions of Commission Implementing Regulation (EU) 2024/482 of 31 January 2024 laying down rules for the application of Regulation (EU) 2019/881 of the European Parliament and of the Council as regards the adoption of the European Common Criteria-based cybersecurity certification scheme (EUCC) and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced. Bonn, 23 June 2026 For the Federal Office for Info an baba SAD er her ton ‘abian Hodousche Head of Certificatioi éctor-General Directorate General S wy berger Allee 87 - D-53175 Bonn - Postfach 20 03 63 - D-53133 Bonn Phone +49 (0)228 99 9582-0 - Fax +49 (0)228 9582-5477 - Infoline +49 (0)228 99 9582-111 This certificate is not an endorsement of the IT Product by the Federal Office for Information Security or any other organisation that recognises or gives effect to this certificate, and no warranty of the IT Product by the Federal Office for Information Security or any other organisation that recognises or gives effect to this certificate, is either expressed or implied. This certificate and its holder are both subject to obligations and monitoring activities as specified in Commission Implementing Regulation (EU) 2024/482. This certificate, its holder and its issuer are furthermore subject to compliance rules and supervision by the National Cybersecurity Certification Authority as established at Federal Office for Information Security, Division S 14, Freital, Email: vio CC-Zert-304 EUCC-V5.5