Secrétariat général de la défense et de la sécurité nationale Agence nationale de la sécurité des systèmes d’information 5 1 b o u l e v a r d d e L a T o u r - M a u b o u r g - 7 5 7 0 0 P A R I S 0 7 S P - T é l 0 1 . 7 1 . 7 5 . 8 2 . 8 2 Rapport de certification / Certification report EUCC-3090-2026-31 Nokia 1830 Photonic Service Switch (Version R13.1.4) Paris, le Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 13/5/2026 | 19:30 CEST R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 2 s u r 1 6 AVERTISSEMENT / WARNING Ce rapport est destiné à fournir aux commanditaires un document leur permettant d’attester du niveau de sécurité offert par le produit dans les conditions d’utilisation ou d’exploitation définies dans ce rapport pour la version qui a été évaluée. Il est destiné également à fournir à l’acquéreur potentiel du produit les conditions dans lesquelles il pourra exploiter ou utiliser le produit de manière à se trouver dans les conditions d’utilisation pour lesquelles le produit a été évalué et certifié ; c’est pourquoi ce rapport de certification doit être lu conjointement aux guides d’utilisation et d’administration évalués ainsi qu’à la cible de sécurité du produit qui décrit les menaces, les hypothèses sur l’environnement et les conditions d’emploi présupposées afin que l’utilisateur puisse juger de l’adéquation du produit à son besoin en termes d’objectifs de sécurité. La certification ne constitue pas en soi une recommandation du produit par l’Agence nationale de la sécurité des systèmes d’information (ANSSI) et ne garantit pas que le produit certifié soit totalement exempt de vulnérabilités exploitables. This report is intended to provide individuals requesting evaluations with a document certifying the level of security provided by the product, under the usage or operating conditions defined in this report, for the version that was evaluated. It is also intended to inform potential purchasers of the product about the conditions under which it can be used to ensure compliance with the requirements for which the product was evaluated and certified. For this reason, the certification report must be read in conjunction with the evaluated usage and administration guides, as well as the product's security target, which describes the assumed threats, environmental assumptions, and usage conditions. This allows users to determine whether the product meets their security objectives. The certification itself does not constitute a product endorsement by the Agence nationale de la sécurité des systèmes d’information (ANSSI), nor does it guarantee that the certified product is entirely free from exploitable vulnerabilities. Toute correspondance relative à ce rapport doit être adressée au : All correspondence related to this report must be sent to: Secrétariat général de la défense et de la sécurité nationale Agence nationale de la sécurité des systèmes d’information Centre de certification 51, boulevard de la Tour Maubourg 75700 Paris cedex 07 SP certification@ssi.gouv.fr La reproduction de ce document sans altération ni coupure est autorisée. Reproduction of this document without alteration or cutting is authorized. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 3 s u r 1 6 PREFACE / FOREWORD La certification de la sécurité offerte par les produits et les systèmes des technologies de l’information est régie par le décret 2002-535 du 18 avril 2002 modifié. Ce décret indique que : - l’Agence nationale de la sécurité des systèmes d’information élabore les rapports de certification. Ces rapports précisent les caractéristiques des objectifs de sécurité proposés. Ils peuvent comporter tout avertissement que ses rédacteurs estiment utile de mentionner pour des raisons de sécurité ; - Les certificats délivrés par le directeur général de l’Agence nationale de la sécurité des systèmes d’information attestent que l’exemplaire des produits soumis à évaluation répond aux caractéristiques de sécurité spécifiées. Ils attestent également que les évaluations ont été conduites conformément aux règles et normes en vigueur, avec la compétence et l’impartialité requises (article 8). Certification of the security provided by information technology products and systems is governed by amended Decree 2002-535 of April 18th , 2002. This decree states that: - The Agence nationale de la sécurité des systèmes d’information drafts the certification reports. These reports specify the characteristics of the proposed security objectives. They may include any warnings authors deem necessary to mention for security reasons. - The certificates issued by the Director General of ANSSI certify that the specific product or system submitted for evaluation meets the defined security characteristics. They also confirm that the evaluations were carried out according to current rules and standards, with the required levels of competence and impartiality (Article 8). Ce rapport est conforme à [EUCC]. This report is in compliance with [EUCC]. Les procédures de certification sont disponibles sur le site Internet https://www.cyber.gouv.fr/. The certification procedures are available on the website www.cyber.gouv.fr. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 4 s u r 1 6 TABLE DES MATIERES / TABLE OF CONTENT 1 Résumé / Summary ........................................................................................................................................... 5 2 Le produit / Product ......................................................................................................................................... 7 2.1 Présentation du produit / Product presentation.................................................................................................. 7 2.2 Description du produit / Product description ...................................................................................................... 7 2.2.1 Introduction .......................................................................................................................................................................... 7 2.2.2 Services de sécurité / Security services............................................................................................................................. 7 2.2.3 Architecture .......................................................................................................................................................................... 8 2.2.4 Identification du produit / Product identification.......................................................................................................... 8 2.2.5 Cycle de vie / Lifecycle ........................................................................................................................................................ 9 2.2.6 Configuration évaluée / Evaluated configuration ........................................................................................................... 9 2.3 Contacts du produit / Product contacts ..............................................................................................................10 3 L’évaluation / Evaluation.................................................................................................................................11 3.1 Référentiels d’évaluation / Evaluation reference bases...................................................................................... 11 3.2 Travaux d’évaluation / Evaluation tasks................................................................................................................ 11 3.3 Analyse des mécanismes cryptographiques selon les référentiels techniques de l’ANSSI / Analysis of cryptographic mechanisms according to ANSSI technical standards ....................................................................... 11 4 La certification / Certification ...................................................................................................................... 12 4.1 Conclusion / Conclusion..........................................................................................................................................12 4.2 Restrictions d’usage / Use Restriction...................................................................................................................12 4.3 Reconnaissance du certificat / Certificate recognition .....................................................................................13 4.3.1 Reconnaissance internationale critères communs (CCRA) / International Common Criteria Recognition.........13 ANNEXE A. Références documentaires du produit évalué / Documentary references for the product evaluated ................................................................................................................................................ 14 ANNEXE B. Références liées à la certification / Certification references .......................................... 15 Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 5 s u r 1 6 1 Résumé / Summary Référence du rapport de certification / Certification report reference EUCC-3090-2026-31 Nom du produit / Product name Nokia 1830 Photonic Service Switch Référence/version du produit / Product reference/version Version R13.1.4 Type de produit / Type of product Produits réseaux ou logiciels génériques (Network or generic software products) Conformité à un profil de protection / Conformity with a protection profile Néant / None Critère d’évaluation et version / Evaluation criteria and version ISO/IEC 15408-1:2009, 15408-2:2008 15408-3:2008 Critères Communs version 3.1 rev. 5 Niveau d’évaluation / Evaluation level Elevé (High) / EAL3 augmenté (augmented) ALC_FLR.3, AVA_VAN.3 Référence du rapport d’évaluation / Evaluation report reference Project « GUSTAVE » Evaluation Technical Report Ref. CC-ETR-GUSTAVE-1.03 version 1.03 01/04/2026. Fonctionnalité de sécurité du produit / Product’s security features § 2.2.2Services de sécurité / Security services Résumé des menaces / Threat summary Remote management Local management Malicious updates Admin error TSF failure Undetected actions Unauthorized access Time base Residual data Exigences de configuration du produit / Product configuration requirements § 4.2 Restrictions d’usage / restrictions usage Hypothèses liées à l’environnement d’exploitation / Operating environment assumptions § 4.2Restrictions d’usage / restrictions usage Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 6 s u r 1 6 Développeur / Developer NOKIA NETWORKS FRANCE 12 rue Jean Bart 91300 Massy, France Commanditaire / Sponsor NOKIA NETWORKS FRANCE 12 rue Jean Bart 91300 Massy, France Centre d’évaluation (CESTI) / Evaluation center (ITSEF) ALMOND 11 rue Maurice Fabre, 35000 Rennes, France Marque EUCC / EUCC Mark Accords de reconnaissance applicables / Applicable recognition agreements CCRA Ce certificat est reconnu au niveau EAL2 augmenté de ALC_FLR.3. This certificate is recognized at EAL2 level augmented with ALC_FLR.3. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 7 s u r 1 6 2 Le produit / Product 2.1 Présentation du produit / Product presentation Le produit évalué est « Nokia 1830 Photonic Service Switch, Version R13.1.4 » développé par NOKIA NETWORKS FRANCE. Le produit 1830 PSS1 est une plateforme DWDM2 évolutive qui permet d’agréger différents protocoles tels que la fibre optique, Ethernet ou autres. Le produit évalué permet l’usage de deux cartes 11QPEN4 (10Gbits/s en ligne) et S13X100E (100Gbits/s en ligne) de chiffrement de la couche 1 (physique) pour la protection de bout en bout contre la perte de confidentialité le long de la fibre, pilotées par le logiciel fonctionnant sur un contrôleur d’équipement redondé. The product evaluated is « Nokia 1830 Photonic Service Switch, Version R13.1.4 » developed by NOKIA NETWORKS FRANCE. The 1830 PSS product is a DWDM platform that supports aggregation for Ethernet, Fibre Channel and other protocols. The product evaluated is based on the 11QPEN4 (Quad Port 10G Encryption) and S13X100E (Single Port 100G Encryption) transponders that are pluggable cards providing Layer 1 data encryption for end-to-end protection against loss of confidentiality along the fiber and that are installed on an 1830 PSS shelf with an Equipment Controller. 2.2 Description du produit / Product description 2.2.1 Introduction La cible de sécurité [ST] définit le produit évalué, ses fonctionnalités de sécurité évaluées et son environnement d’exploitation. The security target [ST] defines the product that is evaluated, its security functionalities that are evaluated and its operating environment. 2.2.2 Services de sécurité / Security services Les services de sécurité évalués fournis par le produit sont présentés au chapitre 1.5.2 « Summary of Security Features » de la cible de sécurité [ST]. The main security services provided by the product are listed at chapter 1.5.2 “Summary of Security Features” of the security target [ST]. 1 Photonic Service Switch 2 Dense Wavelength Division Multiplexing est une technologie de multiplexage optique utilisée pour augmenter la largeur de bande sur une même fibre optique en combinant et transmettant plusieurs signaux de longueurs d’ondes différentes simultanément. DWDM is an optical multiplexing technology used to increase bandwidth in the same fiber by combining and transmitting multiple signals simultaneously over different wavelengths. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 8 s u r 1 6 2.2.3 Architecture L’architecture du produit est décrite au chapitre 1.4 « Target of Evaluation (TOE) Overview » de la cible de sécurité [ST]. The product’s architecture is described at chapter 1.4 « Target of Evaluation (TOE) Overview »of the security target [ST]. Le produit peut être décomposé en deux parties distinctes : une partie physique et une partie logique ; chacune est présentée au chapitre 1.5 « TOE Description » de la cible de sécurité [ST]. The product is composed of a physical scope and a logical scope; both are presented in chapter 1.5 “TOE Description” of the security target [ST]. 2.2.4 Identification du produit / Product identification La version certifiée du produit est identifiable par les éléments détaillés dans la cible de sécurité [ST] au chapitre 1.5 « TOE Description », table 1.4 « Physical Scope ». The certified version of the product can be identified by the elements detailed in the security target [ST] in the « TOE Description » chapter, table 1.4 “Physical Scope”. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 9 s u r 1 6 2.2.5 Cycle de vie / Lifecycle Le cycle de vie du produit est le suivant : The product life cycle is as follows: Le produit a été développé sur les trois sites mentionnés ci-après. Ceux-ci ont tous été audités dans le cadre de cette évaluation. The product has been developed on the three following sites, which have all been audited within this evaluation. Site Adresse Nokia - Ottawa, Canada 600 March Road, Ottawa, Ontario CANADA K2K 2T6 Nokia Murray Hills 600-700 Mountain Avenue, Murray Hill, NJ 07974 USA Flextronic Manufacturing S.R.I. Strada al Monte d’Oro 14, 34147 Trieste (TS), ITALIE Pour l’évaluation, les rôles considérés sont : - l’administrateur qui fournit les accès à tous les services nécessaires à l’installation initiale et à la gestion des éléments du réseau ; - l’officier crypto qui administre les différentes clés cryptographiques. Il délivre tous les services nécessaires pour la gestion des fonctions et des paramètres de cryptographie. The roles considered for the evaluation are: - the administrator, who provides all needed services for initial installation and management of network elements; - the crypto officer, who manages the various cryptographic keys. They deliver all needed services for management of cryptographic functions and parameters. 2.2.6 Configuration évaluée / Evaluated configuration Le certificat porte sur les configurations permises par la cible de sécurité [ST], pourvu que les [GUIDES] soient respectés. The certificate covers the configurations permitted by the security target [ST], provided that the [GUIDES] are followed. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 1 0 s u r 1 6 2.3 Contacts du produit / Product contacts Les informations en matière de cybersécurité du produit sont disponibles ici : The product's cybersecurity information is available here: - https://www.nokia.com/asset/213394/. Le développeur peut être contacté via cette adresse : The developer can be contacted at this address: - security.psirt@nokia.com. La procédure complète de signalement d’une vulnérabilité est disponible sur le lien suivant : The complete procedure for reporting a vulnerability is available at the following link: - https://www.nokia.com/we-are-nokia/security/products/#product-security-incidents-and- psirt. Les informations sur l’Autorité nationale de certification de cybersécurité en France sont disponibles ici : Information on France's National Cybersecurity Certification Authority is available here: - https://cyber.gouv.fr/cybersecurity-act Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 1 1 s u r 1 6 3 L’évaluation / Evaluation 3.1 Référentiels d’évaluation / Evaluation reference bases L’évaluation a été menée conformément aux Critères Communs [CC], et à la méthodologie d’évaluation définie dans le manuel [CEM]. The evaluation was carried out in accordance with the Common Criteria [CC], and with the evaluation methodology defined in the manual [CEM]. 3.2 Travaux d’évaluation / Evaluation tasks Le rapport technique d’évaluation [RTE], remis à l’ANSSI le 1er avril 2026, détaille les travaux menés par le centre d’évaluation et atteste que toutes les tâches d’évaluation sont à « réussite ». The Evaluation Technical Report [ETR], submitted to ANSSI on February 26th 2026 details the work carried out by the evaluation center and attests that all the evaluation tasks were rated as « PASS ». 3.3 Analyse des mécanismes cryptographiques selon les référentiels techniques de l’ANSSI / Analysis of cryptographic mechanisms according to ANSSI technical standards Les mécanismes cryptographiques mis en œuvre par les fonctions de sécurité du produit (voir [ST]) ont fait l’objet d’une analyse conformément à la procédure [CRY-P-01] et les résultats ont été consignés dans le rapport [ANA_CRY]. The cryptographic mechanisms implemented by the product's security functions (see [ST]) have been analyzed in accordance with procedure [CRY-P-01] and the results recorded in report [ANA_CRY]. Cette analyse a identifié des non-conformités par rapport au référentiel [ANSSI Crypto]. Elles ont été prises en compte dans l’analyse de vulnérabilité indépendante réalisée par l’évaluateur et n’ont pas permis de mettre en évidence de vulnérabilité exploitable pour le niveau d’attaquant visé. This analysis identified the following non-conformities with respect to the standard [ANSSI Crypto]. They were taken into account in the independent vulnerability analysis carried out by the evaluator, which did not reveal any exploitable vulnerabilities at the targeted attacker level. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 1 2 s u r 1 6 4 La certification / Certification 4.1 Conclusion / Conclusion L’évaluation a été conduite conformément aux règles et normes en vigueur, avec la compétence et l’impartialité requises pour un centre d’évaluation agréé. L’ensemble des travaux d’évaluation réalisés permet la délivrance d’un certificat conformément au décret 2002-535 et à [EUCC]. The evaluation was carried out according to current rules and standards, with the levels of competence and impartiality required for an approved evaluation body. All of the evaluation work performed permits the delivery of a certificate in accordance with decree 2002-535 and to [EUCC]. Ce certificat atteste que le produit soumis à l’évaluation répond aux caractéristiques de sécurité spécifiées dans sa cible de sécurité [ST] pour le niveau d’évaluation visé (voir chapitre 1 Résumé / Summary). This certificate confirms that the product under evaluation meets the security requirements specified in its security target [ST] for the intended evaluation level (see chapter 1 Résumé / Summary). Le certificat associé à ce rapport, référencé EUCC-3090-2026-31 a une date de délivrance identique à la date de signature de ce rapport et a une durée de validité de cinq ans à partir de cette date. The certificate associated with this report, referenced EUCC-3090-2026-31 has an issue date identical to the signature date of this report and is valid for five years from that date. Le certificat est délivré sous accréditation Cofrac Certification de produits et services, attestation n°5-0669, liste des sites et portée disponibles sous www.cofrac.fr. The certificate is issued under accreditation of Cofrac Certification, certificate n°. 5-0669, list of sites and scope availableat www.cofrac.fr. 4.2 Restrictions d’usage / Use Restriction Ce certificat porte sur le produit spécifié au chapitre 2.2 du présent rapport de certification. This certificate relates to the product specified in chapter 2.2 of this certification report. L’utilisateur du produit certifié devra s’assurer du respect des objectifs de sécurité sur l’environnement d’exploitation, tels que spécifiés dans la cible de sécurité [ST], et suivre les recommandations se trouvant dans les guides fournis [GUIDES]. The user of the certified product must ensure compliance with the security objectives for the operating environment, as specified in the security target [ST], and follow the recommendations outlined in the provided guides [GUIDES]. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 1 3 s u r 1 6 4.3 Reconnaissance du certificat / Certificate recognition 4.3.1 Reconnaissance internationale critères communs (CCRA) / International Common Criteria Recognition Ce certificat est émis dans les conditions de l’accord du CCRA [CCRA]. L’accord « Common Criteria Recognition Arrangement » permet la reconnaissance, par les pays signataires3 , des certificats Critères Communs. This certificate is issued under the conditions of the CCRA agreement [CCRA]. The "Common Criteria Recognition Arrangement" enables the recognition of Common Criteria certificates by the signatory countries. La reconnaissance s’applique jusqu’aux composants d’assurance du niveau CC EAL2 ainsi qu’à la famille ALC_FLR. Les certificats reconnus dans le cadre de cet accord sont émis avec la marque suivante : Recognition applies up to the assurance components of CC EAL2 level as well as the ALC_FLR family. Certificates recognised under this agreement are issued with the following mark: 3 La liste des pays signataires de l’accord CCRA est disponible sur le site web de l’accord : www.commoncriteriaportal.org. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 1 4 s u r 1 6 ANNEXE A. Références documentaires du produit évalué / Documentary references for the product evaluated [ST] Cible de sécurité de référence pour l’évaluation / Security target for the evaluation: - Security Target – Nokia 1830 Photonic Service Switch (PSS), ref. ST Nokia 1830 PSS, version 1.1, 31/03/2026. [RTE] Rapport technique d’évaluation / Evaluation Technical Report: - Project « GUSTAVE » - Evaluation Technical Report, ref. CC-ETR-GUSTAVE- 1.03, version 1.03, 01/04/2026. [ANA_CRY] Analysis of Cryptographic Mechanisms – Project « GUSTAVE » – version R13.1.4, ref. CRY-GUSTAVE-1.01, version 1.01, 12/01/2026. [GUIDES] Guide d’installation du produit / Product installation guide: - 1830 Photonic Service Switch 32 (PSS-32) Release 13.1 Installation and System Turn-Up Guide, ref. 3KC-70745-NBAATJZZA, version 1, 07/10/2021 ; - 1830 Photonic Service Switch 816II1632PSI-8L (PSS-8PSS-16IIPSS-16PSS- 32PSI-8L) Release 13.1 User Provisioning Guide, ref. 3KC-70745- NBAATCZZA, version 1, 07/10/2021. Guide d’administration du produit / Product administration guide: - 1830 Photonic Service Switch 8/16II/32 (PSS-8/PSS-16II/PSS-32) Release 13.1.0 ECE Customer Release Notes, ref. 3KC-71499-AAAA, version 1, 07/10/2021 ; - 1830 Photonic Service Switch (PSS) Release 13.1 Command Line Interface Guide, ref. 3KC-70745-NBAATHZZA, version 1, 07/10/2021 ; - 1830 Photonic Service Switch (PSS) Release 13.1 Maintenance and Trouble- Clearing Guide (Photonic Applications), ref. 3KC-70745-NBAATMZZA, version 2, 07/10/2021 ; - 1830 Security Management Server Release 4.0 Administrator Guide, ref. 3KC-68273-AAAATUZZA, version 1, 16/12/2021. Guide d’utilisation du produit / Product user guide: - 1830 Photonic Service Switch (PSS) Release 13.1.4 Common Criteria User Guide, ref. 3KC-70745-NBEATSZZA, version 1, 24/11/2025 ; - 1830 Security Management Server Release 4.0 User Guide, ref. 3KC-68273- AAAATVZZA, version 1, 16/12/2021. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 1 5 s u r 1 6 ANNEXE B. Références liées à la certification / Certification references Décret 2002-535 du 18 avril 2002 modifié relatif à l’évaluation et à la certification de la sécurité offerte par les produits et les systèmes des technologies de l’information. Amended decree No. 2002-535 of April 18th , 2002 relating to the evaluation and certification of the security provided by information technology products and systems. [CER-P-01] Certification critères communs de la sécurité offerte par les produits, les systèmes des technologies de l’information, ou les profils de protection, référence ANSSI-CC-CER-P-01, version 5.4. Certification procedure of the security provided by information technology products and systems, ref ANSSI-CC-CER-P-01. [EUCC] Schéma européen de certification de cybersécurité fondé sur les critères communs (règlement d’exécution (UE) 2024/482) et ses amendements. European cybersecurity certification scheme based on common criteria (implementing regulation (EU) 2024/482) and its amendments. [CRY-P-01] Modalités pour la réalisation des analyses cryptographiques et des évaluations des générateurs de nombres aléatoires, référence ANSSI-CC-CRY-P01, version en vigueur. Methods for carrying out cryptographic analyses, reference ANSSI-CC-CRY-P01, current version. [CC] Information technology — Security techniques — Evaluation criteria for IT security - Part 1: Introduction and general model: ISO/IEC 15408-1:2009 ; - Part 2: Security functional components: ISO/IEC 15408-2:2008 ; - Part 3: Security Assurance components: ISO/IEC 15408-3:2008 ; - et correctifs techniques associés / and associated technical fixes. Equivalent à la version CCRA / equivalent to CCRA version : - Common Criteria for Information Technology Security Evaluation, version 3.1, rev. 5, vol. 1 -> 3, ref. CCMB-2017-04-001 -> CCMB-2017-04- 003. [CEM] Information technology — Security techniques — Methodology for IT security evaluation, ISO/IEC 18045:2008, et correctifs techniques associés / and associated technical fixes Equivalent à la version CCRA / equivalent to CCRA version : - Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, version 3.1, rev. 5, ref. CCMB-2017-04-004. [CCRA] Arrangement on the Recognition of Common Criteria Certificates in the field of Information Technology Security, 2/07/2014. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020 R a p p o r t d e c e r t i f i c a t i o n / C e r t i f i c a t i o n r e p o r t E U C C - 3 0 9 0 - 2 0 2 6 - 3 1 N o k i a 1 8 3 0 P h o t o n i c S e r v i c e S w i t c h ( V e r s i o n R 1 3 . 1 . 4 ) A N S S I - C C - C E R - F - 0 7 _ v 3 2 . 2 P a g e 1 6 s u r 1 6 [ANSSI Crypto] Guide des mécanismes cryptographiques : Règles et recommandations concernant le choix et le dimensionnement des mécanismes cryptographiques Guide to cryptographic mechanisms: Rules and recommendations concerning the choice and sizing of cryptographic mechanisms ANSSI-PG-083, version 2.04, 01/2020. *Dans le cadre de l’accord de reconnaissance du CCRA, le document support du CCRA équivalent s’applique. *Under the CCRA recognition agreement, the equivalent CCRA support document applies. Docusign Envelope ID: 1A0D886D-3850-8EB3-8313-F69E0AF14020