Certificate ID: EUCC-3110-2026-03-2500075-01 Common Criteria Recognition Arrangement for components up to EAL2 and ALC_FLR.3 The IT product identified in this certificate has been evaluated at an accredited and licensed / approved evaluation facility using the Common Methodology for IT Security Evaluation (CEM:2022) for conformance to the Common Criteria for IT Security Evaluation (CC:2022). CC:2022 and CEM:2022 are also published as ISO/IEC 15408-1, 2, 3, 4, 5:2022 and ISO/IEC 18045:2022. This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete certification report. The evaluation has been conducted in accordance with the provisions of (EU) 2024/482, the European Cybersecurity Certification Scheme (EUCC), and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced. This certificate is not an endorsement of the IT product by TrustCB B.V. or by any other organisation that recognises or gives effect to this certificate, and no warranty of the IT Product by TrustCB B.V. or by any other organisation that recognises or gives effect to this certificate, is either expressed or implied. TrustCB B.V. | www.trustcb.com | eucc@trustcb.com | Van den Berghlaan 48, 2132 AT Hoofddorp | The Netherlands TrustCB B.V certifies that ICT Product NXP JCOP 7.x on SN300 Secure Element, versions JCOP 7.0 R1.62.0.1, JCOP 7.1 R1.04.0.1, JCOP 7.2 R1.09.0.1, JCOP 7.3 R1.07.0.1 of Certificate holder and developer NXP Semiconductors Netherlands N.V. High Tech Campus 60, 5656AG Eindhoven, The Netherlands Certificate contact: cybersecurity.certification@nxp.com Website link https://www.nxp.com/products/wireless-connectivity/nfc-hf/nfc-enabled-digital-wallet:NFC-ENABLED- DIGITAL-WALLET Complies to the requirements described in the Standard: ISO/IEC 15408-1:2022, -2:2022, -3:2022, -4:2022, -5:2022, Common Criteria for Information Technology Security Evaluation, CC:2022 R1 and ISO/IEC 18045:2022, Common Methodology for Information Technology Security Evaluation, CEM:2022 R1 Summarised as: Certification Report EUCC-3110-2026-03-2500075-01-Certification Report TOE type Smart Cards and Similar Devices Assurance EUCC Level: High CC Package conformance: • EAL5 augmented with AVA_VAN.5, ALC_DVS.2, ALC_FLR.2 and ASE_TSS.2, Protection Profile Conformance: • Security IC Platform Protection Profile with Augmentation Packages version 1.0, 13 January 2014, registered under the reference BSI-CC-PP-0084-2014 • Java Card System – Open Configuration Protection Profile, Version 3.2, July 2024, registered under the reference BSI-CC-PP-0099-V3-2024 As evaluated by: SGS Brightsight B.V. located in Delft, the Netherlands Under scheme: European Cybersecurity Certification Scheme (EUCC), (EU) 2024/482 of 31-01- 2024, amended by (EU) 2024/3144 of 18-12-2024 Authorised by: The Dutch Authority for Digital Infrastructure (RDI) This certificate is valid for five years from the latest stated issue date until, and including, the stated certificate expiry date unless otherwise suspended or withdrawn. Date of 1st issue: 05-03-2026 Certificate expiry: 05-03-2031 Wouter Slegers, CEO