Version 2023-07 TrustCB and TrustCB TRUST AND VERIFY are registered trademarks. Any use or application requires prior approval. Certificate Standard ISO/IEC 15408-1 :2009, -2 :2008, -3 :2008, Common Criteria for Information Technology Security Evaluation (CC) v3.1 rev 5 and ISO/IEC 18045 :2008, Common Criteria Evaluation Methodology for Information Security Evaluation (CEM) v3.1 rev 5 Certificate number NSCIB-CC-2400013-01 TrustCB B.V. certifies: Certificate holder and developer CyberArk Software Ltd. 9 Hapsagot St. Park Ofer 2, P.O. Box 3143, Petach-Tikva 4951040, Israel Product and assurance level CyberArk Privileged Access Manager – Digital Vault Server v14.0.0.40 Assurance Requirements: ▪ ASE_INT.1, ASE_CCL.1, ASE_SPD.1, ASE_OBJ.1, ASE_ECD.1, ASE.REQ.1, ASE.TSS.1, ADV_FSP.1, AGD_OPE.1, AGD_PRE.1, ALC_CMC.1, ALC_CMS.1, ALC_TSU_EXT.1, ATE_IND.1, and AVA_VAN.1 Protection Profile Conformance: ▪ NIAP Protection Profile for Application Software, v1.4 (PP_APP), 2021-10-07 ▪ NIAP Functional Package for Transport Layer Security, v1.1, 2019-03-01 Project number NSCIB-2400013-01 Evaluation facility Common Criteria Recognition Arrangement for components up to EAL2 and ALC_FLR.3 SOGIS Mutual Recognition Agreement for components up to EAL4 and ALC_FLR 3 SGS Brightsight BV located in Delft, the Netherlands Applying the Common Methodology for Information Technology Security Evaluation (CEM), Version 3.1 Revision 5 (also published as ISO/IEC 18045) The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation version 3.1 Revision 5 for conformance to the Common Criteria for IT Security Evaluation version 3.1 Revision 5. CC and CEM are also published as ISO/IEC 15408-1 :2009, -2 :2008, -3 :2008 and ISO/IEC 18045:2008. This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete certification report. The evaluation has been conducted in accordance with the provisions of the Netherlands scheme for certification in the area of IT security [NSCIB] and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced. This certificate is not an endorsement of the IT product by TrustCB B.V. or by other organisation that recognises or gives effect to this certificate, and no warranty of the IT product by TrustCB B.V. or by any other organisation that recognises or gives effect to this certificate, is either expressed or implied. Validity Date of 1st issue : 03-07-2024 Certificate expiry : 03-07-2029 Wouter Slegers, CEO TrustCB B.V. Van den Berghlaan 48, 2132 AT Hoofddorp, The Netherlands