MRA recognition for components CCRA recognition for components up 10 EAL 4 and ALC_FLR on up 10 EAL 2 and ALCFLR on centro criptolégico nacional CERTIFICATE CCN-CC-28/2020 Microsoft SQL Server 2019 on Linux Database Engine Enterprise Edition x64 (English), version 15.0.4033.1 Type of product Database Management System (DBMS) Conformance of functionality PP Conformance functionality Protection Profile Conformance DBMS Working Group Technical Community Protection Profile for Database Management Systems (DBMS PP) Base Package (Version 2.12, March 23rd, 2017), DBMS Working Group Technical Community DBMS Protection Profile Extended Package - Access History (DBMS PP_EP_AH) (Version 1.02, March 23rd, 2017) Evaluation Facility DEKRA Testing and Certification S.A.U. Certification Report CCN-CC/2019-43/INF-3225 Expiration Date See Certification Report Pursuant to the authority vested in me under Act 11/2002 regulating the National Intelligence Centre, and under Article 1 and Article 2.2.c of Royal Decree 421/2004 of March 12th regulating the National Cryptologic Centre, | hereby: Certify that the security of Microsoft SQL Server 2019 on Linux Database Engine Enterprise Edition x64 (English), version 15.0.4033.1, developed by Microsoft Corporation, 1 Microsoft Way, Redmond, WA 98052, U.S.A., has been evaluated using Common Methodology for Information Technology Security Evaluation/Common Criteria for Information Technology Security Evaluation version 3.1 release 5, and it has met the requirements of its Security Target identified as “Microsoft SQL Server 2019 on Linux Database Engine Common Criteria Evaluation (EAL2+) Security Target (version: 1.3, date: 2020-07-20)”, for evaluation assurance level EAL2 + ALC_FLR.2. Madrid, 03 August 2020 Secretary of State Director ‘steban Lopez This certificate, its scope and validity are subject to the terms, conditions and requirements specified in the “Reglamento de Evaluaciön y Certificaciön de la Seguridad de las T.I.C.” at PRE/2740/2007, September 19th. The above-mentioned Security Target and Certification Report are available at the National Cryptologic Centre. This certificate will come into effect the following day that the associated certificate resolution signed by the Secretary of State Director of CCN is published in the Official State Gazette (B.O.E — https://www.boe.es). The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for Information Technology Security Evaluation/Common Criteria for Information Technology Security Evaluation version 3.1 release 5 and CC Supporting Documents as listed in the Certification Report. This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report. The evaluation has been conducted in accordance with the provisions of the Spanish IT Security Evaluation and Certification Scheme, PRE/2740/2007 September the 19th, and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced. This certificate is not an endorsement of the IT product by the Spanish Scheme or by any other organisation that recognises or gives effect to this certificate, and no warranty of the IT product by the Spanish Scheme or by any other organisation that recognises or gives effect to this certificate, is either expressed or implied.