{"_id": "122fa718060e7cdd", "_type": "sec_certs.sample.eucc.EUCCCertificate", "dgst": "122fa718060e7cdd", "cert_id": "EUCC-3087-2026-0012", "category": "SMARTCARDS AND SIMILAR DEVICES", "name": "TCOS FlexCert Version 2.0 Release 2/SLC52", "status": "active", "manufacturer": "Deutsche Telekom Security GmbH", "scheme": "DE", "security_level": {"_type": "Set", "elements": []}, "not_valid_before": "2026-07-03", "not_valid_after": "2031-07-03", "report_link": "https://certification.enisa.europa.eu/document/download/a3b3ac32-c987-405a-aeed-1ae8685f23db_en?filename=EUCC-3087-2026-0012%20Certification%20Report.pdf", "st_link": "https://certification.enisa.europa.eu/document/download/ac407808-1505-45cc-beb7-bc6a9b935aef_en?filename=EUCC-3087-2026-0012%20Security%20Target.pdf", "cert_link": "https://certification.enisa.europa.eu/document/download/0e312e99-9cb1-4f06-9ae6-6ea8eb1e27d1_en?filename=EUCC-3087-2026-0012%20Certificate.pdf", "manufacturer_web": "https://www.telekom.com/en/company/data-privacy-and-security/hacking-and-testing", "protection_profile_links": null, "state": {"_type": "sec_certs.sample.cc_eucc_common.InternalState", "report": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "1448b48aa010df4e4344e7dfeaba5227d5b7e228bcda6236ee4608d6fba23806", "txt_hash": "05b4897d21cb6170b0aabf5a60fcf3fdebd95bc7cbe634c00e09f7b7be407881", "json_hash": null}, "st": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "405d50c87b9f0e6c752b0dcbc2ae462259b51ed46fea923dea20f5923661367c", "txt_hash": "9c0995033cd2a7062c96ce52a0a752995754e4e2c53c57ff4bbe05523aeb769d", "json_hash": null}, "cert": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "eecaa07d6eec3ed2678127c6722345e04c861a6eb9e9589500dc82e801334fe3", "txt_hash": "4ebdf238828d5f770f746bf4612d6c52f29764c92e996a32396336bd93b29394", "json_hash": null}}, "pdf_data": {"_type": "sec_certs.sample.cc_eucc_common.PdfData", "report_metadata": {"pdf_file_size_bytes": 618472, "pdf_is_encrypted": false, "pdf_number_of_pages": 37, "/Title": "Certification Report EUCC-3087-2026-0012; BSI-DSZ-CC-0904-V3", "/Subject": "TCOS FlexCert Version 2.0 Release 2/SLC52 from Deutsche Telekom Security GmbH", "/Keywords": "Common Criteria, Certification, Zertifizierung, G2 COS, eHealth, gematik", "/Creator": "Writer", "/Producer": "LibreOffice 24.8.7.2 (X86_64) / LibreOffice Community", "/CreationDate": "D:20260713102018+02'00'", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://www.iso.org/standard/72917.html", "https://www.iso.org/standard/72892.html", "https://www.bsi.bund.de/zertifizierungsreporte", "https://www.iso.org/standard/72906.html", "https://www.iso.org/standard/72891.html", "http://www.commoncriteriaportal.org/", "https://www.commoncriteriaportal.org/", "https://www.bsi.bund.de/AIS", "https://www.telekom.com/en/company/data-privacy-and-security/hacking-and-testing", "https://www.iso.org/standard/72889.html", "https://certification.enisa.europa.eu/publications/eucc-state-art-documents_en", "https://eur-lex.europa.eu/eli/reg_impl/2025/2462/oj", "https://certification.enisa.europa.eu/", "https://www.bsi.bund.de/zertifizierung", "https://www.iso.org/standard/72913.html"]}}, "st_metadata": {"pdf_file_size_bytes": 3188796, "pdf_is_encrypted": false, "pdf_number_of_pages": 129, "/Title": "Security Target TCOS FlexCert Version 2.0 Release 2", "/Author": "Deutsche Telekom Security GmbH", "/Subject": "TCOS FlexCert Version 2.0 Release 2", "/Keywords": "\"TCOS FlexCert, Generation 2\", Gesundheitskarte, electronic health card, TCOS", "/Creator": "Microsoft\u00ae Word f\u00fcr Microsoft 365", "/CreationDate": "D:20260611093646+02'00'", "/ModDate": "D:20260611093646+02'00'", "/Producer": "Microsoft\u00ae Word f\u00fcr Microsoft 365", "pdf_hyperlinks": {"_type": "Set", "elements": ["http://www.phy.duke.edu/~rgb/General/dieharder/dieharder-3.31.0.tgz", "http://csrc.nist.gov/groups/ST/toolkit/rng/documents/sts-2.1.1.zip"]}}, "cert_metadata": {"pdf_file_size_bytes": 118556, "pdf_is_encrypted": false, "pdf_number_of_pages": 2, "/Title": "KM_C300i26071305190", "/Creator": "KM_C300i", "/Producer": "KONICA MINOLTA bizhub C300i", "/CreationDate": "D:20260713051950+01'00'", "/ModDate": "D:20260713051950+01'00'", "pdf_hyperlinks": {"_type": "Set", "elements": []}}, "report_frontpage": {"DE": {"match_rules": ["(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)"], "cert_id": "BSI-DSZ-CC-0904-V3-2026", "cert_item": "TCOS FlexCert Version 2.0 Release 2/SLC52", "developer": "Deutsche Telekom Security GmbH", "cert_lab": "BSI"}}, "st_frontpage": null, "cert_frontpage": null, "report_keywords": {"cc_cert_id": {"DE": {"BSI-DSZ-CC-0904-V3-2026": 42, "BSI-DSZ-CC-0904-V2-2021": 2, "BSI-DSZ-CC-0904-V2-": 1, "BSI-DSZ-CC-1079-V6-2025": 3, "BSI-DSZ-CC-1079-V6-": 1, "EUCC-3087-2026-0012": 37, "EUCC-3087-2025- 12-0001": 1, "EUCC-3087-2025-12-0001": 6, "EUCC-3087- 2025-12-0001": 1}}, "cc_protection_profile_id": {"BSI": {"BSI-CC-PP-0082-V4-2019": 3}}, "cc_security_level": {"EAL": {"EAL 2": 2, "EAL 4": 1}}, "cc_sar": {"ADV": {"ADV_ARC": 1}, "ALC": {"ALC_FLR": 2, "ALC_DVS.2": 1, "ALC_FLR.1": 1}, "ATE": {"ATE_DPT.2": 1}, "AVA": {"AVA_VAN.5": 2}}, "cc_sfr": {"FCS": {"FCS_COP": 28, "FCS_CKM": 4, "FCS_RNG": 6, "FCS_RNG.1": 1}, "FIA": {"FIA_UAU": 2, "FIA_USB": 1}, "FPT": {"FPT_ITE.1": 1}, "FTP": {"FTP_ITC": 2}}, "cc_claims": {}, "vendor": {"Infineon": {"Infineon": 8, "Infineon Technologies AG": 6}}, "eval_facility": {"TUV": {"T\u00dcV Informationstechnik": 1}, "DeutscheTelekom": {"Deutsche Telekom Security": 20}, "SRC": {"SRC Security Research & Consulting": 6}, "TSystems": {"T-Systems International": 2}}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 31}, "HPC": {"HPC": 4}}, "constructions": {"MAC": {"CMAC": 17}}}, "asymmetric_crypto": {"RSA": {"RSA-OAEP": 2}, "ECC": {"ECDH": {"ECDH": 3}, "ECDSA": {"ECDSA": 13}, "ECC": {"ECC": 5}}, "FF": {"DH": {"Diffie-Hellman": 1, "DH": 1}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA2": {"SHA-256": 4}}}, "crypto_scheme": {"MAC": {"MAC": 3}, "KA": {"Key Agreement": 2}}, "crypto_protocol": {"PACE": {"PACE": 13}}, "randomness": {"PRNG": {"PRNG": 1}, "RNG": {"RNG": 8}}, "cipher_mode": {"CBC": {"CBC": 10}}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"side channel": 1, "DPA": 1, "SPA": 1}, "FI": {"malfunction": 1, "DFA": 1, "fault injection": 1}, "other": {"JIL": 2}}, "technical_report_id": {"BSI": {"BSI TR-03116-1": 1, "BSI TR-03144": 10, "BSI TR-03143": 5}}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 180-4": 7, "FIPS 197": 13, "FIPS PUB 180-4": 1, "FIPS PUB 197": 1}, "PKCS": {"PKCS#1": 5}, "BSI": {"AIS 20": 3, "AIS 31": 5, "AIS 37": 2, "AIS 46": 2, "AIS 38": 2, "AIS 1": 2, "AIS 25": 2, "AIS 32": 2, "AIS 14": 1, "AIS 19": 1, "AIS 26": 1, "AIS31": 2, "AIS20": 2}, "RFC": {"RFC 5639": 11}, "ISO": {"ISO/IEC 15408": 2, "ISO/IEC 18045": 2, "ISO/IEC 17065": 2, "ISO/IEC 18031:2005": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"ConfidentialDocument": {"Version 2.0 Release 2/SLC52, Version 1.1, 19 June 2026, SRC Security Research & Consulting GmbH (confidential document) [ConfList] Configuration List BSI-DSZ-CC-0904-V3-2026, Konfigurationsliste von TCOS FlexCert": 1, "2.0 Release 2/SLC52, Version 0.94, 10 June 2026, Deutsche Telekom Security GmbH (confidential document) [Guide ADM] TCOS FlexCert Version 2.0 Release 2, Administrator\u2019s Guidance, Guidance Documentation": 1, "Infineon Technologies AG, EUCC-3087-2025-12-0001 (Administration ID BSI- DSZ-CC-1079-V6-2025) (confidential document) Security Target Lite of the underlying hardware platform, Security Target IFX_CCI_00000Fh": 1, "ID BSI-DSZ-CC-1079-V6- 2025), Version 4, 18 December 2025, T\u00dcV Informationstechnik GmbH (confidential document) [Spec G2 COS] Einf\u00fchrung der Gesundheitskarte, Spezifikation des Card Operating System (COS": 1, "RNG] Zufallszahlengenerierung in TCOS, Version 0.7, 3 November 2020, T-Systems International GmbH (confidential document) [AIS 20] see chapter 14, [4] of this report [AIS 31] see chapter 14, [4] of this report Note: End": 1}}}, "st_keywords": {"cc_cert_id": {}, "cc_protection_profile_id": {"BSI": {"BSI-CC-PP-0082-V4-2019": 2, "BSI-CC-PP-0084-2014": 21, "BSI-CC-PP-0084-": 1, "BSI-CC-PP0082": 4, "BSI-CC-PP0084": 2, "BSI-CC-PP- 0035-2007": 1, "BSI-PP-0082": 1, "BSI-CC-PP- 0082-V4": 1}}, "cc_security_level": {"EAL": {"EAL4": 10, "EAL5": 2, "EAL6": 2, "EAL 4": 1, "EAL4 augmented": 2, "EAL5 augmented": 2, "EAL6 augmented": 2, "EAL 4 augmented": 1}}, "cc_sar": {"ADV": {"ADV_IMP.2": 2, "ADV_INT.3": 2, "ADV_TDS.5": 2, "ADV_ARC.1": 4, "ADV_TDS.3": 3, "ADV_FUN.1": 1, "ADV_FSP.4": 2, "ADV_IMP.1": 2, "ADV_ARC": 1, "ADV_FSP": 1}, "AGD": {"AGD_OPE.1": 2, "AGD_PRE.1": 2, "AGD_OPE": 1}, "ALC": {"ALC_DVS.2": 9, "ALC_FLR.1": 6, "ALC_CMC.5": 2, "ALC_FLR.3": 4, "ALC_TAT.3": 2, "ALC_DEL": 1, "ALC_DVS": 1, "ALC_CMS": 1, "ALC_CMC.4": 1, "ALC_CMS.4": 1, "ALC_DEL.1": 1, "ALC_LCD.1": 1, "ALC_TAT.1": 1}, "ATE": {"ATE_DPT.2": 7, "ATE_FUN.2": 2, "ATE_COV.3": 2, "ATE_DPT.1": 1, "ATE_COV": 1, "ATE_FUN": 1, "ATE_COV.2": 1, "ATE_FUN.1": 1}, "AVA": {"AVA_VAN.5": 10, "AVA_VAN": 1}}, "cc_sfr": {"FAU": {"FAU_SAS": 10, "FAU_SAS.1": 7, "FAU_SAS.1.1": 1}, "FCS": {"FCS_RNG": 32, "FCS_RNG.1": 31, "FCS_RNG.1.2": 2, "FCS_COP": 141, "FCS_CKM": 61, "FCS_CKM.6": 42, "FCS_CKM.4": 26, "FCS_RNG.1.1": 3, "FCS_CKM.1": 29, "FCS_COP.1": 20, "FCS_CKM.2": 4, "FCS_CKM.5": 6, "FCS_RBG.1": 4, "FCS_CKM.6.1": 3, "FCS_CKM.6.2": 2}, "FDP": {"FDP_SDC": 9, "FDP_SDI": 8, "FDP_ITT": 5, "FDP_IFC": 5, "FDP_RIP.1": 9, "FDP_RIP": 6, "FDP_SDI.2": 6, "FDP_ACC": 64, "FDP_ACF": 76, "FDP_UCT": 6, "FDP_UIT": 6, "FDP_ITC.1": 19, "FDP_ITC.2": 17, "FDP_ACF.1": 38, "FDP_ACC.1": 39, "FDP_IFF.1": 1, "FDP_IFC.1": 10, "FDP_ITT.1": 3, "FDP_SDI.1": 2, "FDP_RIP.1.1": 1, "FDP_SDI.2.1": 1, "FDP_SDI.2.2": 1, "FDP_UCT.1": 1, "FDP_UIT.1": 2, "FDP_SDC.1": 1}, "FIA": {"FIA_API": 9, "FIA_AFL": 19, "FIA_ATD.1": 12, "FIA_ATD": 6, "FIA_SOS.1": 6, "FIA_UAU.1": 12, "FIA_UAU": 38, "FIA_UAU.4": 12, "FIA_UAU.5": 15, "FIA_API.1": 13, "FIA_USB.1": 29, "FIA_USB": 29, "FIA_UID.1": 14, "FIA_UID": 7, "FIA_UAU.6": 9, "FIA_AFL.1": 4, "FIA_ATD.1.1": 1, "FIA_UAU.1.1": 1, "FIA_UAU.1.2": 1, "FIA_UAU.4.1": 1, "FIA_UAU.5.1": 1, "FIA_UAU.5.2": 1, "FIA_UAU.6.1": 1, "FIA_UID.1.1": 1, "FIA_UID.1.2": 1, "FIA_API.1.1": 1, "FIA_USB.1.1": 1, "FIA_USB.1.2": 1, "FIA_USB.1.3": 2, "FIA_SOS.1.1": 1, "FIA_SOS": 1}, "FMT": {"FMT_LIM": 14, "FMT_SMR.1": 22, "FMT_MSA.3": 25, "FMT_MSA": 52, "FMT_SMF.1": 34, "FMT_SMR": 6, "FMT_MTD": 27, "FMT_SMF.1.1": 1, "FMT_SMR.1.1": 1, "FMT_SMR.1.2": 1, "FMT_MSA.1": 7, "FMT_MSA.3.1": 1, "FMT_MSA.3.2": 1, "FMT_MTD.1": 4, "FMT_LIM.2": 8, "FMT_LIM.1": 8, "FMT_SMF": 1}, "FPT": {"FPT_ITE": 16, "FPT_EMS": 8, "FPT_ITE.1": 12, "FPT_ITE.2": 12, "FPT_ITE.1.1": 2, "FPT_ITE.1.2": 2, "FPT_ITE.2.1": 6, "FPT_ITE.2.2": 2, "FPT_FLS": 7, "FPT_PHP": 5, "FPT_ITT": 5, "FPT_FLS.1": 17, "FPT_EMS.1": 10, "FPT_TDC.1": 5, "FPT_TST.1": 7, "FPT_PHP.3": 7, "FPT_EMS.1.1": 1, "FPT_TDC.1.1": 1, "FPT_TDC.1.2": 1, "FPT_FLS.1.1": 2, "FPT_TST": 3, "FPT_ITT.1": 2, "FPT_TST.1.1": 1, "FPT_TST.1.2": 1, "FPT_TST.1.3": 1, "FPT_TST.2": 1, "FPT_TDC": 1}, "FRU": {"FRU_FLT": 6, "FRU_FLT.2": 3}, "FTP": {"FTP_ITC": 12, "FTP_TRP.1": 2, "FTP_ITC.1": 6}}, "cc_claims": {"O": {"O.RND": 3, "O.AES": 1, "O.PACE_CHIP": 9}, "T": {"T.RND": 4}}, "vendor": {"NXP": {"NXP Semiconductors": 1}, "Infineon": {"Infineon": 1, "Infineon Technologies AG": 2}, "STMicroelectronics": {"STMicroelectronics": 1}}, "eval_facility": {"DeutscheTelekom": {"Deutsche Telekom Security": 135}}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 50, "AES128": 2, "AES-192": 1, "AES-256": 1}}, "DES": {"DES": {"DES": 2}, "3DES": {"TDES": 1, "TDEA": 1}}, "constructions": {"MAC": {"CMAC": 36, "CBC-MAC": 1}}}, "asymmetric_crypto": {"ECC": {"ECDH": {"ECDH": 5}, "ECDSA": {"ECDSA": 26}, "ECC": {"ECC": 10}}, "FF": {"DH": {"DH": 4, "Diffie-Hellman": 2}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 5}, "SHA2": {"SHA-256": 12, "SHA-384": 7, "SHA-512": 5, "SHA512": 1, "SHA-2": 2}}}, "crypto_scheme": {"MAC": {"MAC": 27}, "KA": {"Key agreement": 1, "Key Agreement": 1}}, "crypto_protocol": {"TLS": {"SSL": {"SSL": 1}}, "PACE": {"PACE": 99}}, "randomness": {"TRNG": {"TRNG": 1}, "RNG": {"RND": 7, "RNG": 46}}, "cipher_mode": {"ECB": {"ECB": 2}, "CBC": {"CBC": 5}}, "ecc_curve": {"NIST": {"P-256": 3, "P-384": 2, "NIST P-256": 1}, "Brainpool": {"brainpoolP256r1": 3, "brainpoolP384r1": 3, "brainpoolP512r1": 2}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"Leak-Inherent": 8, "Physical Probing": 2, "physical probing": 1, "Physical probing": 1, "SPA": 1, "DPA": 1}, "FI": {"physical tampering": 1, "Malfunction": 7, "malfunction": 6, "DFA": 1}, "other": {"Bleichenbacher attack": 1}}, "technical_report_id": {}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS186": 5, "FIPS 180-4": 1, "FIPS180": 2, "FIPS 197": 4, "FIPS197": 8, "FIPS PUB 180-4": 1, "FIPS PUB 186-4": 1}, "NIST": {"NIST SP 800-38B": 1, "SP 800-38A": 3}, "PKCS": {"PKCS#3": 3, "PKCS1": 3}, "BSI": {"AIS36": 4, "AIS31": 5, "AIS 31": 1, "AIS 36": 1}, "RFC": {"RFC5639": 8, "RFC3447": 7, "RFC 3447": 1, "RFC 5639": 1}, "ISO": {"ISO/IEC 18033-3": 3, "ISO/IEC 9797-1": 2}, "ICAO": {"ICAO": 2}, "CC": {"CCMB-2022-11-006": 2}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "cert_keywords": {"cc_cert_id": {"DE": {"BSI-DSZ-CC-0904-V3-2026": 1, "EUCC-3087-2026-0012": 1}}, "cc_protection_profile_id": {"BSI": {"BSI-CC-PP-0082-V4-2019": 1}}, "cc_security_level": {"EAL": {"EAL 2": 1, "EAL 4": 1}}, "cc_sar": {"ALC": {"ALC_FLR": 1, "ALC_DVS.2": 1, "ALC_FLR.1": 1}, "ATE": {"ATE_DPT.2": 1}, "AVA": {"AVA_VAN.5": 2, "AVA_VAN": 1}}, "cc_sfr": {}, "cc_claims": {}, "vendor": {}, "eval_facility": {"DeutscheTelekom": {"Deutsche Telekom Security": 1}, "SRC": {"SRC Security Research & Consulting": 1}}, "symmetric_crypto": {}, "asymmetric_crypto": {}, "pq_crypto": {}, "hash_function": {}, "crypto_scheme": {}, "crypto_protocol": {}, "randomness": {}, "cipher_mode": {}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "technical_report_id": {}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"ISO": {"ISO/IEC 15408": 2, "ISO/IEC 18045": 2}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "report_filename": "a3b3ac32-c987-405a-aeed-1ae8685f23db_en", "st_filename": "ac407808-1505-45cc-beb7-bc6a9b935aef_en", "cert_filename": "0e312e99-9cb1-4f06-9ae6-6ea8eb1e27d1_en"}, "heuristics": {"_type": "sec_certs.sample.cc_eucc_common.Heuristics", "extracted_versions": {"_type": "Set", "elements": ["2.0"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "cert_lab": ["BSI"], "cert_id": "EUCC-3087-2026-12", "prev_certificates": null, "next_certificates": null, "st_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "report_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "annotated_references": null, "extracted_sars": {"_type": "Set", "elements": [{"_type": "sec_certs.sample.sar.SAR", "family": "AGD_OPE", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_TDS", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_CMS", "level": 4}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_IMP", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_DPT", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_ARC", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_DVS", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_DEL", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_FUN", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_LCD", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "AVA_VAN", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_FSP", "level": 4}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_COV", "level": 3}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_CMC", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_FLR", "level": 3}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_FUN", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_INT", "level": 3}, {"_type": "sec_certs.sample.sar.SAR", "family": "AGD_PRE", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_TAT", "level": 3}]}, "direct_transitive_cves": null, "indirect_transitive_cves": null, "scheme_data": {"cert_id": "EUCC-3087-2026-0012", "product": "TCOS FlexCert Version 2.0 Release 2/SLC52", "vendor": "Deutsche Telekom Security GmbH", "certification_date": "2026-07-03", "category": "eHealth", "url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Gesundheitswesen_SmartCards/0904.html", "enhanced": {"product": "TCOS FlexCert Version 2.0 Release 2/SLC52", "applicant": "Deutsche Telekom Security GmbH Neue Adresse: Koblenzer Stra\u00dfe 87-93 57072 Siegen Alte Adresse: Untere Industriestra\u00dfe 20 57250 Netphen", "evaluation_facility": "SRC Security Research & Consulting GmbH", "assurance_level": "EAL4+,ALC_DVS.2,ATE_DPT.2,AVA_VAN.5,ALC_FLR.1", "protection_profile": "Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4-2019", "certification_date": "2026-07-03", "expiration_date": "2031-07-02", "entries": [{"id": "EUCC-3087-2026-0012 / BSI-DSZ-CC-0904-V3-2026 (Ausstellungsdatum / Certification Date 03.07.2026, g\u00fcltig bis / valid until 02.07.2031)", "description": "The focus of this re-certification was on the transfer of the certification procedure to CC/CEM:2022 and to EUCC. Included is the update of the product life-cycle concerning the involved development and production sites, the underlying HW-certificate as well as the vulnerability analysis andvaluation of the TOE's (crypto) implementation. The certified product itself including its related guidance documentation did not change."}, {"id": "BSI", "description": "The Partial ALC Re-Evaluation for BSI-DSZ-CC-0904-V2-2021 covers the update of the product life-cycle concerning the relocation of the involved development and production sites. The certified product itself did not change."}, {"id": "BSI-DSZ-CC-0904-V2-2021 (Ausstellungsdatum / Certification Date 24.06.2021, g\u00fcltig bis / valid until 23.06.2026) Zertifizierungsreport / Certification Report Sicherheitsvorgaben / Security Target Zertifikat / Certificate Im Fokus der vorliegenden Re-Zertifizierung stand die Anpassung des Evaluierungsgegenstandes (EVG) an die aktuelle Version der G2.1 COS-Spezifikation der gematik und das zugeh\u00f6rige \u00fcberarbeitete Schutzprofil PP-0082-V4. Dies war verbunden mit dem Wechsel des unterliegenden Halbleiters, Anpassungen im Lebenszyklusmodell, weiteren spezifischen \u00c4nderungen in der Embedded Software und einer entsprechenden Aktualisierung der zugeh\u00f6rigen Benutzerdokumentation. Insbesondere wurde die (Krypto-) Implementierung des EVG \u00fcberarbeitet, re-evaluiert und neu bewertet.", "description": "Software"}, {"id": "BSI", "description": "The maintenance procedure addresses the change of the production site."}, {"id": "BSI", "description": "Maintenance Report"}, {"id": "BSI", "description": "Security Target"}], "description": "The Target of Evaluation (TOE) is the product TCOS FlexCert 2.0 Release 1/SLE78CLX1440P developed by T-Systems International GmbH. The TOE is a smart card product according to the G2 Card Operating System specification from gematik. The TOE is intended to be used as a card operating system platform for different card types and applications of the card generation G2 in the framework of the German health care system. The TOE implements from the PP-0082-V2 the base part and the packages Crypto Box, Logical Channel and Contactless."}, "subcategory": "Smartcards"}, "protection_profiles": null, "eal": null}, "other_metadata": {"_type": "sec_certs.sample.eucc.EUCCCertificate.EnisaMetadata", "certificate_id": "EUCC-3087-2026-0012", "product_name": "TCOS FlexCert Version 2.0 Release 2/SLC52", "product_type": "Smartcards and similar devices", "product_version": "Refer to Table 1 in the Certification Report", "product_description": "The TOE is a smart card product according to the G2-COS specification from gematik and is implemented on the hardware platform Infineon Security Controller IFX_CCI_000010h (SLC52GDA600A8 / SLC52GDA600A9) from Infineon Technologies AG. The TOE is intended to be used as a card operating system platform for cards of the card generation G2 in the framework of the German health care system.", "holder_name": "Deutsche Telekom Security GmbH", "holder_address": "Koblenzer Stra\u00dfe 87-93, 57072 Siegen", "holder_contact": null, "holder_website": "https://www.telekom.com/en/company/data-privacy-and-security/hacking-and-testing", "certification_body": "BSI", "nando_id": "3087", "certification_body_address": "Postfach 200363\\n53133 Bonn, Bonn", "certification_body_contact": "zertdokus@bsi.bund.de Phone: +49 228 99 9582-0", "itsef": "SRC Security Research & Consulting GmbH", "responsible_ncca": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik", "scheme": "(UE) 2024/482 - EUCC", "report_reference": "EUCC-3087-2026-0012 Certificate Report", "assurance_level": "High", "cc_version": "CC:2022 Revision 1", "cem_version": "CEM:2022 Revision 1", "ava_van_level": "5", "package": {"EAL4": ["ALC_DVS.2", "ATE_DPT.2", "AVA_VAN.5", "ALC_FLR.1"]}, "protection_profile": "Common Criteria Protection Profile Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4-2019, Bundesamt f\u00fcr Sicherheit in der Informationstechnik (BSI)", "issuance_year": "2026", "issuance_month": "7", "issuance_date_full": "03/07/2026", "certificate_yearly_number": "EUCC-3087-2026-000012-I-00", "modification_or_reassurance": null, "validity_period_years": "5 years"}}