Infineon Technologies Security Controller M9900 A22/C22/D22, M9905 A11, M9906 A11

Certificate details

Certificate ID EUCC-3087-2026-04-0005
Product name Infineon Technologies Security Controller M9900 A22/C22/D22, M9905 A11, M9906 A11
Scheme 🇩🇪 DE
Assurance level high
Status active

Product Specification

Type Smartcard Controller
Description
The Target of Evaluation (TOE) is Infineon smart card IC (Security Controller) M9900 A22/C22/D22, M9905 A11, M9906 A11 with optional Software Librarie...
The Target of Evaluation (TOE) is Infineon smart card IC (Security Controller) M9900 A22/C22/D22, M9905 A11, M9906 A11 with optional Software Libraries EC, Toolbox, Base, and with specific IC dedicated software.
Version 7.1
Package EAL6 augmented with ALC_FLR.1 , ATE_SDP.1

Certificate holder

Name Infineon Technologies AG
Address Am Campeon 1-15, 85579 Neubiberg
Contact information [email protected]
Website https://www.infineon.com/product-information/cybersecurity-information

Certification body

Name BSI
NANDO ID 3087
Address Postfach 200363\n53133 Bonn, Bonn
Contact information [email protected] Phone: +49 228 99 9582-0

Standards & Compliance

CC Version CC:2022 Revision 1
CEM Version CEM:2022 Revision 1
AVA_VAN level 5
Certification report reference EUCC-3087-2026-04-0005 Certificate Report

Other

ITSEF TÜV Informationstechnik GmbH
Responsible NCCA Bundesamt für Sicherheit in der Informationstechnik
Protection profile Security IC Platform Protection Profile with Augmentation PackagesVersion 1.0, 13 January 2014, BSI-CC-PP-0084-2014
Certification date 13.04.2026
Archived date 13.04.2031

Certificate

Extracted keywords

Vendor
Infineon Technologies, Infineon Technologies AG

Security level
EAL 2, EAL 5
Security Assurance Requirements (SAR)
ALC_FLR, ALC_DVS.2, AVA_VAN.5, AVA_VAN
Protection profiles
BSI-CC-PP-0084-2014
Certificates
EUCC-3087-2026-04-0005
Evaluation facilities
TUV Informationstechnik

Certification report

Extracted keywords

Symmetric Algorithms
AES, Triple-DES, 3DES
Asymmetric Algorithms
ECDH, ECDSA, ECC
Schemes
Key Agreement
Randomness
RNG
Block cipher modes
ECB, CBC

Vendor
Infineon Technologies, Infineon Technologies AG, Infineon

Security level
EAL 2, EAL 5
Security Assurance Requirements (SAR)
ALC_FLR, ALC_DVS.2, AVA_VAN.5
Protection profiles
BSI-CC-PP-0084-2014
Certificates
EUCC-3087-2026-04-0005
Evaluation facilities
TÜV Informationstechnik

Side-channel analysis
physical probing, physical tampering
Certification process
“Security Target M9900/M9905/M9906 with optional ACL Software Libraries”, Infineon Technologies AG (confidential document) Security Target lite, Rev. 7.1, 2026-01-20, Public Security Target “Security Target Lite, Report, Version 4, 2026-03-02, EVALUATION TECHNICAL REPORT SUMMARY, TÜV Informationstechnik GmbH, (confidential document) [ETRfCOMP] „Evaluation Technical for Composite Evaluation (ETR COMP) for the M990x, Version 4, 2026-03-02, TÜV Informationstechnik GmbH, (confidential document) [CSCV] Cryptographic Standards Compliance Verification, Version 1, 2025-07- 07, TÜV, GmbH (confidential document) 19 / 21 Certification Report EUCC-3087-2026-04-0005 BSI-DSZ-CC-0827-V11-2026 C. Annexes List of

Technical reports
BSI TR-02102

Frontpage

Certificate ID BSI-DSZ-CC-0827-V11-2026
Certified item Infineon Technologies Security Controller M9900 A22/C22/D22, M9905 A11, M9906 A11
Certification lab BSI
Developer Infineon Technologies AG

Security target

Extracted keywords

Symmetric Algorithms
AES, DES, Triple-DES, 3DES, TDES, TDEA
Asymmetric Algorithms
ECDH, ECDSA, ECC, Diffie-Hellman, DSA
Schemes
Key Agreement
Randomness
TRNG, RNG, RND
Libraries
Crypto Library 38
Block cipher modes
ECB, CBC

Trusted Execution Environments
SSC
Vendor
Infineon Technologies, Infineon, Infineon Technologies AG

Security level
EAL5, EAL5+, EAL 5, EAL5 augmented, EAL 5 augmented
Claims
O.RND, T.RND
Security Assurance Requirements (SAR)
ADV_COMP.1, ADV_ARC.1, ADV_FSP.5, ADV_IMP.1, ADV_INT.2, ADV_TDS.4, ADV_FSP, ADV_FSP.4, ADV_TDS.3, AGD_OPE.1, AGD_PRE.1, ALC_DVS, ALC_DVS.2, ALC_TAT, ALC_CMC.4, ALC_CMS.5, ALC_DEL.1, ALC_LCD.1, ALC_TAT.2, ALC_CMS, ALC_CMS.4, ALC_TAT.1, ALC_DVS.1, ATE_COV.2, ATE_DPT.3, ATE_FUN.1, ATE_IND.2, ATE_DPT.2, ATE_DPT.1, AVA_VAN.5, AVA_VAN, ASE_INT, ASE_CCL, ASE_SPD, ASE_OBJ, ASE_ECD, ASE_REQ, ASE_TSS, ASE_CCL.1, ASE_ECD.1, ASE_INT.1, ASE_OBJ.2, ASE_REQ.2, ASE_SPD.1, ASE_TSS.1
Security Functional Requirements (SFR)
FAU_SAS, FAU_SAS.1, FAU_GEN, FAU_SAS.1.1, FCS_RNG, FCS_COP.1, FCS_CKM.1, FCS_COP, FCS_CKM.4, FCS_CKM.6, FCS_CKM.5, FCS_CKM, FCS_CKM.2, FCS_RNG.1, FCS_RBG.1, FCS_RNG.1.1, FCS_RNG.1.2, FDP_ACC.1, FDP_ACF.1, FDP_SDC, FDP_ITT.1, FDP_IFC.1, FDP_SDI.2, FDP_SDC.1, FDP_ACC.1.1, FDP_ACF.1.1, FDP_ACF.1.2, FDP_ACF.1.3, FDP_ACF.1.4, FDP_ITC.1, FDP_ITC.2, FDP_SDI.1, FDP_SDI.2.1, FDP_SDI.2.2, FDP_SDC.1.1, FDP_PHP.3, FMT_MSA.1, FMT_MSA.3, FMT_SMF, FMT_LIM.1, FMT_LIM.2, FMT_SMF.1, FMT_LIM, FMT_LIM.1.1, FMT_LIM.2.1, FMT_SMR.1, FMT_MSA.3.1, FMT_MSA.3.2, FMT_MSA.1.1, FMT_SMF.1.1, FPT_TST, FPT_TST.2, FPT_TST.1, FPT_TST.2.1, FPT_FLS.1, FPT_PHP.3, FPT_ITT.1, FPT_FLS, FRU_FLT.2
Protection profiles
BSI-CC-PP-0084-2014, BSI-PP-0084-, BSI-PP-0084-2014
Certificates
CC-1, CC-2, CC-3, CC-4, CC-5

Side-channel analysis
Leak-Inherent, Physical Probing, physical probing, side channel, Side-channel, SPA, DPA, Timing Attack, Malfunction, DFA, JIL
Certification process
out of scope, 3 The Toolbox libraries are additionally supporting software which is out of scope of this certification, ACL Software Libraries . 3 The Toolbox libraries are additionally supporting software which is out of scope of this certification. 4 The Toolbox libraries do not provide cryptographic support or additional

Standards
FIPS PUB 186-5, FIPS PUB 197, AIS31, RFC 5639, ISO/IEC 7816-3, ISO/IEC14443-3, CCMB-2022-11-001, CCMB-2022-11-002, CCMB-2022-11-003, CCMB-2022-11-004, CCMB-2022-11-005

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

Extracted SARs

ADV_ARC.1, ADV_COMP.1, ADV_FSP.5, ADV_IMP.1, ADV_INT.2, ADV_TDS.4, AGD_OPE.1, AGD_PRE.1, ALC_CMC.4, ALC_CMS.5, ALC_DEL.1, ALC_DVS.2, ALC_LCD.1, ALC_TAT.2, ASE_CCL.1, ASE_ECD.1, ASE_INT.1, ASE_OBJ.2, ASE_REQ.2, ASE_SPD.1, ASE_TSS.1, ATE_COV.2, ATE_DPT.3, ATE_FUN.1, ATE_IND.2, AVA_VAN.5

Similar certificates

Name Certificate ID Actions
Infineon Technologies Security Controller M9900 A22/C22/D22, M9905 A11, M9906 A11 EUCC-3087-2026-EUCC-3087-2026-04-0005-00000 Compare

Scheme data

Certificate ID BSI-DSZ-CC-0827-V10-2025
Product Infineon Technologies Security Controller M9905 A11 with optional ACL v2.07.003 and v2.09.002
Vendor Infineon Technologies AG
Certification Date 04.11.2025
Category Smart Cards and similar devices
URL https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/SmartCards_IC_Cryptolib/0827.html
Subcategory ICs, Cryptolib
Enhanced
Product Infineon Technologies Security Controller M9905 A11 with optional ACL v2.07.003 and v2.09.002
Applicant Infineon Technologies AG Melli-Beese-Str. 9 86159 Augsburg
Evaluation Facility TÜV Informationstechnik GmbH
Assurance Level EAL 5+,ALC_DVS.2,AVA_VAN.5
Protection Profile Security IC Platform Protection Profile, Version 1.0, 15 June 2007, BSI-CC-PP-0035-2007
Certification Date 04.11.2025
Expiration Date 03.11.2030
Certification history
BSI-DSZ-CC-0827-V10-2025 In comparison to the TOE forerunner, the CC version has been updated to version CC-2022. Moreover, the derivates M9900 A22/C22/D22/G11 and M9906 A11 were removed from the certification scope, and the scope of cryptographic functions has been reduced.
BSI-DSZ-CC-0827-V9-2024 In comparison to the TOE forerunner changes were conducted in TOE documentation (guidance), and the certification scope has been reduced.
BSI-DSZ-CC-0827-V8-2020 (Ausstellungsdatum / Certification Date 06.07.2020, gültig bis / valid until 05.07.2025) Certificate
BSI-DSZ-CC-0827-V7-2018 (Ausstellungsdatum / Certification Date 14.09.2018, gültig bis / valid until 13.09.2023) Certificate
BSI-DSZ-CC-0827-V6-2017 (Ausstellungsdatum / Certification Date 02.11.2017, gültig bis / valid until 01.11.2022) forerunner, the changes comprise the addition of new software library versions and change of the respective guidance documentations.
BSI design step. Furthermore, adjustments and changes in guidance documentations apply.
BSI-DSZ-CC-0827-V4-2016 (Ausstellungsdatum / Certification Date 23.11.2016, gültig bis / valid until 22.11.2021) The changes, compared to the preceding certification, consist of addition of a new configuration as well as addition of optional software libraries.
BSI-DSZ-CC-0827-V3-2015 (Ausstellungsdatum / Certification Date 03.11.2015, gültig bis / valid until 02.11.2020) Security Target
BSI-DSZ-CC-0827-V2-2014 (30.04.2014) Zertifizierungsreport / Certification Report Sicherheitsvorgaben / Security Target in Taiwan.
BSI-DSZ-CC-0827-2013-MA-01 (19.06.2013) dedicated software
BSI Security Target
Report Link https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte08/0827V10c_pdf.pdf?__blob=publicationFile&v=2
Target Link https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte08/0827V10b_pdf.pdf?__blob=publicationFile&v=2
Description The Target of Evaluation (TOE) is Infineon smart card IC (Security Controller) M9900 A21 with optional Software Libraries RSA2048 v1.03.006 – RSA4096 v1.03.006 – EC v1.03.006 – Toolbox v1.03.006 – FTL v1.01.0008 and with specific IC dedicated software. The TOE provides a real 32-bit CPU-architecture and is compatible to the ARMv7-M instruction set. The major components of the core system are the 32-bit CPU (Central Processing Unit), the Cache system, the MPU (Memory Protection Unit) and MED (Memory Encryption/Decryption Unit. The TOE consists of the hardware part, the firmware parts and the software parts. The software parts are differentiated into: the cryptographic libraries RSA and EC and the supporting libraries Toolbox, Base and FTL. RSA, EC, Toolbox, and FTL provide certain functionality to the Smartcard Embedded Software. This TOE is intended to be used in smart cards for particularly security relevant applications and for its previous use as developing platform for smart card operating systems. The term Smartcard Embedded Software is used in the following for all operating systems and applications stored and executed on the TOE. The TOE is the platform for the Smartcard Embedded Software.

Processing updates

Feed
  • The certificate became unavailable — it disappeared from the upstream listing.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.eucc.EUCCCertificate",
  "category": "SMARTCARD CONTROLLER",
  "cert_id": "EUCC-3087-2026-04-0005",
  "cert_link": "https://certification.enisa.europa.eu/document/download/b67badb4-d3dd-461a-8db8-323cff4b1322_en?filename=EUCC-3087-2026-04-0005%20Certificate.pdf",
  "dgst": "1b7823d66bdf1cff",
  "heuristics": {
    "_type": "sec_certs.sample.cc_eucc_common.Heuristics",
    "annotated_references": null,
    "cert_id": "EUCC-3087-2026-5",
    "cert_lab": [
      "BSI"
    ],
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "eal": null,
    "extracted_sars": {
      "_type": "Set",
      "elements": [
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_INT",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_CCL",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AGD_OPE",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_FUN",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_DPT",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_COV",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_TAT",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_ARC",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_FSP",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_DVS",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_DEL",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_CMC",
          "level": 4
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_LCD",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AVA_VAN",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_IMP",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_TDS",
          "level": 4
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_CMS",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_IND",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_OBJ",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_SPD",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_REQ",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_COMP",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_ECD",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AGD_PRE",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_TSS",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_INT",
          "level": 2
        }
      ]
    },
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "next_certificates": null,
    "prev_certificates": null,
    "protection_profiles": null,
    "related_cves": null,
    "report_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "scheme_data": {
      "category": "Smart Cards and similar devices",
      "cert_id": "BSI-DSZ-CC-0827-V10-2025",
      "certification_date": "2025-11-04",
      "enhanced": {
        "applicant": "Infineon Technologies AG Melli-Beese-Str. 9 86159 Augsburg",
        "assurance_level": "EAL 5+,ALC_DVS.2,AVA_VAN.5",
        "certification_date": "2025-11-04",
        "description": "The Target of Evaluation (TOE) is Infineon smart card IC (Security Controller) M9900 A21 with optional Software Libraries RSA2048 v1.03.006 \u2013 RSA4096 v1.03.006 \u2013 EC v1.03.006 \u2013 Toolbox v1.03.006 \u2013 FTL v1.01.0008 and with specific IC dedicated software. The TOE provides a real 32-bit CPU-architecture and is compatible to the ARMv7-M instruction set. The major components of the core system are the 32-bit CPU (Central Processing Unit), the Cache system, the MPU (Memory Protection Unit) and MED (Memory Encryption/Decryption Unit. The TOE consists of the hardware part, the firmware parts and the software parts. The software parts are differentiated into: the cryptographic libraries RSA and EC and the supporting libraries Toolbox, Base and FTL. RSA, EC, Toolbox, and FTL provide certain functionality to the Smartcard Embedded Software. This TOE is intended to be used in smart cards for particularly security relevant applications and for its previous use as developing platform for smart card operating systems. The term Smartcard Embedded Software is used in the following for all operating systems and applications stored and executed on the TOE. The TOE is the platform for the Smartcard Embedded Software.",
        "entries": [
          {
            "description": "In comparison to the TOE forerunner, the CC version has been updated to version CC-2022. Moreover, the derivates M9900 A22/C22/D22/G11 and M9906 A11 were removed from the certification scope, and the scope of cryptographic functions has been reduced.",
            "id": "BSI-DSZ-CC-0827-V10-2025"
          },
          {
            "description": "In comparison to the TOE forerunner changes were conducted in TOE documentation (guidance), and the certification scope has been reduced.",
            "id": "BSI-DSZ-CC-0827-V9-2024"
          },
          {
            "description": "Certificate",
            "id": "BSI-DSZ-CC-0827-V8-2020 (Ausstellungsdatum / Certification Date 06.07.2020, g\u00fcltig bis / valid until 05.07.2025)"
          },
          {
            "description": "Certificate",
            "id": "BSI-DSZ-CC-0827-V7-2018 (Ausstellungsdatum / Certification Date 14.09.2018, g\u00fcltig bis / valid until 13.09.2023)"
          },
          {
            "description": "forerunner, the changes comprise the addition of new software library versions and change of the respective guidance documentations.",
            "id": "BSI-DSZ-CC-0827-V6-2017 (Ausstellungsdatum / Certification Date 02.11.2017, g\u00fcltig bis / valid until 01.11.2022)"
          },
          {
            "description": "design step. Furthermore, adjustments and changes in guidance documentations apply.",
            "id": "BSI"
          },
          {
            "description": "The changes, compared to the preceding certification, consist of addition of a new configuration as well as addition of optional software libraries.",
            "id": "BSI-DSZ-CC-0827-V4-2016 (Ausstellungsdatum / Certification Date 23.11.2016, g\u00fcltig bis / valid until 22.11.2021)"
          },
          {
            "description": "Security Target",
            "id": "BSI-DSZ-CC-0827-V3-2015 (Ausstellungsdatum / Certification Date 03.11.2015, g\u00fcltig bis / valid until 02.11.2020)"
          },
          {
            "description": "in Taiwan.",
            "id": "BSI-DSZ-CC-0827-V2-2014 (30.04.2014) Zertifizierungsreport / Certification Report Sicherheitsvorgaben / Security Target"
          },
          {
            "description": "dedicated software",
            "id": "BSI-DSZ-CC-0827-2013-MA-01 (19.06.2013)"
          },
          {
            "description": "Security Target",
            "id": "BSI"
          }
        ],
        "evaluation_facility": "T\u00dcV Informationstechnik GmbH",
        "expiration_date": "2030-11-03",
        "product": "Infineon Technologies Security Controller M9905 A11 with optional ACL v2.07.003 and v2.09.002",
        "protection_profile": "Security IC Platform Protection Profile, Version 1.0, 15 June 2007, BSI-CC-PP-0035-2007",
        "report_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte08/0827V10c_pdf.pdf?__blob=publicationFile\u0026v=2",
        "target_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte08/0827V10b_pdf.pdf?__blob=publicationFile\u0026v=2"
      },
      "product": "Infineon Technologies Security Controller M9905 A11 with optional ACL v2.07.003 and v2.09.002",
      "subcategory": "ICs, Cryptolib",
      "url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/SmartCards_IC_Cryptolib/0827.html",
      "vendor": "Infineon Technologies AG"
    },
    "st_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "verified_cpe_matches": null
  },
  "manufacturer": "Infineon Technologies AG",
  "manufacturer_web": "https://www.infineon.com/product-information/cybersecurity-information",
  "name": "Infineon Technologies Security Controller M9900 A22/C22/D22, M9905 A11, M9906 A11",
  "not_valid_after": "2031-04-13",
  "not_valid_before": "2026-04-13",
  "other_metadata": {
    "_type": "sec_certs.sample.eucc.EUCCCertificate.EnisaMetadata",
    "assurance_level": "High",
    "ava_van_level": "5",
    "cc_version": "CC:2022 Revision 1",
    "cem_version": "CEM:2022 Revision 1",
    "certificate_id": "EUCC-3087-2026-04-0005",
    "certificate_yearly_number": "EUCC-3087-2026-000005-I-00",
    "certification_body": "BSI",
    "certification_body_address": "Postfach 200363\\n53133 Bonn, Bonn",
    "certification_body_contact": "[email protected] Phone: +49 228 99 9582-0",
    "holder_address": "Am Campeon 1-15, 85579 Neubiberg",
    "holder_contact": "[email protected]",
    "holder_name": "Infineon Technologies AG",
    "holder_website": "https://www.infineon.com/product-information/cybersecurity-information",
    "issuance_date_full": "13/04/2026",
    "issuance_month": "4",
    "issuance_year": "2026",
    "itsef": "T\u00dcV Informationstechnik GmbH",
    "modification_or_reassurance": null,
    "nando_id": "3087",
    "package": {
      "EAL6": [
        "ALC_FLR.1",
        "ATE_SDP.1"
      ]
    },
    "product_description": "The Target of Evaluation (TOE) is Infineon smart card IC (Security Controller) M9900 A22/C22/D22, M9905 A11, M9906 A11 with optional Software Libraries EC, Toolbox, Base, and with specific IC dedicated software.",
    "product_name": "Infineon Technologies Security Controller M9900 A22/C22/D22, M9905 A11, M9906 A11",
    "product_type": "Smartcard Controller",
    "product_version": "7.1",
    "protection_profile": "Security IC Platform Protection Profile with Augmentation PackagesVersion 1.0, 13 January 2014, BSI-CC-PP-0084-2014",
    "report_reference": "EUCC-3087-2026-04-0005 Certificate Report",
    "responsible_ncca": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
    "scheme": "(UE) 2024/482 - EUCC",
    "validity_period_years": "5 years"
  },
  "pdf_data": {
    "_type": "sec_certs.sample.cc_eucc_common.PdfData",
    "cert_filename": "b67badb4-d3dd-461a-8db8-323cff4b1322_en",
    "cert_frontpage": null,
    "cert_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {
        "DE": {
          "EUCC-3087-2026-04-0005": 1
        }
      },
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP-0084-2014": 1
        }
      },
      "cc_sar": {
        "ALC": {
          "ALC_DVS.2": 1,
          "ALC_FLR": 1
        },
        "AVA": {
          "AVA_VAN": 1,
          "AVA_VAN.5": 2
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 2": 1,
          "EAL 5": 1
        }
      },
      "cc_sfr": {},
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {
        "TUV": {
          "TUV Informationstechnik": 1
        }
      },
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {},
      "standard_id": {
        "ISO": {
          "ISO/IEC 15408": 2,
          "ISO/IEC 18045": 2
        }
      },
      "symmetric_crypto": {},
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Infineon": {
          "Infineon Technologies": 1,
          "Infineon Technologies AG": 1
        }
      },
      "vulnerability": {}
    },
    "cert_metadata": {
      "/CreationDate": "D:20260416085025+01\u002700\u0027",
      "/Creator": "BSI00021016",
      "/ModDate": "D:20260416085025+01\u002700\u0027",
      "/Producer": "KONICA MINOLTA bizhub C308",
      "/Title": "SBSI000210126041608500",
      "pdf_file_size_bytes": 113523,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 2
    },
    "report_filename": "296c499c-288f-4a53-becd-6e5bef519f99_en",
    "report_frontpage": {
      "DE": {
        "cert_id": "BSI-DSZ-CC-0827-V11-2026",
        "cert_item": "Infineon Technologies Security Controller M9900 A22/C22/D22, M9905 A11, M9906 A11",
        "cert_lab": "BSI",
        "developer": "Infineon Technologies AG",
        "match_rules": [
          "(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)"
        ]
      }
    },
    "report_keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 2
          },
          "ECDH": {
            "ECDH": 1
          },
          "ECDSA": {
            "ECDSA": 1
          }
        }
      },
      "cc_cert_id": {
        "DE": {
          "EUCC-3087-2026-04-0005": 21
        }
      },
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP-0084-2014": 3
        }
      },
      "cc_sar": {
        "ALC": {
          "ALC_DVS.2": 1,
          "ALC_FLR": 2
        },
        "AVA": {
          "AVA_VAN.5": 2
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 2": 2,
          "EAL 5": 1
        }
      },
      "cc_sfr": {},
      "certification_process": {
        "ConfidentialDocument": {
          "GmbH (confidential document) 19 / 21 Certification Report EUCC-3087-2026-04-0005 BSI-DSZ-CC-0827-V11-2026 C. Annexes List of": 1,
          "Report, Version 4, 2026-03-02, EVALUATION TECHNICAL REPORT SUMMARY, T\u00dcV Informationstechnik GmbH, (confidential document) [ETRfCOMP] \u201eEvaluation Technical for Composite Evaluation (ETR COMP) for the M990x": 1,
          "Version 4, 2026-03-02, T\u00dcV Informationstechnik GmbH, (confidential document) [CSCV] Cryptographic Standards Compliance Verification, Version 1, 2025-07- 07, T\u00dcV": 1,
          "\u201cSecurity Target M9900/M9905/M9906 with optional ACL Software Libraries\u201d, Infineon Technologies AG (confidential document) Security Target lite, Rev. 7.1, 2026-01-20, Public Security Target \u201cSecurity Target Lite": 1
        }
      },
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "ECB": {
          "ECB": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {
        "TUV": {
          "T\u00dcV Informationstechnik": 8
        }
      },
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RNG": 2
        }
      },
      "side_channel_analysis": {
        "FI": {
          "physical tampering": 1
        },
        "SCA": {
          "physical probing": 1
        }
      },
      "standard_id": {
        "BSI": {
          "AIS31": 1
        },
        "FIPS": {
          "FIPS186-4": 1,
          "FIPS186-5": 5,
          "FIPS197": 1
        },
        "ISO": {
          "ISO/IEC 15408": 2,
          "ISO/IEC 17065": 2,
          "ISO/IEC 18045": 2
        },
        "RFC": {
          "RFC5639": 6
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 3
          }
        },
        "DES": {
          "3DES": {
            "3DES": 1,
            "Triple-DES": 2
          }
        }
      },
      "technical_report_id": {
        "BSI": {
          "BSI TR-02102": 1
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Infineon": {
          "Infineon": 2,
          "Infineon Technologies": 8,
          "Infineon Technologies AG": 7
        }
      },
      "vulnerability": {}
    },
    "report_metadata": {
      "/CreationDate": "D:20260518145212+02\u002700\u0027",
      "/Creator": "Writer",
      "/Keywords": "Common Criteria, Certification, Zertifizierung",
      "/Producer": "LibreOffice 5.3",
      "/Title": "Certification Report EUCC-3087-2026-04-0005",
      "pdf_file_size_bytes": 439520,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://www.iso.org/standard/72917.html",
          "https://www.iso.org/standard/72892.html",
          "https://www.bsi.bund.de/zertifizierungsreporte",
          "https://www.iso.org/standard/72906.html",
          "https://www.commoncriteriaportal.org/",
          "http://www.commoncriteriaportal.org/",
          "https://www.iso.org/standard/72891.html",
          "https://www.bsi.bund.de/AIS",
          "https://www.iso.org/standard/72889.html",
          "https://www.bsi.bund.de/",
          "https://certification.enisa.europa.eu/publications/eucc-state-art-documents_en",
          "https://eur-lex.europa.eu/eli/reg_impl/2025/2462/oj",
          "https://www.bsi.bund.de/zertifizierung",
          "https://www.iso.org/standard/72913.html"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 21
    },
    "st_filename": "e1cbb7f9-7c58-46f8-a2a2-22013f9cc0ea_en",
    "st_frontpage": null,
    "st_keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 39
          },
          "ECDH": {
            "ECDH": 5
          },
          "ECDSA": {
            "ECDSA": 12
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 6
          },
          "DSA": {
            "DSA": 2
          }
        }
      },
      "cc_cert_id": {
        "NL": {
          "CC-1": 4,
          "CC-2": 19,
          "CC-3": 3,
          "CC-4": 2,
          "CC-5": 2
        }
      },
      "cc_claims": {
        "O": {
          "O.RND": 1
        },
        "T": {
          "T.RND": 1
        }
      },
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP-0084-2014": 2,
          "BSI-PP-0084-": 1,
          "BSI-PP-0084-2014": 1
        }
      },
      "cc_sar": {
        "ADV": {
          "ADV_ARC.1": 2,
          "ADV_COMP.1": 1,
          "ADV_FSP": 1,
          "ADV_FSP.4": 1,
          "ADV_FSP.5": 2,
          "ADV_IMP.1": 2,
          "ADV_INT.2": 2,
          "ADV_TDS.3": 1,
          "ADV_TDS.4": 2
        },
        "AGD": {
          "AGD_OPE.1": 2,
          "AGD_PRE.1": 1
        },
        "ALC": {
          "ALC_CMC.4": 1,
          "ALC_CMS": 1,
          "ALC_CMS.4": 1,
          "ALC_CMS.5": 3,
          "ALC_DEL.1": 1,
          "ALC_DVS": 1,
          "ALC_DVS.1": 1,
          "ALC_DVS.2": 9,
          "ALC_LCD.1": 1,
          "ALC_TAT": 2,
          "ALC_TAT.1": 1,
          "ALC_TAT.2": 3
        },
        "ASE": {
          "ASE_CCL": 3,
          "ASE_CCL.1": 1,
          "ASE_ECD": 2,
          "ASE_ECD.1": 1,
          "ASE_INT": 3,
          "ASE_INT.1": 1,
          "ASE_OBJ": 2,
          "ASE_OBJ.2": 1,
          "ASE_REQ": 3,
          "ASE_REQ.2": 1,
          "ASE_SPD": 2,
          "ASE_SPD.1": 1,
          "ASE_TSS": 2,
          "ASE_TSS.1": 1
        },
        "ATE": {
          "ATE_COV.2": 1,
          "ATE_DPT.1": 1,
          "ATE_DPT.2": 1,
          "ATE_DPT.3": 4,
          "ATE_FUN.1": 1,
          "ATE_IND.2": 1
        },
        "AVA": {
          "AVA_VAN": 1,
          "AVA_VAN.5": 11
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 5": 4,
          "EAL 5 augmented": 3,
          "EAL5": 7,
          "EAL5 augmented": 3,
          "EAL5+": 1
        }
      },
      "cc_sfr": {
        "FAU": {
          "FAU_GEN": 1,
          "FAU_SAS": 5,
          "FAU_SAS.1": 8,
          "FAU_SAS.1.1": 1
        },
        "FCS": {
          "FCS_CKM": 9,
          "FCS_CKM.1": 19,
          "FCS_CKM.2": 4,
          "FCS_CKM.4": 3,
          "FCS_CKM.5": 17,
          "FCS_CKM.6": 17,
          "FCS_COP": 32,
          "FCS_COP.1": 22,
          "FCS_RBG.1": 4,
          "FCS_RNG": 4,
          "FCS_RNG.1": 13,
          "FCS_RNG.1.1": 1,
          "FCS_RNG.1.2": 1
        },
        "FDP": {
          "FDP_ACC.1": 22,
          "FDP_ACC.1.1": 1,
          "FDP_ACF.1": 19,
          "FDP_ACF.1.1": 1,
          "FDP_ACF.1.2": 1,
          "FDP_ACF.1.3": 1,
          "FDP_ACF.1.4": 1,
          "FDP_IFC.1": 14,
          "FDP_ITC.1": 10,
          "FDP_ITC.2": 10,
          "FDP_ITT.1": 11,
          "FDP_PHP.3": 1,
          "FDP_SDC": 1,
          "FDP_SDC.1": 6,
          "FDP_SDC.1.1": 1,
          "FDP_SDI.1": 1,
          "FDP_SDI.2": 13,
          "FDP_SDI.2.1": 1,
          "FDP_SDI.2.2": 1
        },
        "FMT": {
          "FMT_LIM": 2,
          "FMT_LIM.1": 13,
          "FMT_LIM.1.1": 1,
          "FMT_LIM.2": 12,
          "FMT_LIM.2.1": 1,
          "FMT_MSA.1": 17,
          "FMT_MSA.1.1": 1,
          "FMT_MSA.3": 19,
          "FMT_MSA.3.1": 1,
          "FMT_MSA.3.2": 1,
          "FMT_SMF": 1,
          "FMT_SMF.1": 14,
          "FMT_SMF.1.1": 1,
          "FMT_SMR.1": 6
        },
        "FPT": {
          "FPT_FLS": 1,
          "FPT_FLS.1": 17,
          "FPT_ITT.1": 13,
          "FPT_PHP.3": 14,
          "FPT_TST": 5,
          "FPT_TST.1": 12,
          "FPT_TST.2": 36,
          "FPT_TST.2.1": 2
        },
        "FRU": {
          "FRU_FLT.2": 7
        }
      },
      "certification_process": {
        "OutOfScope": {
          " 3 The Toolbox libraries are additionally supporting software which is out of scope of this certification": 1,
          "ACL Software Libraries . 3 The Toolbox libraries are additionally supporting software which is out of scope of this certification. 4 The Toolbox libraries do not provide cryptographic support or additional": 1,
          "out of scope": 1
        }
      },
      "cipher_mode": {
        "CBC": {
          "CBC": 4
        },
        "ECB": {
          "ECB": 4
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "Generic": {
          "Crypto Library 38": 1
        }
      },
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 3
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RND": 2,
          "RNG": 11
        },
        "TRNG": {
          "TRNG": 14
        }
      },
      "side_channel_analysis": {
        "FI": {
          "DFA": 5,
          "Malfunction": 8
        },
        "SCA": {
          "DPA": 5,
          "Leak-Inherent": 7,
          "Physical Probing": 2,
          "SPA": 4,
          "Side-channel": 1,
          "Timing Attack": 1,
          "physical probing": 1,
          "side channel": 5
        },
        "other": {
          "JIL": 2
        }
      },
      "standard_id": {
        "BSI": {
          "AIS31": 6
        },
        "CC": {
          "CCMB-2022-11-001": 2,
          "CCMB-2022-11-002": 2,
          "CCMB-2022-11-003": 2,
          "CCMB-2022-11-004": 2,
          "CCMB-2022-11-005": 1
        },
        "FIPS": {
          "FIPS PUB 186-5": 1,
          "FIPS PUB 197": 1
        },
        "ISO": {
          "ISO/IEC 7816-3": 1,
          "ISO/IEC14443-3": 1
        },
        "RFC": {
          "RFC 5639": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 21
          }
        },
        "DES": {
          "3DES": {
            "3DES": 12,
            "TDEA": 1,
            "TDES": 1,
            "Triple-DES": 3
          },
          "DES": {
            "DES": 5
          }
        }
      },
      "technical_report_id": {},
      "tee_name": {
        "IBM": {
          "SSC": 4
        }
      },
      "tls_cipher_suite": {},
      "vendor": {
        "Infineon": {
          "Infineon": 8,
          "Infineon Technologies": 7,
          "Infineon Technologies AG": 13
        }
      },
      "vulnerability": {}
    },
    "st_metadata": {
      "/Author": "infineon",
      "/Keywords": "Infineon",
      "/Subject": "Infineon",
      "pdf_file_size_bytes": 1290239,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "mailto:[email protected]",
          "http://www.ietf.org/rfc/rfc5639.txt",
          "http://www.infineon.com/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 65
    }
  },
  "protection_profile_links": null,
  "report_link": "https://certification.enisa.europa.eu/document/download/296c499c-288f-4a53-becd-6e5bef519f99_en?filename=EUCC-3087-2026-04-0005%20Certification%20Report.pdf",
  "scheme": "DE",
  "security_level": {
    "_type": "Set",
    "elements": []
  },
  "st_link": "https://certification.enisa.europa.eu/document/download/e1cbb7f9-7c58-46f8-a2a2-22013f9cc0ea_en?filename=EUCC-3087-2026-04-0005%20Security%20Target.pdf",
  "state": {
    "_type": "sec_certs.sample.cc_eucc_common.InternalState",
    "cert": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "1aa82d0862592647ae3d75daa0c262b02472aba26ad718df43a374eb392201c3",
      "txt_hash": "2a515708708111c064dcdc3f1f7f4fc65329d78a8ce04070e0b6c7c9cb5b69d9"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "7482ec713af12531f34737a6758b3a653e6b4e5a44e0754340aefab353cd7dbb",
      "txt_hash": "4fe806f42c0475580cb06664193943ed338755854782d1ec1d9870c8fab34e96"
    },
    "st": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "a36ab73631d9d17b2bcd6c91e5e1d171f870f88be8a589eb9ccf11278b55691a",
      "txt_hash": "ae66ebbb02bdfe1aa9b4356783ab06242369a73768855359dbce90692c863986"
    }
  },
  "status": "active"
}