{"_id": "69fb2d0b33e3d387", "_type": "sec_certs.sample.eucc.EUCCCertificate", "dgst": "69fb2d0b33e3d387", "cert_id": "EUCC-3090-2026-0023", "category": "SMARTCARDS AND SIMILAR DEVICES", "name": "ST33J2M0 including optional cryptographic library NESLIB", "status": "active", "manufacturer": "STMICROELECTRONICS", "scheme": "FR", "security_level": {"_type": "Set", "elements": ["EAL5"]}, "not_valid_before": "2026-04-27", "not_valid_after": "2031-04-27", "report_link": "https://certification.enisa.europa.eu/document/download/f9781754-3db2-49d4-b747-69e994d3a446_en?filename=EUCC-3090-2026-23-rapport.pdf", "st_link": "https://certification.enisa.europa.eu/document/download/dfc91fca-61de-4916-8a7f-65c37590eb16_en?filename=EUCC-3090-2026-23-cible.pdf", "cert_link": "https://certification.enisa.europa.eu/document/download/8e60198f-9cd6-4949-a359-31ce044930fe_en?filename=EUCC-3090-2026-23-certificat.pdf", "manufacturer_web": "https://www.st.com/en/secure-mcus/st33j2m0.html", "protection_profile_links": null, "state": {"_type": "sec_certs.sample.cc_eucc_common.InternalState", "report": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "ad38b2b3f4a6d3ae7fcffd4e081878f30b4ab961e16424081cc2cff66b59e898", "txt_hash": "88b269f2769b54374853bdd51c5a3a7b9168813ca085a4d2e51492c6e0875016", "json_hash": null}, "st": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "25cc7cf1c51300c4ffb7054635455db50f2902a9ed6ee294d88559f695f3d572", "txt_hash": "d7ef1db6cdfb243bd52ac426f5475a36c6a1952967386601275ebd8eac7e4e19", "json_hash": null}, "cert": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "10549b3b7551a44156b91e0258ae7128e26d7f22c829ae11d9002227ef120bc6", "txt_hash": "f07fbba335de36cd068418e7c2d62f373af26ad70f900cf5d6a07050402ba4c4", "json_hash": null}}, "pdf_data": {"_type": "sec_certs.sample.cc_eucc_common.PdfData", "report_metadata": {"pdf_file_size_bytes": 893934, "pdf_is_encrypted": false, "pdf_number_of_pages": 18, "/Creator": "Acrobat PDFMaker 26 pour Word", "/Producer": "Docusign DMv10", "/CreationDate": "D:20260417170851+02'00'", "/ModDate": "D:20260427114332+00'00'", "pdf_hyperlinks": {"_type": "Set", "elements": ["mailto:psirt@st.com", "https://cyber.gouv.fr/cybersecurity-act", "https://www.cyber.gouv.fr/", "http://www.cofrac.fr/", "http://www.commoncriteriaportal.org/", "mailto:certification@ssi.gouv.fr", "https://www.ssi.gouv.fr/", "https://www.st.com/en/secure-mcus/st33j2m0.html", "https://www.st.com/content/st_com/en/about/security-and-privacy/psirt.html"]}}, "st_metadata": {"pdf_file_size_bytes": 2195278, "pdf_is_encrypted": false, "pdf_number_of_pages": 93, "/Author": "samantha rigaudie", "/CreationDate": "D:20251027110547Z", "/Creator": "FrameMaker 17.0.3", "/ModDate": "D:20251027113958+01'00'", "/Producer": "Adobe PDF Library 17.0", "/Title": "SMD_ST33J2M0_ST_19_004_F03_0P.pdf", "/Trapped": "/False", "pdf_hyperlinks": {"_type": "Set", "elements": ["http://www.st.com", "http://ed25519.cr.yp.to/ed25519-20110926.pdf", "http://ed25519.cr.yp.to/eddsa-20150704.pdf", "https://tools.ietf.org/html/draft-irtf-cfrg-eddsa-08"]}}, "cert_metadata": {"pdf_file_size_bytes": 353584, "pdf_is_encrypted": false, "pdf_number_of_pages": 2, "/Creator": "Acrobat PDFMaker 26 pour Word", "/Producer": "Docusign DMv10", "/CreationDate": "D:20260417171059+02'00'", "/ModDate": "D:20260427114332+00'00'", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://cyber.gouv.fr/", "mailto:psirt@st.com", "https://cyber.gouv.fr/cybersecurity-act", "https://www.st.com/content/st_com/en/about/security-and-privacy/psirt.html", "mailto:certification@ssi.gouv.fr", "https://www.st.com/en/secure-mcus/st33j2m0.html"]}}, "report_frontpage": {"FR": {}}, "st_frontpage": null, "cert_frontpage": null, "report_keywords": {"cc_cert_id": {"FR": {"EUCC-3090-2026-23": 4}}, "cc_protection_profile_id": {"BSI": {"BSI-CC-PP-0084-2014": 1, "BSI-PP- 0084-2014": 1}}, "cc_security_level": {"EAL": {"EAL5": 1, "EAL2": 4}}, "cc_sar": {"ADV": {"ADV_IMP.2": 1, "ADV_INT.3": 1, "ADV_TDS.5": 1}, "ALC": {"ALC_CMC.5": 1, "ALC_DVS.2": 1, "ALC_FLR.2": 3, "ALC_TAT.3": 1, "ALC_FLR": 2}, "ATE": {"ATE_COV.3": 1, "ATE_FUN.2": 1}, "AVA": {"AVA_VAN.5": 1, "AVA_VAN": 2}, "ASE": {"ASE_TSS.2": 1}}, "cc_sfr": {}, "cc_claims": {}, "vendor": {}, "eval_facility": {"Serma": {"SERMA": 1}, "CESTI": {"CESTI": 2}}, "symmetric_crypto": {"DES": {"DES": {"DES": 1}}}, "asymmetric_crypto": {}, "pq_crypto": {}, "hash_function": {}, "crypto_scheme": {}, "crypto_protocol": {}, "randomness": {}, "cipher_mode": {}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {"Neslib": {"NesLib 6.3": 1, "NesLib 6.3.4": 1}}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"Physical Probing": 1}, "FI": {"Malfunction": 1}}, "technical_report_id": {}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"BSI": {"AIS31": 4}, "ISO": {"ISO/IEC 15408-": 1, "ISO/IEC 15408:2022": 1, "ISO/IEC 18045:2022": 2}, "CC": {"CCMB-2022-11-001": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "st_keywords": {"cc_cert_id": {}, "cc_protection_profile_id": {"BSI": {"BSI-CC-PP-0084-2014": 69, "BSI-CC-PP- 0084-2014": 10, "BSI-CC-PP-0084-": 3}}, "cc_security_level": {"EAL": {"EAL5": 14, "EAL 5": 1, "EAL5+": 1, "EAL4": 1, "EAL5 augmented": 1, "EAL 5 augmented": 1}}, "cc_sar": {"ADV": {"ADV_FSP": 4, "ADV_IMP.2": 4, "ADV_INT.3": 4, "ADV_TDS.5": 4, "ADV_ARC.1": 2, "ADV_FSP.5": 3, "ADV_ARC": 2, "ADV_IMP": 1}, "AGD": {"AGD_PRE": 3, "AGD_OPE.1": 1, "AGD_PRE.1": 1, "AGD_OPE": 1}, "ALC": {"ALC_DEL": 3, "ALC_CMC.5": 4, "ALC_DVS.2": 5, "ALC_FLR.2": 6, "ALC_TAT.3": 4, "ALC_CMS.5": 1, "ALC_DEL.1": 1, "ALC_LCD.1": 1, "ALC_DVS": 1, "ALC_CMS": 1, "ALC_CMC": 1}, "ATE": {"ATE_COV": 3, "ATE_COV.3": 4, "ATE_FUN.2": 4, "ATE_DPT.3": 1, "ATE_IND.2": 1}, "AVA": {"AVA_VAN.5": 5, "AVA_VAN": 1}, "ASE": {"ASE_INT": 2, "ASE_CCL": 7, "ASE_ECD": 5, "ASE_SPD": 7, "ASE_OBJ": 11, "ASE_REQ": 34, "ASE_TSS": 11, "ASE_TSS.2": 6, "ASE_CCL.1": 1, "ASE_ECD.1": 1, "ASE_INT.1": 2, "ASE_OBJ.2": 1, "ASE_REQ.2": 1, "ASE_SPD.1": 1, "ASE_REQ.1": 1}}, "cc_sfr": {"FAU": {"FAU_SAR.1": 26, "FAU_SAS.1": 30, "FAU_SAS": 1, "FAU_GEN.1": 8}, "FCS": {"FCS_RNG.1": 9, "FCS_COP.1": 36, "FCS_CKM.1": 20, "FCS_CKM.4": 4, "FCS_CKM.6": 7, "FCS_CKM.6.1": 1, "FCS_CKM.5": 2, "FCS_RBG.1": 1}, "FDP": {"FDP_SDC.1": 9, "FDP_SDI.2": 14, "FDP_ITT.1": 10, "FDP_IFC.1": 17, "FDP_ACC.2": 12, "FDP_ACF.1": 28, "FDP_UCT.1": 16, "FDP_UIT.1": 16, "FDP_ACC.1": 23, "FDP_ACF": 1, "FDP_ITC.1": 2, "FDP_ITC.2": 2, "FDP_CKM.2": 1, "FDP_SMF.1": 2, "FDP_SMR.1": 1}, "FIA": {"FIA_API.1": 7, "FIA_UID.1": 16, "FIA_UAU.1": 14}, "FMT": {"FMT_LIM.1": 32, "FMT_LIM.2": 33, "FMT_MSA.3": 26, "FMT_MSA.1": 26, "FMT_SMF.1": 21, "FMT_SMR.1": 17}, "FPT": {"FPT_FLS.1": 22, "FPT_PHP.3": 11, "FPT_ITT.1": 9}, "FRU": {"FRU_FLT.2": 11}, "FTP": {"FTP_ITC.1": 27, "FTP_TRP.1": 2}}, "cc_claims": {"O": {"O.RND": 4, "O.TOE-": 2, "O.C": 3}, "T": {"T.RND": 3}, "R": {"R.O": 3}}, "vendor": {"Infineon": {"Infineon Technologies": 1}, "STMicroelectronics": {"STMicroelectronics": 26}, "GD": {"G+D": 1, "Giesecke+Devrient": 1}, "Philips": {"Philips": 1}}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 23, "AES-128": 1, "AES-192": 1, "AES-256": 1}}, "DES": {"DES": {"DES": 18}, "3DES": {"TDES": 9, "Triple-DES": 1, "TDEA": 1}}, "constructions": {"MAC": {"HMAC": 3, "CMAC": 3, "CBC-MAC": 2}}}, "asymmetric_crypto": {"ECC": {"ECDH": {"ECDH": 3}, "ECDSA": {"ECDSA": 4}, "EdDSA": {"EdDSA": 5}, "ECC": {"ECC": 5}}, "FF": {"DH": {"Diffie-Hellman": 11}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 17}, "SHA2": {"SHA-224": 3, "SHA-256": 7, "SHA-384": 5, "SHA-512": 5, "SHA-2": 5}, "SHA3": {"SHA-3": 8, "SHA3-224": 4, "SHA3-256": 4, "SHA3-384": 4, "SHA3-512": 4}}, "Keccak": {"Keccak": 14}, "SHAKE": {"SHAKE128": 4, "SHAKE256": 4}}, "crypto_scheme": {"KEM": {"KEM": 1}}, "crypto_protocol": {}, "randomness": {"TRNG": {"TRNG": 2}, "PRNG": {"DRBG": 10}, "RNG": {"RND": 7, "RNG": 6}}, "cipher_mode": {"ECB": {"ECB": 9}, "CBC": {"CBC": 10}, "GCM": {"GCM": 3}, "CCM": {"CCM": 3}}, "ecc_curve": {}, "crypto_engine": {"NesCrypt": {"Nescrypt": 7, "NESCRYPT": 3}}, "tls_cipher_suite": {}, "crypto_library": {"Neslib": {"NesLib 6.3.4": 2, "NesLib ": 9, "NesLib 320": 1, "NesLib 321": 1, "NesLib 324": 1, "NesLib 327": 1, "NesLib 331": 1, "NesLib 333": 1, "NesLib 334": 1, "NesLib 336": 1, "NesLib 337": 1, "NesLib 6.3": 2}}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"Leak-Inherent": 14, "Physical Probing": 4, "physical probing": 3, "side channel": 10}, "FI": {"physical tampering": 1, "Malfunction": 13, "malfunction": 2}, "other": {"JIL": 15}}, "technical_report_id": {}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS PUB 197": 4, "FIPS PUB 186-4": 4, "FIPS PUB 180-2": 5, "FIPS PUB 198-1": 3, "FIPS PUB 202": 6, "FIPS PUB 140-2": 5}, "NIST": {"NIST SP 800-67": 3, "SP 800-38A": 3, "NIST SP 800-38B": 2, "SP 800-38D": 1, "SP 800-38C": 1, "NIST SP 800-56A": 3, "NIST SP 800-90": 4, "NIST SP 800-38A": 2, "SP 800-67": 1, "NIST SP 800-38C": 1, "NIST SP 800-38D": 1, "SP 800-56A": 1}, "PKCS": {"PKCS1": 1, "PKCS #1": 6}, "BSI": {"AIS31": 2}, "ISO": {"ISO/IEC 7816-3": 1, "ISO/IEC 9796-2": 3, "ISO/IEC 14888": 2, "ISO/IEC 9796": 1}, "CC": {"CCMB-2022-11-002": 10, "CCMB-2022-11-003": 2, "CCMB-2017-04-002": 17, "CCMB-2022-11-001": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"OutOfScope": {"out of scope": 1, " 43 Note: The ES is not part of the TOE and is out of scope of the evaluation, except NesLib when it is embedded": 1, "number generation and RSA key pairs generation [3]. 43 Note: The ES is not part of the TOE and is out of scope of the evaluation, except NesLib when it is embedded. a. Note that SHA-1 is no longer recommended": 1}}}, "cert_keywords": {"cc_cert_id": {"FR": {"EUCC-3090-2026-23": 2}}, "cc_protection_profile_id": {"BSI": {"BSI-CC-PP-0084-2014": 1}}, "cc_security_level": {"EAL": {"EAL5": 1, "EAL2": 1}}, "cc_sar": {"ADV": {"ADV_IMP.2": 1, "ADV_INT.3": 1, "ADV_TDS.5": 1}, "ALC": {"ALC_CMC.5": 1, "ALC_DVS.2": 1, "ALC_FLR.2": 2, "ALC_TAT.3": 1}, "ATE": {"ATE_COV.3": 1, "ATE_FUN.2": 1}, "AVA": {"AVA_VAN.5": 1}, "ASE": {"ASE_TSS.2": 1}}, "cc_sfr": {}, "cc_claims": {}, "vendor": {}, "eval_facility": {"Serma": {"SERMA": 2}}, "symmetric_crypto": {}, "asymmetric_crypto": {}, "pq_crypto": {}, "hash_function": {}, "crypto_scheme": {}, "crypto_protocol": {}, "randomness": {}, "cipher_mode": {}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "technical_report_id": {}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"ISO": {"ISO/IEC 15408:2022": 2, "ISO/IEC 18045:2022": 2}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "report_filename": "f9781754-3db2-49d4-b747-69e994d3a446_en", "st_filename": "dfc91fca-61de-4916-8a7f-65c37590eb16_en", "cert_filename": "8e60198f-9cd6-4949-a359-31ce044930fe_en"}, "heuristics": {"_type": "sec_certs.sample.cc_eucc_common.Heuristics", "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "cert_lab": null, "cert_id": "EUCC-3090-2026-23", "prev_certificates": null, "next_certificates": null, "st_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "report_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "annotated_references": null, "extracted_sars": {"_type": "Set", "elements": [{"_type": "sec_certs.sample.sar.SAR", "family": "ASE_INT", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_CCL", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "AGD_OPE", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_TDS", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_DPT", "level": 3}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_IMP", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_ARC", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_FSP", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_DVS", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_DEL", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_LCD", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "AVA_VAN", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_COV", "level": 3}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_CMS", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_TSS", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_FLR", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_IND", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_OBJ", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_CMC", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_SPD", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_REQ", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_FUN", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_INT", "level": 3}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_ECD", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "AGD_PRE", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_TAT", "level": 3}]}, "direct_transitive_cves": null, "indirect_transitive_cves": null, "scheme_data": null, "protection_profiles": null, "eal": "EAL5"}, "other_metadata": {"_type": "sec_certs.sample.eucc.EUCCCertificate.EnisaMetadata", "certificate_id": "EUCC-3090-2026-0023", "product_name": "ST33J2M0 including optional cryptographic library NESLIB", "product_type": "Smartcards and similar devices", "product_version": "F03", "product_description": "The product evaluated is \"ST33J2M0 including optional cryptographic library NESLIB, F03\" developed by STMICROELECTRONICS. The microcontroller, by itself, is not a standalone product that can be used in its current state. It is designed to host one or more applications and may be embedded in a plastic support to form a smart card. This card has multiple uses (secure identity documents, banking applications, subscription television, transport, health, etc.) depending on the application software embedded in it. These software examples are not included in the scope of this evaluation.", "holder_name": "STMICROELECTRONICS", "holder_address": "190 Avenue Celestin Coq, 13106 Rousset", "holder_contact": "Psirt@st.com", "holder_website": "https://www.st.com/en/secure-mcus/st33j2m0.html", "certification_body": "ANSSI", "nando_id": "3090", "certification_body_address": "Tour Mercure 31 Quai de Grenelle, 75015 Paris", "certification_body_contact": "certification@ssi.gouv.fr Phone: +33 (0)1 71 75 82 82", "itsef": "Serma Safety and Security SAS", "responsible_ncca": "Agence nationale de la s\u00e9curit\u00e9 des syst\u00e8mes d\u2019information", "scheme": "(UE) 2024/482 - EUCC", "report_reference": "EUCC-3090-2026-23 Certification Report", "assurance_level": "High", "cc_version": "CC:2022 Revision 1", "cem_version": "CEM:2022 Revision 1", "ava_van_level": "5", "package": {"EAL5": ["ADV_IMP.2", "ADV_INT.3", "ADV_TDS.5", "ALC_CMC.5", "ALC_DVS.2", "ALC_FLR.2", "ALC_TAT.3", "ASE_TSS.2", "ATE_COV.3", "ATE_FUN.2", "AVA_VAN.5"]}, "protection_profile": "Security IC Platform Protection Profile with Augmentation Packages Version 1.0, 13 January 2014, BSI-CC-PP-0084-2014", "issuance_year": "2026", "issuance_month": "4", "issuance_date_full": "27/04/2026", "certificate_yearly_number": "EUCC-3090-2026-000023-I-00", "modification_or_reassurance": null, "validity_period_years": "5 years"}}