Conexa 3.0

Certificate details

Certificate ID EUCC-3087-2026-000014-I-00
Product name Conexa 3.0
Scheme 🇩🇪 DE
Assurance level high
Status active

Product Specification

Type Smart Meter Gateway
Description
The Target of Evaluation (TOE) is the Smart Meter Gateway (SMGW) CONEXA 3.0, Version 1.8. The Smart Meter Gateway is the communication unit in a smart...
The Target of Evaluation (TOE) is the Smart Meter Gateway (SMGW) CONEXA 3.0, Version 1.8. The Smart Meter Gateway is the communication unit in a smart metering system. The main functionality of the gateway is the reception and the storage of measured consumption and status values of the connected meters as well as the processing and the transfer of these consumption and status  values to authorized entities.
Version Version 1.8
Package EAL4

Certificate holder

Name Theben Smart Energy GmbH
Address Schlossfeld 9, 72401 Haigerloch, Germany
Contact information [email protected]
Website https://www.theben-se.de/conexa/cyber-security-info

Certification body

Name BSI
NANDO ID 3087
Address Postfach 200363\n53133 Bonn, Bonn
Contact information [email protected] Phone: +49 228 99 9582-0

Standards & Compliance

CC Version CC:2022 Revision 1
CEM Version None
AVA_VAN level 5
Certification report reference None

Other

ITSEF TÜV Informationstechnik GmbH
Responsible NCCA Bundesamt für Sicherheit in der Informationstechnik
Protection profile Protection Profile for the Gateway of a Smart Metering System, Version 1.3, 31 March 2014, BSI-CC-PP-0073-2014
Certification date 31.07.2026
Archived date 31.07.2031

Certificate

Extracted keywords

Security level
EAL 2, EAL 4
Security Assurance Requirements (SAR)
ALC_FLR, ALC_FLR.2, AVA_VAN.5, AVA_VAN
Protection profiles
BSI-CC-PP-0073-2014
Certificates
BSI-DSZ-CC-0918-V9-2026, EUCC-3087-2026-0014
Evaluation facilities
TÜV Informationstechnik

Certification report

certification report could not be downloaded, no link is available.

Security target

Extracted keywords

Symmetric Algorithms
AES
Asymmetric Algorithms
ECDSA, ECC, Diffie-Hellman
Hash functions
SHA-256, SHA-384
Schemes
MAC
Protocols
TLS, TLS 1.2
Randomness
PRNG, RNG
Block cipher modes
GCM
TLS cipher suites
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384

Security level
EAL 4, EAL4, EAL 4 augmented, EAL4 augmented
Claims
OE.SM, OSP.SM
Security Assurance Requirements (SAR)
ADV_ARC.1, ADV_IMP.1, ADV_FSP.4, ADV_TDS.3, AGD_OPE.1, AGD_PRE.1, ALC_DEL.1, ALC_FLR.2, ALC_CMC.4, ALC_LCD.1, ALC_CMS.4, ALC_DVS.1, ALC_TAT.1, ATE_COV.2, ATE_FUN.1, ATE_DPT.1, ATE_IND.2, AVA_VAN.5, ASE_CCL.1, ASE_INT.1, ASE_REQ.2, ASE_TSS.1, ASE_ECD.1, ASE_OBJ.2, ASE_REQ.1, ASE_SPD.1
Security Functional Requirements (SFR)
FAU_ARP, FAU_GEN, FAU_SAA, FAU_SAR, FAU_STG, FAU_GEN.2, FAU_STG.3, FAU_ARP.1, FAU_SAA.1, FAU_GEN.1, FAU_SAR.1, FAU_STG.5, FAU_STG.4, FAU_STG.2, FAU_GEN.2.1, FAU_STG.3.1, FAU_STG.3.2, FAU_STG.3.3, FCO_NRO, FCO_NRO.2, FCO_NRO.2.1, FCO_NRO.2.2, FCO_NRO.2.3, FCO_NRO.1, FCS_RNG.1, FCS_CKM.1, FCS_CKM, FCS_COP, FCS_CKM.6, FCS_CKM.2, FCS_CKM.5, FCS_COP.1, FCS_RBG.1, FCS_COP.1.1, FCS_CKM.6.1, FCS_CKM.6.2, FCS_CKM.4, FDP_IFC, FDP_ACC.2, FDP_ACF.1, FDP_IFF, FDP_RIP.2, FDP_SDI.2, FDP_ITC.1, FDP_ITC.2, FDP_ACC, FDP_ACC.2.1, FDP_ACC.2.2, FDP_ACC.1, FDP_ACF.1.1, FDP_ACF.1.2, FDP_ACF.1.3, FDP_ACF.1.4, FDP_IFC.2, FDP_IFC.1, FDP_IFF.1, FDP_IFF.1.3, FDP_RIP, FDP_RIP.2.1, FDP_RIP.1, FDP_SDI, FDP_SDI.2.1, FDP_SDI.2.2, FDP_SDI.1, FIA_ATD, FIA_AFL, FIA_UAU, FIA_UID, FIA_USB, FIA_ATD.1, FIA_AFL.1, FIA_UAU.2, FIA_UAU.5, FIA_UAU.6, FIA_UID.2, FIA_USB.1, FIA_UID.1, FIA_ATD.1.1, FIA_AFL.1.1, FIA_AFL.1.2, FIA_UAU.1, FIA_UAU.2.1, FIA_UAU.5.1, FIA_UAU.5.2, FIA_UAU.6.1, FIA_UID.2.1, FIA_USB.1.1, FIA_USB.1.2, FIA_USB.1.3, FMT_SMR, FMT_MOF.1, FMT_SMF.1, FMT_SMR.1, FMT_MSA, FMT_MSA.3, FMT_MOF, FMT_MOF.1.1, FMT_SMF, FMT_SMF.1.1, FMT_SMR.1.1, FMT_SMR.1.2, FMT_MSA.1, FPR_CON, FPR_CON.1, FPR_PSE, FPR_CON.1.2, FPR_CON.1.1, FPR_PSE.1, FPR_PSE.1.1, FPR_PSE.1.2, FPR_PSE.1.3, FPT_FLS, FPT_RPL, FPT_STM, FPT_TST, FPT_PHP, FPT_FLS.1, FPT_RPL.1, FPT_STM.1, FPT_TST.1, FPT_PHP.1, FPT_FLS.1.1, FPT_RPL.1.1, FPT_RPL.1.2, FPT_STM.1.1, FPT_TST.1.1, FPT_TST.1.2, FPT_TST.1.3, FPT_PHP.1.1, FPT_PHP.1.2, FTP_ITC, FTP_ITC.1
Protection profiles
BSI-CC-PP-0073, BSI-CC-PP-0077
Certificates
BSI-DSZ-CC-0918-V9-2026, BSI-DSZ-CC-0957-V2-2016, CC-1217-2024

Side-channel analysis
physical tampering, malfunction

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

Extracted SARs

ADV_ARC.1, ADV_FSP.4, ADV_IMP.1, ADV_TDS.3, AGD_OPE.1, AGD_PRE.1, ALC_CMC.4, ALC_CMS.4, ALC_DEL.1, ALC_DVS.1, ALC_FLR.2, ALC_LCD.1, ALC_TAT.1, ASE_CCL.1, ASE_ECD.1, ASE_INT.1, ASE_OBJ.2, ASE_REQ.2, ASE_SPD.1, ASE_TSS.1, ATE_COV.2, ATE_DPT.1, ATE_FUN.1, ATE_IND.2, AVA_VAN.5

Similar certificates

Name Certificate ID Actions
Conexa 3.0 EUCC-3087-2026-000014-I-00 Compare

Scheme data

Certificate ID BSI-DSZ-CC-0918-V8-2025
Product CONEXA 3.0, Version 1.7
Vendor Theben Smart Energy GmbH
Certification Date 03.07.2025
Category Intelligent measuring systems
URL https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/SmartMeter_Gateway/0918.html
Subcategory (Smart Meter Gateway)
Enhanced
Product CONEXA 3.0, Version 1.7
Applicant Theben Smart Energy GmbH Schlossfeld 9 72401 Haigerloch
Evaluation Facility TÜV Informationstechnik GmbH
Assurance Level EAL4+,ALC_FLR.2,AVA_VAN.5
Protection Profile Protection Profile for the Gateway of a Smart Metering System, Version 1.3, 31 March 2014, BSI-CC-PP-0073-2014
Certification Date 03.07.2025
Expiration Date 02.07.2033
Certification history
BSI-DSZ-CC-0918-V8-2025-MA-01 The changes are related to an update of the communication in the LMN.
BSI-DSZ-CC-0918-V8-2025 (Ausstellungsdatum / Certification Date 03.07.2025, gültig bis / valid until 02.07.2033) The Target of Evaluation (TOE) presented in this document is called "Smart Meter Gateway", “SMGW” or “Gateway” and uniquely identified as CONEXA 3.0 (CC), Version 1.7. It is the communication unit used within such an intelligent metering system and represented by the product CONEXA 3.0 except for the integrated Security Module. Besides data processing, Smart Meter Gateway offers possibility to generate tariff rates in order to enable network operators and consumers to control energy consumption in an intelligent way. The changes regarding this re-certification are based on using a new security module and some bug fixing.
BSI-DSZ-CC-0918-V7-2025 (Ausstellungsdatum / Certification Date 06.02.2025, gültig bis / valid until 05.02.2033) The Target of Evaluation (TOE) presented in this document is called "Smart Meter Gateway", “SMGW” or “Gateway” and uniquely identified as CONEXA 3.0 (CC), Version 1.6. It is the communication unit used within such an intelligent metering system and represented by the product CONEXA 3.0 except for the integrated Security Module. Besides data processing, Smart Meter Gateway offers possibility to generate tariff rates in order to enable network operators and consumers to control energy consumption in an intelligent way. The following changes on the evaluated product have been in the focus of this re-evaluation procedure: Adjustment in assignment of counter register to measured value list, optimization GWA change process, compression of data at the WAN interface, documentation adaptions, implementation of the MPO delivery method, further changes and bugfixes, kernel update and editorial changes.
BSI-DSZ-CC-0918-V6-2024-RA-01 (Ausstellungsdatum / Certification Date 29.01.2025) Successful Re-Assessment with update of the vulnerability analysis. The CC-certificate BSI-DSZ-CC-0918-V6-2024 remains valid for 2 further years.
BSI-DSZ-CC-0918-V6-2024-MA-03 The changes are related to an update of the user guidance and to the certified scope of the delivery procedures. For the certified scope of the delivery procedures, the assurance component ALC_DEL.1 (ALC_DEL.1.1D, ALC_DEL.1.1C) has been refined in the ST to only cover the delivery of the TOE from the manufacturer to the MPO (metering point operator), who is the customer of the developer and the recipient of the TOE.
BSI-DSZ-CC-0918-V6-2024-MA-02 The changes are related to an update of the user guidance and to the certified scope of the delivery procedures. For the certified scope of the delivery procedures, the assurance component ALC_DEL.1 (ALC_DEL.1.1D, ALC_DEL.1.1C) has been refined in the ST to only cover the delivery of the TOE from the manufacturer to the MPO (metering point operator), who is the customer of the developer and the recipient of the TOE.
BSI-DSZ-CC-0918-V6-2024-MA-01 The maintenance consists of a bug fix that was necessary to eliminate problems with connection interruptions both when tariffing with compact profiles and during network Management.
BSI-DSZ-CC-0918-V6-2024 (Ausstellungsdatum / Certification Date 08.02.2024, gültig bis / valid until 07.02.2032) , some software adjustments and adjustment of kernel-hardening. And last but not least the boot process was improved, some further adjustments with impact on documentation and editorial changes were made.
BSI-DSZ-CC-0918-V5-2023-MA-02 The change to the certified product is at the level of vendor’s renaming.
BSI-DSZ-CC-0918-V5-2023-MA-01 The description of the secure delivery procedure was extended due to adding an alternative delivery procedure (cardbox delivery).
BSI-DSZ-CC-0918-V5-2023 (Ausstellungsdatum / Certification Date 11.05.2023, gültig bis / valid until 10.05.2031) The focus of this re-evaluation was on certification obligations following BSI-K-TR-0507-2022, mobile phone signal validation without tools, adaption reaction of >36h no time synchronization and some further small changes, adjustments and updates.
BSI-DSZ-CC-0918-V4-2022-MA-03
BSI-DSZ-CC-0918-V4-2022-MA-02 The assembly space for the Fakra socket was adapted.
BSI-DSZ-CC-0918-V4-2022-MA-01 The order of the configuration parameters regarding the LTE module were corrected.
BSI-DSZ-CC-0918-V4-2022 (Ausstellungsdatum / Certification Date 08.03.2022, gültig bis / valid until 07.03.2030) Certificate
BSI-DSZ-CC-0918-V3-2022 (Ausstellungsdatum / Certification Date 24.01.2022, gültig bis / valid until 23.01.2030) Certificate
BSI-DSZ-CC-0918-V2-2021 (Ausstellungsdatum / Certification Date 01.07.2021, gültig bis / valid until 30.06.2029) ), Version 1.1 was enhanced due to the new tariff use cases (TAF) 9, 10 and 14. Further optimizations and some minor bugfixing were also performed.
BSI-DSZ-CC-0918-2020-MA-01 alive values. Therefore the version number changed for the Software from v3.33.0-cc to v3.33.3-cc.
Report Link https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0918V8a_pdf.pdf?__blob=publicationFile&v=2
Target Link https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0918V8b_pdf.pdf?__blob=publicationFile&v=2
Cert Link https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0918V8c_pdf.pdf?__blob=publicationFile&v=2
Description The Target of Evaluation (TOE) is the Smart Meter Gateway (SMGW) CONEXA 3.0, Version 1.0. The Smart Meter Gateway is the communication unit in a smart metering system. The main functionality of the gateway is the reception and the storage of measured consumption and status values of the connected meters as well as the processing and the transfer of these consumption and status values to authorized entities.

Processing updates

Feed
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.eucc.EUCCCertificate",
  "category": "SMART METER GATEWAY",
  "cert_id": "EUCC-3087-2026-000014-I-00",
  "cert_link": "https://certification.enisa.europa.eu/document/download/b6c8a9fa-ac58-4be9-addb-ff1d9efb74fa_en?filename=EUCC-3087-2026-0014%20Certificate.pdf",
  "dgst": "9498a0ae4a7fca64",
  "heuristics": {
    "_type": "sec_certs.sample.cc_eucc_common.Heuristics",
    "annotated_references": null,
    "cert_id": "EUCC-3087-2026-14",
    "cert_lab": null,
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "eal": null,
    "extracted_sars": {
      "_type": "Set",
      "elements": [
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_INT",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_CCL",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_DVS",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AGD_OPE",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_FUN",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_CMS",
          "level": 4
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_COV",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_ARC",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_DEL",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_TAT",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_CMC",
          "level": 4
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_LCD",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AVA_VAN",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_IMP",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_FSP",
          "level": 4
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_FLR",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_IND",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_OBJ",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_SPD",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_DPT",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_TDS",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_REQ",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_ECD",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AGD_PRE",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ASE_TSS",
          "level": 1
        }
      ]
    },
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "3.0"
      ]
    },
    "indirect_transitive_cves": null,
    "next_certificates": null,
    "prev_certificates": null,
    "protection_profiles": null,
    "related_cves": null,
    "report_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "scheme_data": {
      "category": "Intelligent measuring systems",
      "cert_id": "BSI-DSZ-CC-0918-V8-2025",
      "certification_date": "2025-07-03",
      "enhanced": {
        "applicant": "Theben Smart Energy GmbH Schlossfeld 9 72401 Haigerloch",
        "assurance_level": "EAL4+,ALC_FLR.2,AVA_VAN.5",
        "cert_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0918V8c_pdf.pdf?__blob=publicationFile\u0026v=2",
        "certification_date": "2025-07-03",
        "description": "The Target of Evaluation (TOE) is the Smart Meter Gateway (SMGW) CONEXA 3.0, Version 1.0. The Smart Meter Gateway is the communication unit in a smart metering system. The main functionality of the gateway is the reception and the storage of measured consumption and status values of the connected meters as well as the processing and the transfer of these consumption and status values to authorized entities.",
        "entries": [
          {
            "description": "The changes are related to an update of the communication in the LMN.",
            "id": "BSI-DSZ-CC-0918-V8-2025-MA-01"
          },
          {
            "description": "The Target of Evaluation (TOE) presented in this document is called \"Smart Meter Gateway\", \u201cSMGW\u201d or \u201cGateway\u201d and uniquely identified as CONEXA 3.0 (CC), Version 1.7. It is the communication unit used within such an intelligent metering system and represented by the product CONEXA 3.0 except for the integrated Security Module. Besides data processing, Smart Meter Gateway offers possibility to generate tariff rates in order to enable network operators and consumers to control energy consumption in an intelligent way. The changes regarding this re-certification are based on using a new security module and some bug fixing.",
            "id": "BSI-DSZ-CC-0918-V8-2025 (Ausstellungsdatum / Certification Date 03.07.2025, g\u00fcltig bis / valid until 02.07.2033)"
          },
          {
            "description": "The Target of Evaluation (TOE) presented in this document is called \"Smart Meter Gateway\", \u201cSMGW\u201d or \u201cGateway\u201d and uniquely identified as CONEXA 3.0 (CC), Version 1.6. It is the communication unit used within such an intelligent metering system and represented by the product CONEXA 3.0 except for the integrated Security Module. Besides data processing, Smart Meter Gateway offers possibility to generate tariff rates in order to enable network operators and consumers to control energy consumption in an intelligent way. The following changes on the evaluated product have been in the focus of this re-evaluation procedure: Adjustment in assignment of counter register to measured value list, optimization GWA change process, compression of data at the WAN interface, documentation adaptions, implementation of the MPO delivery method, further changes and bugfixes, kernel update and editorial changes.",
            "id": "BSI-DSZ-CC-0918-V7-2025 (Ausstellungsdatum / Certification Date 06.02.2025, g\u00fcltig bis / valid until 05.02.2033)"
          },
          {
            "description": "Successful Re-Assessment with update of the vulnerability analysis. The CC-certificate BSI-DSZ-CC-0918-V6-2024 remains valid for 2 further years.",
            "id": "BSI-DSZ-CC-0918-V6-2024-RA-01 (Ausstellungsdatum / Certification Date 29.01.2025)"
          },
          {
            "description": "The changes are related to an update of the user guidance and to the certified scope of the delivery procedures. For the certified scope of the delivery procedures, the assurance component ALC_DEL.1 (ALC_DEL.1.1D, ALC_DEL.1.1C) has been refined in the ST to only cover the delivery of the TOE from the manufacturer to the MPO (metering point operator), who is the customer of the developer and the recipient of the TOE.",
            "id": "BSI-DSZ-CC-0918-V6-2024-MA-03"
          },
          {
            "description": "The changes are related to an update of the user guidance and to the certified scope of the delivery procedures. For the certified scope of the delivery procedures, the assurance component ALC_DEL.1 (ALC_DEL.1.1D, ALC_DEL.1.1C) has been refined in the ST to only cover the delivery of the TOE from the manufacturer to the MPO (metering point operator), who is the customer of the developer and the recipient of the TOE.",
            "id": "BSI-DSZ-CC-0918-V6-2024-MA-02"
          },
          {
            "description": "The maintenance consists of a bug fix that was necessary to eliminate problems with connection interruptions both when tariffing with compact profiles and during network Management.",
            "id": "BSI-DSZ-CC-0918-V6-2024-MA-01"
          },
          {
            "description": ", some software adjustments and adjustment of kernel-hardening. And last but not least the boot process was improved, some further adjustments with impact on documentation and editorial changes were made.",
            "id": "BSI-DSZ-CC-0918-V6-2024 (Ausstellungsdatum / Certification Date 08.02.2024, g\u00fcltig bis / valid until 07.02.2032)"
          },
          {
            "description": "The change to the certified product is at the level of vendor\u2019s renaming.",
            "id": "BSI-DSZ-CC-0918-V5-2023-MA-02"
          },
          {
            "description": "The description of the secure delivery procedure was extended due to adding an alternative delivery procedure (cardbox delivery).",
            "id": "BSI-DSZ-CC-0918-V5-2023-MA-01"
          },
          {
            "description": "The focus of this re-evaluation was on certification obligations following BSI-K-TR-0507-2022, mobile phone signal validation without tools, adaption reaction of \u003e36h no time synchronization and some further small changes, adjustments and updates.",
            "id": "BSI-DSZ-CC-0918-V5-2023 (Ausstellungsdatum / Certification Date 11.05.2023, g\u00fcltig bis / valid until 10.05.2031)"
          },
          {
            "id": "BSI-DSZ-CC-0918-V4-2022-MA-03"
          },
          {
            "description": "The assembly space for the Fakra socket was adapted.",
            "id": "BSI-DSZ-CC-0918-V4-2022-MA-02"
          },
          {
            "description": "The order of the configuration parameters regarding the LTE module were corrected.",
            "id": "BSI-DSZ-CC-0918-V4-2022-MA-01"
          },
          {
            "description": "Certificate",
            "id": "BSI-DSZ-CC-0918-V4-2022 (Ausstellungsdatum / Certification Date 08.03.2022, g\u00fcltig bis / valid until 07.03.2030)"
          },
          {
            "description": "Certificate",
            "id": "BSI-DSZ-CC-0918-V3-2022 (Ausstellungsdatum / Certification Date 24.01.2022, g\u00fcltig bis / valid until 23.01.2030)"
          },
          {
            "description": "), Version 1.1 was enhanced due to the new tariff use cases (TAF) 9, 10 and 14. Further optimizations and some minor bugfixing were also performed.",
            "id": "BSI-DSZ-CC-0918-V2-2021 (Ausstellungsdatum / Certification Date 01.07.2021, g\u00fcltig bis / valid until 30.06.2029)"
          },
          {
            "description": "alive values. Therefore the version number changed for the Software from v3.33.0-cc to v3.33.3-cc.",
            "id": "BSI-DSZ-CC-0918-2020-MA-01"
          }
        ],
        "evaluation_facility": "T\u00dcV Informationstechnik GmbH",
        "expiration_date": "2033-07-02",
        "product": "CONEXA 3.0, Version 1.7",
        "protection_profile": "Protection Profile for the Gateway of a Smart Metering System, Version 1.3, 31 March 2014, BSI-CC-PP-0073-2014",
        "report_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0918V8a_pdf.pdf?__blob=publicationFile\u0026v=2",
        "target_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0918V8b_pdf.pdf?__blob=publicationFile\u0026v=2"
      },
      "product": "CONEXA 3.0, Version 1.7",
      "subcategory": "(Smart Meter Gateway)",
      "url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/SmartMeter_Gateway/0918.html",
      "vendor": "Theben Smart Energy GmbH"
    },
    "st_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "verified_cpe_matches": null
  },
  "manufacturer": "Theben Smart Energy GmbH",
  "manufacturer_web": "https://www.theben-se.de/conexa/cyber-security-info",
  "name": "Conexa 3.0",
  "not_valid_after": "2031-07-31",
  "not_valid_before": "2026-07-31",
  "other_metadata": {
    "_type": "sec_certs.sample.eucc.EUCCCertificate.EnisaMetadata",
    "assurance_level": "High",
    "ava_van_level": "5",
    "cc_version": "CC:2022 Revision 1",
    "cem_version": null,
    "certificate_id": "EUCC-3087-2026-000014-I-00",
    "certificate_yearly_number": null,
    "certification_body": "BSI",
    "certification_body_address": "Postfach 200363\\n53133 Bonn, Bonn",
    "certification_body_contact": "[email protected] Phone: +49 228 99 9582-0",
    "holder_address": "Schlossfeld 9, 72401 Haigerloch, Germany",
    "holder_contact": "[email protected]",
    "holder_name": "Theben Smart Energy GmbH",
    "holder_website": "https://www.theben-se.de/conexa/cyber-security-info",
    "issuance_date_full": "31/07/2026",
    "issuance_month": "7",
    "issuance_year": "2026",
    "itsef": "T\u00dcV Informationstechnik GmbH",
    "modification_or_reassurance": null,
    "nando_id": "3087",
    "package": {
      "EAL4": []
    },
    "product_description": "The Target of Evaluation (TOE) is the Smart Meter Gateway (SMGW) CONEXA 3.0, Version 1.8. The Smart Meter Gateway is the communication unit in a smart metering system. The main functionality of the gateway is the reception and the storage of measured consumption and status values of the connected meters as well as the processing and the transfer of these consumption and status \u00a0values to authorized entities.",
    "product_name": "Conexa 3.0",
    "product_type": "Smart Meter Gateway",
    "product_version": "Version 1.8",
    "protection_profile": "Protection Profile for the Gateway of a Smart Metering System, Version 1.3, 31 March 2014, BSI-CC-PP-0073-2014",
    "report_reference": null,
    "responsible_ncca": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
    "scheme": "(UE) 2024/482 - EUCC",
    "validity_period_years": "8 years"
  },
  "pdf_data": {
    "_type": "sec_certs.sample.cc_eucc_common.PdfData",
    "cert_filename": "b6c8a9fa-ac58-4be9-addb-ff1d9efb74fa_en",
    "cert_frontpage": null,
    "cert_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {
        "DE": {
          "BSI-DSZ-CC-0918-V9-2026": 1,
          "EUCC-3087-2026-0014": 1
        }
      },
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP-0073-2014": 1
        }
      },
      "cc_sar": {
        "ALC": {
          "ALC_FLR": 1,
          "ALC_FLR.2": 1
        },
        "AVA": {
          "AVA_VAN": 1,
          "AVA_VAN.5": 2
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 2": 1,
          "EAL 4": 1
        }
      },
      "cc_sfr": {},
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {
        "TUV": {
          "T\u00dcV Informationstechnik": 1
        }
      },
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {},
      "standard_id": {
        "ISO": {
          "ISO/IEC 15408": 2,
          "ISO/IEC 18045": 2
        }
      },
      "symmetric_crypto": {},
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "cert_metadata": {
      "/CreationDate": "D:20260805060908+01\u002700\u0027",
      "/Creator": "KM_C300i",
      "/ModDate": "D:20260805060908+01\u002700\u0027",
      "/Producer": "KONICA MINOLTA bizhub C300i",
      "/Title": "KM_C300i26080506080",
      "pdf_file_size_bytes": 121593,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 2
    },
    "report_filename": null,
    "report_frontpage": null,
    "report_keywords": null,
    "report_metadata": null,
    "st_filename": "4cdc19c1-b4fc-40af-9aa2-ceeb7a17e450_en",
    "st_frontpage": null,
    "st_keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 5
          },
          "ECDSA": {
            "ECDSA": 1
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 1
          }
        }
      },
      "cc_cert_id": {
        "DE": {
          "BSI-DSZ-CC-0918-V9-2026": 1,
          "BSI-DSZ-CC-0957-V2-2016": 1
        },
        "NL": {
          "CC-1217-2024": 1
        }
      },
      "cc_claims": {
        "OE": {
          "OE.SM": 4
        },
        "OSP": {
          "OSP.SM": 5
        }
      },
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP-0073": 2,
          "BSI-CC-PP-0077": 1
        }
      },
      "cc_sar": {
        "ADV": {
          "ADV_ARC.1": 2,
          "ADV_FSP.4": 2,
          "ADV_IMP.1": 2,
          "ADV_TDS.3": 1
        },
        "AGD": {
          "AGD_OPE.1": 2,
          "AGD_PRE.1": 1
        },
        "ALC": {
          "ALC_CMC.4": 2,
          "ALC_CMS.4": 1,
          "ALC_DEL.1": 7,
          "ALC_DVS.1": 1,
          "ALC_FLR.2": 7,
          "ALC_LCD.1": 2,
          "ALC_TAT.1": 1
        },
        "ASE": {
          "ASE_CCL.1": 3,
          "ASE_ECD.1": 1,
          "ASE_INT.1": 2,
          "ASE_OBJ.2": 1,
          "ASE_REQ.1": 1,
          "ASE_REQ.2": 2,
          "ASE_SPD.1": 1,
          "ASE_TSS.1": 2
        },
        "ATE": {
          "ATE_COV.2": 2,
          "ATE_DPT.1": 1,
          "ATE_FUN.1": 2,
          "ATE_IND.2": 1
        },
        "AVA": {
          "AVA_VAN.5": 9
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 4": 5,
          "EAL 4 augmented": 2,
          "EAL4": 1,
          "EAL4 augmented": 1
        }
      },
      "cc_sfr": {
        "FAU": {
          "FAU_ARP": 10,
          "FAU_ARP.1": 2,
          "FAU_GEN": 45,
          "FAU_GEN.1": 28,
          "FAU_GEN.2": 10,
          "FAU_GEN.2.1": 1,
          "FAU_SAA": 11,
          "FAU_SAA.1": 5,
          "FAU_SAR": 30,
          "FAU_SAR.1": 8,
          "FAU_STG": 32,
          "FAU_STG.2": 8,
          "FAU_STG.3": 16,
          "FAU_STG.3.1": 1,
          "FAU_STG.3.2": 1,
          "FAU_STG.3.3": 1,
          "FAU_STG.4": 4,
          "FAU_STG.5": 3
        },
        "FCO": {
          "FCO_NRO": 3,
          "FCO_NRO.1": 1,
          "FCO_NRO.2": 10,
          "FCO_NRO.2.1": 1,
          "FCO_NRO.2.2": 1,
          "FCO_NRO.2.3": 1
        },
        "FCS": {
          "FCS_CKM": 45,
          "FCS_CKM.1": 20,
          "FCS_CKM.2": 6,
          "FCS_CKM.4": 2,
          "FCS_CKM.5": 16,
          "FCS_CKM.6": 32,
          "FCS_CKM.6.1": 2,
          "FCS_CKM.6.2": 1,
          "FCS_COP": 66,
          "FCS_COP.1": 11,
          "FCS_COP.1.1": 1,
          "FCS_RBG.1": 9,
          "FCS_RNG.1": 18
        },
        "FDP": {
          "FDP_ACC": 2,
          "FDP_ACC.1": 9,
          "FDP_ACC.2": 12,
          "FDP_ACC.2.1": 1,
          "FDP_ACC.2.2": 1,
          "FDP_ACF.1": 12,
          "FDP_ACF.1.1": 1,
          "FDP_ACF.1.2": 4,
          "FDP_ACF.1.3": 1,
          "FDP_ACF.1.4": 3,
          "FDP_IFC": 29,
          "FDP_IFC.1": 12,
          "FDP_IFC.2": 5,
          "FDP_IFF": 25,
          "FDP_IFF.1": 25,
          "FDP_IFF.1.3": 1,
          "FDP_ITC.1": 12,
          "FDP_ITC.2": 12,
          "FDP_RIP": 2,
          "FDP_RIP.1": 1,
          "FDP_RIP.2": 10,
          "FDP_RIP.2.1": 1,
          "FDP_SDI": 2,
          "FDP_SDI.1": 1,
          "FDP_SDI.2": 9,
          "FDP_SDI.2.1": 1,
          "FDP_SDI.2.2": 1
        },
        "FIA": {
          "FIA_AFL": 3,
          "FIA_AFL.1": 9,
          "FIA_AFL.1.1": 1,
          "FIA_AFL.1.2": 1,
          "FIA_ATD": 3,
          "FIA_ATD.1": 14,
          "FIA_ATD.1.1": 1,
          "FIA_UAU": 5,
          "FIA_UAU.1": 2,
          "FIA_UAU.2": 9,
          "FIA_UAU.2.1": 1,
          "FIA_UAU.5": 8,
          "FIA_UAU.5.1": 1,
          "FIA_UAU.5.2": 1,
          "FIA_UAU.6": 9,
          "FIA_UAU.6.1": 1,
          "FIA_UID": 3,
          "FIA_UID.1": 8,
          "FIA_UID.2": 13,
          "FIA_UID.2.1": 1,
          "FIA_USB": 3,
          "FIA_USB.1": 9,
          "FIA_USB.1.1": 1,
          "FIA_USB.1.2": 1,
          "FIA_USB.1.3": 1
        },
        "FMT": {
          "FMT_MOF": 1,
          "FMT_MOF.1": 10,
          "FMT_MOF.1.1": 1,
          "FMT_MSA": 65,
          "FMT_MSA.1": 10,
          "FMT_MSA.3": 13,
          "FMT_SMF": 2,
          "FMT_SMF.1": 20,
          "FMT_SMF.1.1": 1,
          "FMT_SMR": 3,
          "FMT_SMR.1": 31,
          "FMT_SMR.1.1": 1,
          "FMT_SMR.1.2": 1
        },
        "FPR": {
          "FPR_CON": 6,
          "FPR_CON.1": 12,
          "FPR_CON.1.1": 3,
          "FPR_CON.1.2": 5,
          "FPR_PSE": 2,
          "FPR_PSE.1": 9,
          "FPR_PSE.1.1": 3,
          "FPR_PSE.1.2": 2,
          "FPR_PSE.1.3": 2
        },
        "FPT": {
          "FPT_FLS": 3,
          "FPT_FLS.1": 11,
          "FPT_FLS.1.1": 1,
          "FPT_PHP": 3,
          "FPT_PHP.1": 9,
          "FPT_PHP.1.1": 1,
          "FPT_PHP.1.2": 1,
          "FPT_RPL": 3,
          "FPT_RPL.1": 9,
          "FPT_RPL.1.1": 1,
          "FPT_RPL.1.2": 1,
          "FPT_STM": 3,
          "FPT_STM.1": 19,
          "FPT_STM.1.1": 1,
          "FPT_TST": 3,
          "FPT_TST.1": 10,
          "FPT_TST.1.1": 1,
          "FPT_TST.1.2": 1,
          "FPT_TST.1.3": 1
        },
        "FTP": {
          "FTP_ITC": 30,
          "FTP_ITC.1": 10
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "GCM": {
          "GCM": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "TLS": {
            "TLS": 62,
            "TLS 1.2": 5
          }
        }
      },
      "crypto_scheme": {
        "MAC": {
          "MAC": 9
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "NIST P-256": 3,
          "NIST P-384": 3,
          "P-256": 3,
          "P-384": 3,
          "secp256r1": 3,
          "secp384r1": 3
        }
      },
      "eval_facility": {},
      "hash_function": {
        "SHA": {
          "SHA2": {
            "SHA-256": 13,
            "SHA-384": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "PRNG": 1
        },
        "RNG": {
          "RNG": 1
        }
      },
      "side_channel_analysis": {
        "FI": {
          "malfunction": 2,
          "physical tampering": 4
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 3,
          "FIPS 180-4": 8,
          "FIPS 197": 12
        },
        "ISO": {
          "ISO/IEC 15408:2022": 2,
          "ISO/IEC 1686": 2,
          "ISO/IEC 18045:2022": 1,
          "ISO/IEC 673": 2
        },
        "RFC": {
          "RFC 2104": 6,
          "RFC 2616": 4,
          "RFC 3394": 3,
          "RFC 4493": 8,
          "RFC 5084": 4,
          "RFC 5114": 5,
          "RFC 5246": 7,
          "RFC 5289": 6,
          "RFC 5639": 5,
          "RFC 5905": 4,
          "RFC5246": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 7
          }
        }
      },
      "technical_report_id": {
        "BSI": {
          "BSI TR-03109": 1,
          "BSI TR-03109-1": 2
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {
        "TLS": {
          "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256": 2,
          "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 2,
          "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384": 2,
          "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 2
        }
      },
      "vendor": {},
      "vulnerability": {}
    },
    "st_metadata": {
      "/Author": "Theben Smart Energy GmbH",
      "/CreationDate": "D:20260714091548+02\u002700\u0027",
      "/Creator": "Theben Smart Energy GmbH",
      "/Keywords": "",
      "/ModDate": "D:20260714091548+02\u002700\u0027",
      "/PTEX.Fullbanner": "This is MiKTeX-pdfTeX 4.11.0 (1.40.24)",
      "/Producer": "Theben Smart Energy GmbH - ToolChain",
      "/Subject": "Security Target",
      "/Title": "Security Target v1.99.5 - CONEXA 3.0",
      "/Trapped": "/False",
      "pdf_file_size_bytes": 2071646,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf",
          "https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Smart-metering/Smart-Meter-Gateway/MSB/MSB_node.html",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a.pdf",
          "http://www.jtc1sc27.din.de/sce/sd6"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 139
    }
  },
  "protection_profile_links": null,
  "report_link": null,
  "scheme": "DE",
  "security_level": {
    "_type": "Set",
    "elements": []
  },
  "st_link": "https://certification.enisa.europa.eu/document/download/4cdc19c1-b4fc-40af-9aa2-ceeb7a17e450_en?filename=EUCC-3087-2026-0014%20Security%20Taget.pdf",
  "state": {
    "_type": "sec_certs.sample.cc_eucc_common.InternalState",
    "cert": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "8d3dfc1988b70b5593c01622e6c4f3f4207200c568e582e80ad3b9102a443706",
      "txt_hash": "9d583e7398d2f4e67b3f30f233caed885776ba854f8c8f87acd449dd8ff0a0b6"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": false,
      "download_ok": false,
      "extract_ok": false,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "st": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "906554c45142aa21e7c58ad9105f3eb218547345b30679e9a997f4660bd83a4e",
      "txt_hash": "a4cd4bfb10e7e0ef385b144119f0d5c1677aab0cc892ced1df7d07b0f6934db3"
    }
  },
  "status": "active"
}