top of page

JAVACARD NATIVE

ML-KEM

ML-DSA

SLH-DSA

NIST FIPS 203 / 204 / 205

Certification services

jNet supports certification planning and documentation for JavaCard OS platforms, applet suites, and composite OS + applet products across Common Criteria, FIPS 140-3, and EMVCo contact/contactless schemes.

In-house EMVCo pre-validation, established CC/FIPS lab coordination, and composite OS + applet certification experience.

Certification Schemes

Three schemes. One team that knows all three

From Common Criteria to FIPS 140-3 and EMVCo, we support the certification paths required for secure platforms, payment products, and regulated deployments.

Common Criteria

EAL5+ / EAL6+

CCRA / SOG-IS

ISO/IEC 15408

Supported PPs

JavaCard System PP (BSI-CC-PP-0099)
GlobalPlatform Card PP
Application-specific PPs on request

Partner labs

TÜV Informationstechnik

SGS Brightsight

CESTI / SERMA

DEKRA

Common Criteria EAL5+ is the recognized assurance standard for secure operating systems used in government ID, ePassport, national payment, and other high-assurance deployments. jNet supports the CC evaluation cycle for Javelin OS, with documentation aligned to JavaCard System PP and GlobalPlatform Card PP under CCRA and SOG-IS.

Security Target (ST) — PP-conformant

ADV_IMP.1 — implementation representation

AVA_VAN.4/5 — vulnerability analysis input

ALC_DVS / ALC_CMC / ALC_CMS lifecycle

ADV_ARC / ADV_FSP.5 / ADV_TDS.4

ATE_COV / ATE_DPT / ATE_FUN / ATE_IND

AGD_OPE / AGD_PRE guidance documentation

EAL6+ augmentation on SLC37 platform

Composite Platform Certification

OS and applet, certified together

Most certification programs evaluate the operating system and the applet as separate targets. When both layers are developed together, jNet can structure one coherent certification package — aligning the OS security architecture, applet Security Function Policy, interface behavior, and evidence documentation from the start.

Why composite certification matters

A separately evaluated applet running on a separately evaluated OS can still require composition analysis or interface agreements to prove that the combined product behaves as the Security Target claims. jNet reduces this ambiguity by documenting both layers as one integrated platform.

Single Security Target covering OS + applet security functions

Consistent ADV_FSP across OS interface and applet APDU surface

No composition gap between OS and applet certificates

Reduced lab time and documentation overhead

Composite platform scope

jNet can scope and deliver composite certification packages for the following combinations, on supported silicon targets:

Javelin OS + PIV applet — CC EAL5+ / FIPS 140-3 L3

Javelin OS + ePassport applet — CC EAL5+ / ICAO

Javelin OS + MChip Advance — CC EAL5+ / EMVCo

Javelin OS + FIDO2 CTAP 2.3 — FIPS 140-3 / FIDO Alliance

Custom OS + custom applet — scheme determined at scoping

PQC composite platform — JavaCard v3.2 target (post-Oracle release)

CERTIFICATION DELIVERY

Built for evaluation timelines

jNet combines JavaCard certification experience, fixed-scope documentation planning, and in-house EMVCo pre-validation to reduce late-stage rework before formal lab submission.

5 days

Fixed-scope proposal

after scoping call

15+ years

JavaCard certification

experience

In-house

EMVCo pre-validation

test room

bottom of page