JAVACARD NATIVE
ML-KEM
ML-DSA
SLH-DSA
NIST FIPS 203 / 204 / 205
Certification services
jNet supports certification planning and documentation for JavaCard OS platforms, applet suites, and composite OS + applet products across Common Criteria, FIPS 140-3, and EMVCo contact/contactless schemes.
In-house EMVCo pre-validation, established CC/FIPS lab coordination, and composite OS + applet certification experience.
Certification Schemes
Three schemes. One team that knows all three
From Common Criteria to FIPS 140-3 and EMVCo, we support the certification paths required for secure platforms, payment products, and regulated deployments.
Common Criteria
EAL5+ / EAL6+
CCRA / SOG-IS
ISO/IEC 15408
Supported PPs
JavaCard System PP (BSI-CC-PP-0099)
GlobalPlatform Card PP
Application-specific PPs on request
Partner labs
TÜV Informationstechnik
SGS Brightsight
CESTI / SERMA
DEKRA
Common Criteria EAL5+ is the recognized assurance standard for secure operating systems used in government ID, ePassport, national payment, and other high-assurance deployments. jNet supports the CC evaluation cycle for Javelin OS, with documentation aligned to JavaCard System PP and GlobalPlatform Card PP under CCRA and SOG-IS.
Security Target (ST) — PP-conformant
ADV_IMP.1 — implementation representation
AVA_VAN.4/5 — vulnerability analysis input
ALC_DVS / ALC_CMC / ALC_CMS lifecycle
ADV_ARC / ADV_FSP.5 / ADV_TDS.4
ATE_COV / ATE_DPT / ATE_FUN / ATE_IND
AGD_OPE / AGD_PRE guidance documentation
EAL6+ augmentation on SLC37 platform
Composite Platform Certification
OS and applet, certified together
Most certification programs evaluate the operating system and the applet as separate targets. When both layers are developed together, jNet can structure one coherent certification package — aligning the OS security architecture, applet Security Function Policy, interface behavior, and evidence documentation from the start.
Why composite certification matters
A separately evaluated applet running on a separately evaluated OS can still require composition analysis or interface agreements to prove that the combined product behaves as the Security Target claims. jNet reduces this ambiguity by documenting both layers as one integrated platform.
Single Security Target covering OS + applet security functions
Consistent ADV_FSP across OS interface and applet APDU surface
No composition gap between OS and applet certificates
Reduced lab time and documentation overhead
Composite platform scope
jNet can scope and deliver composite certification packages for the following combinations, on supported silicon targets:
Javelin OS + PIV applet — CC EAL5+ / FIPS 140-3 L3
Javelin OS + ePassport applet — CC EAL5+ / ICAO
Javelin OS + MChip Advance — CC EAL5+ / EMVCo
Javelin OS + FIDO2 CTAP 2.3 — FIPS 140-3 / FIDO Alliance
Custom OS + custom applet — scheme determined at scoping
PQC composite platform — JavaCard v3.2 target (post-Oracle release)
CERTIFICATION DELIVERY
Built for evaluation timelines
jNet combines JavaCard certification experience, fixed-scope documentation planning, and in-house EMVCo pre-validation to reduce late-stage rework before formal lab submission.
5 days
Fixed-scope proposal
after scoping call
15+ years
JavaCard certification
experience
In-house
EMVCo pre-validation
test room
