For inquiries about GlobalPlatform or website assistance, contact secretariat@globalplatform.org.

Security Certification

GlobalPlatform’s Security Certification scheme validates conformance of a secure component to a Common Criteria-recognized protection profile through independent security evaluation. It ensures that secure components meet the required levels of security defined for a particular service, enabling service providers to confidently and effectively manage risk and comply with industry requirements.

To assist the market in managing varying security requirements, GlobalPlatform has structured the program under three security levels. Each level denotes the ranked levels of threats and attacks that the security certified secure component will defend against. They are:

  • Basic
  • Enhanced (TEE products)
  • High (SE products)

This simple framework allows future technologies and solutions to be added under these levels. In addition, device manufacturers can select the most appropriate accredited component for meeting their particular requirements, while allowing service providers to mandate a particular level of security to protect their digital services on devices.

What is a protection profile?

A protection profile specifies:

  • The typical threats a secure component needs to withstand
  • The security objectives that must be met by the secure component in order to counter these threats
  • The functional requirements that a secure component will have to comply with in order to meet these security objectives
  • The assurance level required for the product and product development process.
Participating in Security Certification

Who should participate?

  • Secure component manufacturers – demonstrate that your products align with the security requirements of the marketplace.
  • Device manufacturers – confirm that digital service management capabilities meet industry-defined security requirements.
  • Application developers and service providers – ensure a product matches your security and privacy needs when seeking to deploy digital services on a particular device.
  • Standardization bodies and issuers – request GlobalPlatform security certificates to take advantage of an off-the-shelf product or component created by certified and accredited test laboratories.
  • Test / evaluation laboratories – become a GlobalPlatform-licensed laboratory to generate new revenue.
Find a Certified Product
Find a Licensed Lab
View Protection Profiles
Certify Your Product

SE, TEE and MCU vendors can certify with GlobalPlatform to demonstrate that their products meet security, regulatory and data protection requirements.

To certify a product, vendors must confirm conformity with the relevant protection profile via an independent security evaluation under an SE certification process, or a TEE certification process.

Apply.

 

Become a GlobalPlatform-Licensed Laboratory

By becoming GlobalPlatform-licensed labs can generate new revenue through third-party validation services. Security evaluation laboratories that are GlobalPlatform full or participating members in good standing can apply to:


Learn more about the TEE Security Certification Program

In this Q&A, GlobalPlatform CTO Gil Bernabeu explores how the security certification program helps protect, ease and accelerate the deployment of digital devices and services.

Participation Forms

The legal and technical forms applicable to each type of qualification are provided below.

Locate your nearest GlobalPlatform-approved laboratory

GlobalPlatform
Hey There!

It seems you are using an outdated browser, unfortunately this means that our website will not render properly for you. Update your browser to view this website correctly.

GOOGLE CHROME
FIREFOX
MICROSOFT EDGE