Regulatory compliance

Support to qualify your product for the CPSTIC catalogue

We take your security product all the way into Spain's CPSTIC, the CCN's Catalogue of Security ICT Products and Services: fit within the CCN-STIC 140 taxonomy, gap analysis against the fundamental security requirements, documentation, coordination of the LINCE or Common Criteria evaluation and the inclusion request. Independent consultancy: you choose the laboratory.

LINCECommon CriteriaCCN-STIC 140CCN-STIC 106ENS category HIGH

We're not a laboratory: independent support up to certification, with the accredited lab you choose.

Selling to the Spanish public sector? CPSTIC connects with your customers' ENS compliance at category HIGH.

Why it matters

The catalogue that opens Spain's public sector

Spain's National Security Framework (ENS, Royal Decree 311/2022) requires category HIGH systems to use qualified products included in the CPSTIC where that requirement applies to the security function. The consequence is direct: if your product (encryption, firewall, VPN, identity management, endpoint protection, monitoring…) wants to compete for public-sector projects, or sell to integrators and suppliers that do work with them, being in the catalogue stops being an advantage and becomes a requirement.

And the market keeps growing: the knock-on effect of NIS2 and the rising bar in public procurement push more organisations to check the CPSTIC before they buy. Qualifying your product is not just compliance; it is a commercial argument and a barrier to entry against those who have not done it.

The process, however, is technical and unforgiving: choosing the wrong taxonomy family, reaching the evaluation with secure-development gaps or weak documentation means failing, and repeating an evaluation costs time and money. That is where the support comes in.

The framework

The framework, in brief

Qualification rests on three CCN pieces: the procedure that governs it, the taxonomy that sets what each type of product must meet, and the functional certification that proves it.

General route · ENS

Qualified products

The route for the ENS and general public-sector use. Inclusion procedure CCN-STIC 106. It is the one most manufacturers need.

CCN-STIC 106

Taxonomy · requirements

Families and requirements

CCN-STIC 140 classifies products into families and defines, in each family's annex, the fundamental security requirements (FSR) that apply.

CCN-STIC 140

The proof

Functional certification

A certification covering your family's requirements: a LINCE evaluation (national, agile) or Common Criteria (international, for high assurance), by an accredited lab.

LINCE · Common Criteria

Note: do not confuse this with approved products (CCN-STIC 102), the specific route for handling classified information, which follows a different process.

Benefits

What you gain by qualifying your product

Access to the public sector

The ENS at category HIGH requires qualified products. With the mark you enter tenders and projects that are closed without it.

First time right

Reaching the evaluation prepared avoids failing. Repeating a LINCE or Common Criteria evaluation costs time and budget.

Independent judgement

We are not a laboratory: we advise you with no conflict of interest and work with whichever evaluator fits you best.

Competitive advantage

Being in the CPSTIC is a commercial argument and a barrier to entry against competitors that are not.

Service

What the support includes

Taxonomy fit: identifying your product's family (or families) in CCN-STIC 140 and the requirements that apply to it.

Gap analysis of the product against those requirements: what you already meet and what is missing to pass the evaluation.

Remediation plan: security functions, secure development and product changes to close the gaps before evaluating.

Evaluation documentation: Security Target, manuals and evidence the laboratory needs.

Laboratory selection and coordination of the accredited lab (LINCE or Common Criteria) and follow-up of the evaluation.

Inclusion request: preparing the FOR-CPSTIC-01 and FOR-CPSTIC-02 forms and managing the process with the CCN through to publication.

Maintaining the qualification: validity, new product versions and renewals so you stay in the catalogue.

Optional technical validation: security testing on your product before the official evaluation to arrive on the safe side.

Method

How to get your product into the CPSTIC, step by step

01

Fit and diagnosis

Family in CCN-STIC 140, applicable requirements and product gap analysis. Output: a realistic estimate of effort, timeline and cost.

02

Preparation

Closing the gaps, Security Target and evidence. We leave the product and documentation ready to evaluate.

03

Evaluation

We coordinate the LINCE or Common Criteria evaluation with the accredited laboratory you choose, and support you throughout.

04

Inclusion

Request with the FOR-CPSTIC-01 and FOR-CPSTIC-02 forms, management with the CCN and publication of the product in the catalogue.

Fits with

From product to project

Qualification does not stand alone: it is a piece of the same puzzle as your customers' ENS compliance. Whoever buys your product often does so because their category HIGH system requires it. Understanding both sides (the manufacturer's and the organisation getting compliant) is what lets us prepare you well.

And before the official evaluation, putting your product to the test reduces surprises: our infrastructure pentest and security testing help find what an evaluator would, while it is still cheap to fix.

FAQ

Frequently asked questions

What is the CPSTIC and what is it for?+

The CPSTIC is the Catalogue of Security ICT Products and Services run by Spain's National Cryptologic Centre (CCN). It lists products that have demonstrated a set of minimum security requirements and can therefore be used in systems subject to the ENS, especially at category HIGH. Being in the catalogue is, in practice, the key to selling security products to the Spanish public sector.

Qualified product or approved product, which one do I need?+

They are two different tracks. Qualified products (procedure CCN-STIC 106) are the ones for the ENS and general public-sector use: that is the usual route. Approved products (CCN-STIC 102) are for handling classified information, with a separate process. For the vast majority of manufacturers, the route is qualification.

What is a LINCE evaluation and how does it differ from Common Criteria?+

LINCE is the CCN's national evaluation methodology: lighter and faster, designed to cover the fundamental security requirements of many families in the catalogue. Common Criteria is a more demanding international scheme, suited to high assurance levels. The functional certification valid for qualification can be achieved through either route; which one suits you depends on your product, your market and your timelines.

Do I need to be in the CPSTIC to sell to the Spanish public sector?+

For many products, yes in practice. The ENS requires category HIGH systems to use qualified products included in the CPSTIC where that requirement applies to the security function. If your product competes for public-sector projects, or sells to their suppliers, not being in the catalogue leaves you out of a large part of the market.

Can you guarantee inclusion in the catalogue?+

No, and be wary of anyone who promises it: certification is issued by an accredited laboratory and qualification is decided by the CCN. What we do is prepare your product and your documentation to pass the evaluation first time, cutting the risk of failing and the cost of repeating it. We support the whole process through to publication.

Which evaluation laboratory do you work with?+

We are independent: we are not a laboratory, so our advice is impartial. We work with the accredited laboratory you choose or, if you prefer, we recommend the one that best fits your product family, timeline and budget, and we coordinate the evaluation with them.

How long does it take and how much does it cost?+

It depends on the product family, its security maturity and the certification route (LINCE is usually faster than Common Criteria). The initial diagnosis of taxonomy fit and gaps against the requirements gives you, within a few weeks, a realistic estimate of effort, timeline and cost before you commit to the evaluation.

Direct line

Shall we qualify your product?

Let's start with the diagnosis: your product's family, the requirements that apply and the real path to the CPSTIC, with an estimate of effort and timelines.

Talk to a consultant