| CARVIEW |
For inquiries about GlobalPlatform or website assistance, contact secretariat@globalplatform.org.
Security Certification
Creating trust through an independent and industry driven certification program
Security Certification
GlobalPlatform’s Security Certification scheme validates conformance of a secure component to a Common Criteria-recognized protection profile through independent security evaluation. It ensures that secure components meet the required levels of security defined for a particular service, enabling service providers to confidently and effectively manage risk and comply with industry requirements.
To assist the market in managing varying security requirements, GlobalPlatform has structured the program under two security levels. Each level denotes the ranked levels of threats and attacks that the security certified secure component will defend against. They are:
- Basic
- Enhanced (TEE products)
This simple framework allows future technologies and solutions to be added under these levels. In addition, device manufacturers can select the most appropriate accredited component for meeting their particular requirements, while allowing service providers to mandate a particular level of security to protect their digital services on devices.
What is a protection profile?
A protection profile specifies:
- The typical threats a secure component needs to withstand
- The security objectives that must be met by the secure component in order to counter these threats
- The functional requirements that a secure component will have to comply with in order to meet these security objectives
- The assurance level required for the product and product development process.
Who should participate?
Secure component manufacturers – demonstrate that your products align with the security requirements of the marketplace.- Device manufacturers – confirm that digital service management capabilities meet industry-defined security requirements.
- Application developers and service providers – ensure a product matches your security and privacy needs when seeking to deploy digital services on a particular device.
- Standardization bodies and issuers – request GlobalPlatform security certificates to take advantage of an off-the-shelf product or component created by certified and accredited test laboratories.
- Test / evaluation laboratories – become a GlobalPlatform-licensed laboratory to generate new revenue.
TEE and MCU vendors can certify with GlobalPlatform to demonstrate that their products meet security, regulatory and data protection requirements.
To certify a product, vendors must confirm conformity with the relevant protection profile via an independent security evaluation under a TEE certification process.


By becoming GlobalPlatform-licensed labs can generate new revenue through third-party validation services. Security evaluation laboratories that are GlobalPlatform full or participating members in good standing can apply to:
- The Trusted Execution Environment (TEE) Security scheme to initiate the licensing process.
Learn more about the TEE Security Certification Program
In this Q&A, GlobalPlatform CTO Gil Bernabeu explores how the security certification program helps protect, ease and accelerate the deployment of digital devices and services.

The legal and technical forms applicable to each type of qualification are provided below.
Sign up to receive the latest Certification Updates
Please enter your information below to receive the latest Program Updates
Locate your nearest GlobalPlatform-approved laboratory