The AppSW-iTC develops internationally agreed Common Criteria security requirements and evaluation activities for application software, including Server and Agent applications and distributed deployments.
Current published documents Application Software cPP, Supporting Document, PP-Modules, and PP-Configurations Version 1.0e. |
PUBLIC REVIEW DRAFT Version 2.0 Public Review Draft 1 Base cPP, Server and Agent modules, Supporting Documents, and PP-Configurations. Comments close October 24, 2026. |
-
Version 1.0e published documents
Current release and document downloads -
Version 2.0 review guide
Rebase, architecture, and substantive changes -
Technical Decisions
Interpretations and updates between releases -
Document source repository
Document sources and issue tracking -
PP-Configuration architecture
Base, Server, and Agent composition -
Contribute or contact the iTC
Submit a review comment or join the community
1. Introduction
Formed from a CCDB-established Working Group, the Application Software international Technical Community brings together Certification Bodies, Common Criteria laboratories, and vendors to create requirements for application security testing.
The AppSW protection-profile family combines a base collaborative Protection Profile (cPP) with Server and Agent PP-Modules. Supporting Documents define Evaluation Activities, and PP-Configurations identify the combinations of the base and modules.
2. Current Status
The site distinguishes the published release, the active public review, and previous versions:
-
Published release identifies Version 1.0e, published on February 15, 2024.
-
Public review draft identifies Version 2.0 Public Review Draft 1. The comment period runs from September 9 through October 24, 2026. The draft does not replace the published Version 1.0e document set.
-
Previous versions retain the Version 1.0 documents and release package for reference.
4. Current Documents for Review
VERSION 2.0 — PUBLIC REVIEW DRAFT 1
- Review Package Date
-
August 17, 2026
- Public Review Opening Date
-
September 9, 2026
- End of Comment Period
-
October 24, 2026
- Status
-
Public Review Draft 1
The AppSW-iTC has opened the Version 2.0 document set for public review. This draft is based on the NIAP Protection Profile for Application Software, Version 2.0, and includes the AppSW-iTC distributed TOE, microservices, module, and PP-Configuration updates.
See the Version 2.0 public-review overview for a high-level explanation of the rebase, the re-layered Server and Agent modules, and the substantive additions that are particularly relevant to review. Use the requirements trigger map to explore selection conditions, package applicability, and module composition alongside the draft text.
Reviewers are encouraged to provide comments by opening an issue in the AppSW-iTC repository. Select the template that fits the cPP, Supporting Document, PP-Module, or PP-Configuration; identify the document and section; and include a proposed resolution where possible.
| Title | Version | Links |
|---|---|---|
Collaborative Protection Profile for Application Software |
2.0 Draft |
|
Supporting Document Mandatory Technical Document: Evaluation Activities for Collaborative Protection Profile for Application Software |
2.0 Draft |
|
PP-Module for Application Software Server |
2.0 Draft |
|
Supporting Document Mandatory Technical Document: Evaluation Activities for PP-Module for Application Software Server |
2.0 Draft |
|
PP-Module for Application Software Agent |
2.0 Draft |
|
Supporting Document Mandatory Technical Document: Evaluation Activities for PP-Module for Application Software Agent |
2.0 Draft |
|
PP-Configuration for Enterprise Server Applications |
2.0 Draft |
|
PP-Configuration for Enterprise Server Applications and Agent/Application Component(s) |
2.0 Draft |
5. Security Architecture at a Glance
The Version 2.0 draft organizes the application-software family into the following layers:
-
Base cPP and Supporting Document — define the common application-software requirements and Evaluation Activities.
-
Server PP-Module and Supporting Document — extend the base with requirements and evaluation material for Server application roles.
-
Agent PP-Module and Supporting Document — extend the base with requirements and evaluation material for Agent/application component roles.
-
PP-Configurations — identify the Base + Server and Base + Server + Agent combinations and explain how components map to the applicable requirements.
The Version 2.0 public-review guide explains the distributed TOE model, component allocation, platform boundaries, and worked deployment examples, with links to the draft text.
6. Technical Decisions
Technical Decisions clarify and update the cPP and related documents between release cycles.
7. Archives and Previous Versions
The Version 1.0 documents, published on April 6, 2022, and their release package remain available below. The current published Version 1.0e set is listed in Current Published Documents.
Version 1.0
- Publication Date
-
April 6, 2022
- Sunset Date
-
Active
- Retired Date
-
Active
The following documents are included in Version 1.0:
| Title | Version | Links |
|---|---|---|
collaborative Protection Profile for Application Software - [cPP_APP_SW] |
1.0 |
|
Supporting Document Mandatory Technical Document: Evaluation Activities for collaborative Protection Profile for Application Software - [SD_APP_SW] |
1.0 |
|
collaborative Protection Profile for Application Software - Allowed With List |
1.0 |
|
collaborative PP-Module for Server Applications [MOD_Server] |
1.0 |
|
Supporting Document Mandatory Technical Document: Evaluation Activities for collaborative Protection Profile Module for Server Applications [SD_MOD_Server] |
1.0 |
|
PP-Configuration for Enterprise Server Applications [cPP + MOD_Server] |
1.0 |
|
collaborative PP-Module for Agent Applications [MOD_Agent] |
1.0 |
|
Supporting Document Mandatory Technical Document: Evaluation Activities for collaborative Protection Profile Module for Agent Applications [SD_MOD_Agent] |
1.0 |
|
PP-Configuration for Enterprise Server Applications and Client Agent(s) [cPP + MOD_Server + MOD_Agent] |
1.0 |
| Title | Link |
|---|---|
cPP + Modules V1.0 Release package |
8. Participate and Source Repositories
Public review welcomes input from Certification Bodies, laboratories, vendors, users, and researchers. Use a GitHub Issue for a specific document comment or request for interpretation. Select the relevant document template, identify the section, and include a proposed resolution where possible.
To join the AppSW-iTC, contact cm-itc-mailing-list@gmail.com.
The Version 2.0 overview and architecture summaries are explanatory aids. The linked cPP, Supporting Documents, PP-Modules, and PP-Configurations provide the document text for the identified release or review draft.