The AppSW-iTC develops internationally agreed Common Criteria security requirements and evaluation activities for application software, including Server and Agent applications and distributed deployments.

PUBLISHED RELEASE

Current published documents

Application Software cPP, Supporting Document, PP-Modules, and PP-Configurations Version 1.0e.

PUBLIC REVIEW DRAFT

Version 2.0 Public Review Draft 1

Base cPP, Server and Agent modules, Supporting Documents, and PP-Configurations. Comments close October 24, 2026.

1. Introduction

Formed from a CCDB-established Working Group, the Application Software international Technical Community brings together Certification Bodies, Common Criteria laboratories, and vendors to create requirements for application security testing.

The AppSW protection-profile family combines a base collaborative Protection Profile (cPP) with Server and Agent PP-Modules. Supporting Documents define Evaluation Activities, and PP-Configurations identify the combinations of the base and modules.

2. Current Status

The site distinguishes the published release, the active public review, and previous versions:

  • Published release identifies Version 1.0e, published on February 15, 2024.

  • Public review draft identifies Version 2.0 Public Review Draft 1. The comment period runs from September 9 through October 24, 2026. The draft does not replace the published Version 1.0e document set.

  • Previous versions retain the Version 1.0 documents and release package for reference.

3. Current Published Documents

CURRENT PUBLISHED RELEASE — VERSION 1.0e

Publication Date

February 15, 2024

Sunset Date

Active

Retired Date

Active

The following documents are included in Version 1.0e:

Table 1. Public Release v1.0e Documents
Title Version Links

collaborative Protection Profile for Application Software - [cPP_APP_SW]

1.0e

PDF / HTML

Supporting Document Mandatory Technical Document: Evaluation Activities for collaborative Protection Profile for Application Software - [SD_APP_SW]

1.0e

PDF / HTML

collaborative Protection Profile for Application Software - Allowed With List

1.0e

PDF

collaborative PP-Module for Server Applications [MOD_Server]

1.0e

PDF / HTML

Supporting Document Mandatory Technical Document: Evaluation Activities for collaborative Protection Profile Module for Server Applications [SD_MOD_Server]

1.0e

PDF / HTML

PP-Configuration for Enterprise Server Applications [cPP + MOD_Server]

1.0e

PDF / HTML

collaborative PP-Module for Agent Applications [MOD_Agent]

1.0e

PDF / HTML

Supporting Document Mandatory Technical Document: Evaluation Activities for collaborative Protection Profile Module for Agent Applications [SD_MOD_Agent]

1.0e

PDF / HTML

PP-Configuration for Enterprise Server Applications and Client Agent(s) [cPP + MOD_Server + MOD_Agent]

1.0e

PDF / HTML

Table 2. GitHub Public Release Packages
Title Link

cPP + Modules V1.0e Release package

Release package

4. Current Documents for Review

VERSION 2.0 — PUBLIC REVIEW DRAFT 1

Review Package Date

August 17, 2026

Public Review Opening Date

September 9, 2026

End of Comment Period

October 24, 2026

Status

Public Review Draft 1

The AppSW-iTC has opened the Version 2.0 document set for public review. This draft is based on the NIAP Protection Profile for Application Software, Version 2.0, and includes the AppSW-iTC distributed TOE, microservices, module, and PP-Configuration updates.

See the Version 2.0 public-review overview for a high-level explanation of the rebase, the re-layered Server and Agent modules, and the substantive additions that are particularly relevant to review. Use the requirements trigger map to explore selection conditions, package applicability, and module composition alongside the draft text.

Reviewers are encouraged to provide comments by opening an issue in the AppSW-iTC repository. Select the template that fits the cPP, Supporting Document, PP-Module, or PP-Configuration; identify the document and section; and include a proposed resolution where possible.

Table 3. Version 2.0 Public Review Documents
Title Version Links

Collaborative Protection Profile for Application Software

2.0 Draft

PDF / HTML

Supporting Document Mandatory Technical Document: Evaluation Activities for Collaborative Protection Profile for Application Software

2.0 Draft

PDF / HTML

PP-Module for Application Software Server

2.0 Draft

PDF / HTML

Supporting Document Mandatory Technical Document: Evaluation Activities for PP-Module for Application Software Server

2.0 Draft

PDF / HTML

PP-Module for Application Software Agent

2.0 Draft

PDF / HTML

Supporting Document Mandatory Technical Document: Evaluation Activities for PP-Module for Application Software Agent

2.0 Draft

PDF / HTML

PP-Configuration for Enterprise Server Applications

2.0 Draft

PDF / HTML

PP-Configuration for Enterprise Server Applications and Agent/Application Component(s)

2.0 Draft

PDF / HTML

5. Security Architecture at a Glance

The Version 2.0 draft organizes the application-software family into the following layers:

  1. Base cPP and Supporting Document — define the common application-software requirements and Evaluation Activities.

  2. Server PP-Module and Supporting Document — extend the base with requirements and evaluation material for Server application roles.

  3. Agent PP-Module and Supporting Document — extend the base with requirements and evaluation material for Agent/application component roles.

  4. PP-Configurations — identify the Base + Server and Base + Server + Agent combinations and explain how components map to the applicable requirements.

The Version 2.0 public-review guide explains the distributed TOE model, component allocation, platform boundaries, and worked deployment examples, with links to the draft text.

6. Technical Decisions

Technical Decisions clarify and update the cPP and related documents between release cycles.

7. Archives and Previous Versions

The Version 1.0 documents, published on April 6, 2022, and their release package remain available below. The current published Version 1.0e set is listed in Current Published Documents.

Version 1.0

Publication Date

April 6, 2022

Sunset Date

Active

Retired Date

Active

The following documents are included in Version 1.0:

Table 4. Public Release v1.0 Documents
Title Version Links

collaborative Protection Profile for Application Software - [cPP_APP_SW]

1.0

PDF / HTML

Supporting Document Mandatory Technical Document: Evaluation Activities for collaborative Protection Profile for Application Software - [SD_APP_SW]

1.0

PDF / HTML

collaborative Protection Profile for Application Software - Allowed With List

1.0

PDF

collaborative PP-Module for Server Applications [MOD_Server]

1.0

PDF / HTML

Supporting Document Mandatory Technical Document: Evaluation Activities for collaborative Protection Profile Module for Server Applications [SD_MOD_Server]

1.0

PDF / HTML

PP-Configuration for Enterprise Server Applications [cPP + MOD_Server]

1.0

PDF / HTML

collaborative PP-Module for Agent Applications [MOD_Agent]

1.0

PDF / HTML

Supporting Document Mandatory Technical Document: Evaluation Activities for collaborative Protection Profile Module for Agent Applications [SD_MOD_Agent]

1.0

PDF / HTML

PP-Configuration for Enterprise Server Applications and Client Agent(s) [cPP + MOD_Server + MOD_Agent]

1.0

PDF / HTML

Table 5. GitHub Public Release Packages
Title Link

cPP + Modules V1.0 Release package

Release package

8. Participate and Source Repositories

Public review welcomes input from Certification Bodies, laboratories, vendors, users, and researchers. Use a GitHub Issue for a specific document comment or request for interpretation. Select the relevant document template, identify the section, and include a proposed resolution where possible.

To join the AppSW-iTC, contact cm-itc-mailing-list@gmail.com.

The Version 2.0 overview and architecture summaries are explanatory aids. The linked cPP, Supporting Documents, PP-Modules, and PP-Configurations provide the document text for the identified release or review draft.