Skip to main content

Your submission was sent successfully! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates from Canonical and upcoming events where you can meet our team.Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

An error occurred while submitting your form. Please try again or file a bug report. Close

  1. Blog
  2. Article

Canonical
on 26 February 2019


Canonical has received Common Criteria EAL2 certification. The evaluation covers a fresh install of Ubuntu 16.04.4 LTS on one of the supported platforms listed in the certification report.

Common Criteria (CC) for Information Technology Security Evaluation is an international standard (ISO/IEC IS 15408) for Computer security certification. It provides an assurance that a product satisfies a defined set of security requirements. The security requirements for the evaluation are specified in the Security Target. The certification is based on the Operating System Protection Profile (OSPP) together with an extended requirement for virtualization. The evaluation was obtained through CSEC – The Swedish Certification Body for IT Security. The consulting for the evaluation was performed by atsec Information Security, a U.S. Govt and BSI accredited laboratory. The certification report is available on the CSEC website for more information.

Canonical has obtained an EAL2 certification which is recognized in 30 countries who are members of CCRA. This is a mandatory requirement for Government usage and also in financial institutions and organizations dealing with sensitive data.  

How to obtain Ubuntu Common Criteria certified configuration?

CC configuration requires a specific set of software and hardware that was used in the certification. The software bits that would put a system in evaluated configuration are available to Ubuntu Advanced  customers. This includes utilities to make the EAL2 configuration changes, additional packages, and the Evaluated Configuration Guide. The Evaluated Configuration Guide is a security guide that explains how to set up the evaluated configuration, and provides information to administrators and ordinary users to ensure secure operation of the system.

After a fresh install of Ubuntu 16.04.4 LTS server following the instructions in the evaluated configuration guide,  the additional software bits are executed to put the system into the EAL2 configuration. The EAL2 configuration includes the Ubuntu FIPS packages offering stronger cryptography.

Please get in touch for more details.

Contact us

The original version of this blog was posted here.

Related posts


Benjamin Ryzman
9 April 2025

SONiC: The open source network operating system for modern data centers

Networking Networking

Software for Open Networking in the Cloud (SONiC) is an open-source network operating system that has revolutionized data center networking. Originating as a Microsoft-led initiative in the Open Compute Project (OCP) in 2016, SONiC has rapidly gained traction among hyperscalers and switch hardware vendors, including Broadcom, Cisco, and N ...


Stephanie Domas
11 August 2025

A CISO’s guide to Application Security best practices 

Hardening Security

Effective AppSec is not a one-time fix but a continuous journey across every facet of your application’s lifecycle. By embracing a Secure Software Development Lifecycle (SSDLC) from the outset, diligently uncovering potential risks, and mastering your cybersecurity fundamentals, you lay a robust foundation for resilient applications. ...


ROS Noetic is EOL – take action to maintain fleet security

Robotics Article

As of May 2025, the Robot Operating System (ROS) Noetic Ninjemys officially reached its end of life (EOL). First released in 2020 as the final ROS (1) distribution, ROS Noetic has been the default choice for thousands of developers building on Ubuntu 20.04 LTS. For developers and businesses running mission-critical systems on ROS Noetic, ...