IGEL Blog

Why IGEL OS™ 12’s Common Criteria Evaluation Matters for Security, Resilience and Business Continuity
In nearly every conversation with CISOs and CIOs, behind architecture diagrams, risk registers and procurement checklists lies the same question: How do we distinguish a security promise from robust security evidence?
The German Federal Office for Information Security (BSI) now publicly lists IGEL OS 12 among the products and systems undergoing evaluation or certification. The Common Criteria process is registered under BSI-DSZ-CC-1294.
That distinction matters: IGEL OS™ 12 is not yet BSI-certified. The listing confirms that a formal Common Criteria evaluation and certification process is underway. Common Criteria provides a structured framework in which defined security functions and assurance claims are independently evaluated and reviewed under the supervision of the certification body.
Why This Matters for CISOs and CIOs
For CISOs, an independent evaluation can provide additional evidence for security architecture reviews, third-party risk assessments, audits and board-level assurance. For CIOs, it can support platform standardization, procurement decisions and modernization programs where security, operational efficiency and user experience need to work together.
It does not replace due diligence, but it makes due diligence less dependent on security claims alone.
The Resilience Question: Preserve Evidence or Restore Operations?
A cyber crisis exposes another uncomfortable truth: preserving forensic evidence and restoring business operations quickly can pull in opposite directions. Security teams need time and an unchanged system state for their investigation. The business needs critical employees and processes back online.
That tension is real and belongs on the executive agenda.
In Germany for example, BSI IT-Grundschutz provides a framework for information security, while BSI Standard 200-4 addresses business continuity management. These approaches complement one another rather than compete. What matters is a clearly governed decision-making process: triage the incident, determine whether the threat has been contained, define recovery priorities, and make any necessary trade-offs explicitly, with appropriate authorization and documentation.
When Endpoint Architecture Becomes Business Architecture
IGEL OS™ 12 is built on an immutable, read-only foundation with centralized policy and lifecycle management. The architecture is designed to limit persistent changes and reduce the endpoint attack surface.
That matters during normal operations, and even more when those operations are disrupted.
In appropriate IGEL Business Continuity & Disaster Recovery™ deployments using IGEL Dual Boot™, an affected Windows partition can be isolated and preserved for investigation while administrators boot the endpoint into IGEL OS™ and reconnect users to approved applications and services.
Incident responders retain forensic options while the business gains a controlled path back to productivity.
This operational example falls outside the scope of the current Common Criteria evaluation. It does, however, illustrate why a trusted endpoint foundation can be strategically relevant: it creates better options when security investigation and business continuity need to move forward at the same time.
A Positive Outlook Based on Evidence
We are confident as we look toward the next steps. Successful completion of the Common Criteria process would give customers an additional source of independent assurance when evaluating IGEL OS™ 12, particularly in the public sector, critical infrastructure, healthcare, financial services and other regulated or security-sensitive environments.
That could strengthen security questionnaires, procurement decisions, audit narratives and risk committee discussions.
What Successful Certification Could Support
SECURITY
Stronger evidence for risk reviews, audits and assurance discussions.
TECHNOLOGY
Greater confidence in standardization, procurement and modernization decisions.
BUSINESS
Clearer support for business continuity, productivity and executive risk discussions.
Certification is not a silver bullet, nor does it certify a customer’s entire security posture or business continuity program. It can, however, provide independent evidence supporting defined product security claims that have been assessed against established criteria.
Three Questions for the Leadership Team
- What evidence supports the security claims of our endpoint platform?
- How quickly can we restore trusted access after a cyber incident?
- Can we preserve forensic options without making the entire business wait?
Trust is good. Independent evidence is better.