The DBMS-iTC develops internationally agreed Common Criteria security requirements and evaluation activities for database management systems, their cryptographic protections, and their tenant-operated and provider-operated cloud deployment models.
Current evaluation baseline DBMS cPP Version 1.3 and Supporting Document Version 1.1. |
ACTIVE PUBLIC COMMENT Base cPP and SD Version 2.0 Public Review Draft 1. Comments are due 10 August 2026. |
FULL MODULE REVIEW PP-Modules and PP-Configurations Version 0.5 Crypto + Cloud and Crypto + DBaaS review families; not an authoritative release. |
-
Public review status
Active drafts and review dates -
PP-Configuration architecture
Base, Crypto, Cloud, and DBaaS composition -
Technical Decisions
Published DBMS interpretations -
Document source repository
AsciiDoc sources and issue tracking -
Common Criteria Portal
DBMS-iTC community page -
Contribute or contact the iTC
Use GitHub Issues or Discussions
Introduction
The Database Management Systems international Technical Community brings together Certification Bodies, Common Criteria laboratories, vendors, government participants, and subject-matter experts to create requirements for repeatable database security evaluations.
The DBMS protection-profile family is being organized around a stable Base cPP and two composed module families: Cryptographic Functions + Cloud for tenant-operated deployments, and Cryptographic Functions + DBaaS for provider-operated managed services. PP-Configurations define the valid combinations presented in a Security Target.
Current Status
The site presents three separate publication states:
-
Authoritative release identifies the documents currently published for evaluation use.
-
Active public comment identifies the formal Version 2.0 review with a defined comment period.
-
Full module review identifies the complete Version 0.5 Crypto + Cloud and Crypto + DBaaS review set. It is available for feedback but does not replace either the authoritative release or the Version 2.0 Base-document review.
Module Review: Full PP-Module and PP-Configuration Set Version 0.5
FULL MODULE SET — PUBLIC REVIEW DRAFT 1
- Publication date
-
30 June 2026
- Last revised
-
20 July 2026
- Review phase
-
Public Review Draft 1
The coordinated review release contains all three PP-Modules, all three Supporting Documents, and all three PP-Configurations. The deployment-oriented review is organized around two complete composition families: Crypto + Cloud and Crypto + DBaaS. The Cryptographic Functions Module is included in both families and is reviewed in the context of each deployment model.
| Review family | Included module documents | Version | PP-Configuration |
|---|---|---|---|
Crypto + Cloud |
DBMS Cryptographic Functions Module and SD; DBMS in the Cloud Module and SD |
0.5 |
Base cPP + Crypto + Cloud |
Crypto + DBaaS |
DBMS Cryptographic Functions Module and SD; Database-as-a-Service Module and SD |
0.5 |
Base cPP + Crypto + DBaaS |
The Crypto-only PP-Configuration remains in the review package as the foundational Base cPP + Crypto composition used by both deployment-oriented families.
Security Architecture at a Glance
-
Base cPP — establishes the common DBMS TOE, security problem, core SFRs, assurance requirements, and evaluation baseline.
-
Cryptographic Functions Module — appears in both review families and owns the common cryptographic requirements, protected channels, key-management integration, D@RE cryptography, and the coordinated classical/PQC selections.
-
Crypto + Cloud — combines those cryptographic requirements with the security behavior and evidence for a tenant-operated cloud deployment.
-
Crypto + DBaaS — combines those cryptographic requirements with tenant isolation, provider-role separation, and the evidence model for a provider-operated managed database service.
-
PP-Configuration — identifies the valid Base-plus-module composition claimed by the Security Target.
The interactive review supplement provides a reader-oriented architecture walkthrough and traces SFRs, operations, dependencies, Evaluation Activities, and tests to the owning documents.
Technical Decisions
Technical Decisions clarify or modify the interpretation of published DBMS requirements. Evaluations should use the TDs applicable to the claimed document versions.
| TD ID | Title | HTML | |
|---|---|---|---|
TD_DBMS_B_001 |
Update to Role Definitions and Security Attribute Management for Consistency |
||
TD_DBMS_B_002 |
Session Locking Mechanism Expansion |
Archives and Previous Versions
Archived material remains available for traceability. These artifacts are neither the current authoritative release nor an active review set, and their presence does not indicate that they are acceptable for new evaluations.
| Document family | Version | Status | Links |
|---|---|---|---|
DBMS Base cPP |
1.0 |
Previous public release |
|
DBMS Supporting Document |
1.0 |
Previous public release |
|
DBMS PP-Modules and PP-Configurations |
0.4 |
Previous public-review snapshot |
Participate and Source Repositories
Public review depends on input from Certification Bodies, laboratories, vendors, users, and researchers. Use a GitHub Issue for a specific document change that should be tracked to resolution, or a GitHub Discussion for a broader design, community, or participation topic.
The PDF, PP-Module, PP-Configuration, and Supporting Document artifacts are authoritative. HTML editions and the requirements-map application are provided to improve navigation and review.
Active Public Comment: Base cPP and SD Version 2.0
PUBLIC REVIEW DRAFT 1
26 June 2026
10 August 2026
Public Review Draft 1
The review set includes PDF and HTML editions, tracked-change PDFs, and text-diff editions against cPP Version 1.3 and SD Version 1.1.
Open the complete Version 2.0 review set
Base cPP Version 2.0 PDF
Supporting Document Version 2.0 PDF