The DBMS-iTC develops internationally agreed Common Criteria security requirements and evaluation activities for database management systems, their cryptographic services, and their cloud deployment models.
-
Current official cPP
Version 1.3 · PDF -
Current official SD
Version 1.1 · PDF -
Public review status
Active drafts and review dates -
PP-Configuration architecture
Base, Crypto, Cloud, and DBaaS composition -
Technical Decisions
Published DBMS interpretations
Introduction
The Database Management Systems international Technical Community brings together Certification Bodies, Common Criteria laboratories, vendors, government participants, and subject-matter experts to create requirements for repeatable database security evaluations.
The DBMS protection-profile family is being organized around a stable Base cPP, a shared Cryptographic Functions Module, and deployment overlays for cloud-hosted and Database-as-a-Service products. PP-Configurations define the valid combinations presented in a Security Target.
Current Status
The currently published evaluation baseline remains the DBMS cPP Version 1.3 and Supporting Document Version 1.1. The iTC is simultaneously reviewing the Version 2.0 Base documents and the Version 0.5 PP-Module architecture.
| Document family | Version | Status | Key date | Primary link |
|---|---|---|---|---|
DBMS Base cPP |
1.3 |
Official release |
21 June 2023 certification |
|
DBMS Supporting Document |
1.1 |
Official release |
15 March 2023 document date |
|
Base cPP and SD |
2.0 |
Public Review Draft 1 |
Comments due 10 August 2026 |
|
PP-Modules and PP-Configurations |
0.5 |
Public Review Draft 1 |
Revised 20 July 2026 |
Current Published Documents
These are the documents currently published for use. Public-review drafts are listed separately and do not replace the official baseline until the publication process is complete.
| Title | Version | Date | Links |
|---|---|---|---|
collaborative Protection Profile for Database Management Systems |
1.3 |
13 March 2023 |
|
Supporting Document Mandatory Technical Document: Evaluation Activities for the collaborative Protection Profile for Database Management Systems |
1.1 |
15 March 2023 |
Current Documents for Review
Base cPP and Supporting Document Version 2.0
- Publication date
-
26 June 2026
- End of comment period
-
10 August 2026
- Review phase
-
Public Review Draft 1
The review set includes PDF and HTML editions, tracked-change PDFs, and text-diff editions against cPP Version 1.3 and SD Version 1.1.
PP-Modules and PP-Configurations Version 0.5
- Publication date
-
30 June 2026
- Last revised
-
20 July 2026
- Review phase
-
Public Review Draft 1
The coordinated module review set contains three PP-Modules, three Supporting Documents, and three PP-Configurations. The Cryptographic Functions and Cloud modules are on the first publication track; the DBaaS material is included for architectural review on a later publication track.
| Layer | Document family | Version | Publication track |
|---|---|---|---|
Shared security service |
DBMS Cryptographic Functions Module and SD |
0.5 |
First module publication set |
Deployment overlay |
DBMS in the Cloud Module and SD |
0.5 |
First module publication set |
Managed-service overlay |
Database-as-a-Service Module and SD |
0.5 |
Later publication track |
Composition |
Crypto, Cloud + Crypto, and DBaaS + Crypto PP-Configurations |
0.5 |
Aligned with their modules |
Security Architecture at a Glance
-
Base cPP — establishes the common DBMS TOE, security problem, core SFRs, assurance requirements, and evaluation baseline.
-
Cryptographic Functions Module — owns shared cryptographic services, protected channels, key-management integration, D@RE cryptography, and the coordinated classical/PQC selections.
-
Cloud or DBaaS deployment overlay — adds only the security behavior and evidence specific to the selected deployment and service-responsibility model.
-
PP-Configuration — identifies the valid Base-plus-module composition claimed by the Security Target.
The interactive review supplement provides a reader-oriented architecture walkthrough and traces SFRs, operations, dependencies, Evaluation Activities, and tests to the owning documents.
Technical Decisions
Technical Decisions clarify or modify the interpretation of published DBMS requirements. Evaluations should use the TDs applicable to the claimed document versions.
| TD ID | Title | HTML | |
|---|---|---|---|
TD_DBMS_B_001 |
Update to Role Definitions and Security Attribute Management for Consistency |
||
TD_DBMS_B_002 |
Session Locking Mechanism Expansion |
Archives and Previous Versions
Archived material remains available for traceability. Its presence does not indicate that it is currently acceptable for new evaluations.
| Document family | Version | Status | Links |
|---|---|---|---|
DBMS Base cPP |
1.0 |
Previous public release |
|
DBMS Supporting Document |
1.0 |
Previous public release |
|
DBMS PP-Modules and PP-Configurations |
0.4 |
Previous public-review snapshot |
Participate and Source Repositories
Public review depends on input from Certification Bodies, laboratories, vendors, users, and researchers. Review comments and membership questions may be sent to dbms.itc@gmail.com. Repository issues and pull requests provide public traceability for proposed changes.
The PDF, PP-Module, PP-Configuration, and Supporting Document artifacts are authoritative. HTML editions and the requirements-map application are provided to improve navigation and review.