The DBMS-iTC develops internationally agreed Common Criteria security requirements and evaluation activities for database management systems, their cryptographic services, and their cloud deployment models.

Public review is open. The Base cPP and Supporting Document Version 2.0 review runs through 10 August 2026. The coordinated PP-Modules and PP-Configurations are available as Version 0.5 review drafts.

Introduction

The Database Management Systems international Technical Community brings together Certification Bodies, Common Criteria laboratories, vendors, government participants, and subject-matter experts to create requirements for repeatable database security evaluations.

The DBMS protection-profile family is being organized around a stable Base cPP, a shared Cryptographic Functions Module, and deployment overlays for cloud-hosted and Database-as-a-Service products. PP-Configurations define the valid combinations presented in a Security Target.

Current Status

The currently published evaluation baseline remains the DBMS cPP Version 1.3 and Supporting Document Version 1.1. The iTC is simultaneously reviewing the Version 2.0 Base documents and the Version 0.5 PP-Module architecture.

Table 1. At-a-glance document status
Document family Version Status Key date Primary link

DBMS Base cPP

1.3

Official release

21 June 2023 certification

Download PDF

DBMS Supporting Document

1.1

Official release

15 March 2023 document date

Download PDF

Base cPP and SD

2.0

Public Review Draft 1

Comments due 10 August 2026

Open review set

PP-Modules and PP-Configurations

0.5

Public Review Draft 1

Revised 20 July 2026

Open review set

Current Published Documents

These are the documents currently published for use. Public-review drafts are listed separately and do not replace the official baseline until the publication process is complete.

Table 2. Official DBMS document set
Title Version Date Links

collaborative Protection Profile for Database Management Systems

1.3

13 March 2023

PDF

Supporting Document Mandatory Technical Document: Evaluation Activities for the collaborative Protection Profile for Database Management Systems

1.1

15 March 2023

PDF

Current Documents for Review

Base cPP and Supporting Document Version 2.0

Publication date

26 June 2026

End of comment period

10 August 2026

Review phase

Public Review Draft 1

The review set includes PDF and HTML editions, tracked-change PDFs, and text-diff editions against cPP Version 1.3 and SD Version 1.1.

PP-Modules and PP-Configurations Version 0.5

Publication date

30 June 2026

Last revised

20 July 2026

Review phase

Public Review Draft 1

The coordinated module review set contains three PP-Modules, three Supporting Documents, and three PP-Configurations. The Cryptographic Functions and Cloud modules are on the first publication track; the DBaaS material is included for architectural review on a later publication track.

Table 3. Module review families
Layer Document family Version Publication track

Shared security service

DBMS Cryptographic Functions Module and SD

0.5

First module publication set

Deployment overlay

DBMS in the Cloud Module and SD

0.5

First module publication set

Managed-service overlay

Database-as-a-Service Module and SD

0.5

Later publication track

Composition

Crypto, Cloud + Crypto, and DBaaS + Crypto PP-Configurations

0.5

Aligned with their modules

Security Architecture at a Glance

  1. Base cPP — establishes the common DBMS TOE, security problem, core SFRs, assurance requirements, and evaluation baseline.

  2. Cryptographic Functions Module — owns shared cryptographic services, protected channels, key-management integration, D@RE cryptography, and the coordinated classical/PQC selections.

  3. Cloud or DBaaS deployment overlay — adds only the security behavior and evidence specific to the selected deployment and service-responsibility model.

  4. PP-Configuration — identifies the valid Base-plus-module composition claimed by the Security Target.

The interactive review supplement provides a reader-oriented architecture walkthrough and traces SFRs, operations, dependencies, Evaluation Activities, and tests to the owning documents.

Technical Decisions

Technical Decisions clarify or modify the interpretation of published DBMS requirements. Evaluations should use the TDs applicable to the claimed document versions.

Table 4. Published Technical Decisions
TD ID Title HTML PDF

TD_DBMS_B_001

Update to Role Definitions and Security Attribute Management for Consistency

View

Download

TD_DBMS_B_002

Session Locking Mechanism Expansion

View

Download

Archives and Previous Versions

Archived material remains available for traceability. Its presence does not indicate that it is currently acceptable for new evaluations.

Table 5. Document and review archive
Document family Version Status Links

DBMS Base cPP

1.0

Previous public release

PDF

DBMS Supporting Document

1.0

Previous public release

PDF

DBMS PP-Modules and PP-Configurations

0.4

Previous public-review snapshot

Review archive

Participate and Source Repositories

Public review depends on input from Certification Bodies, laboratories, vendors, users, and researchers. Review comments and membership questions may be sent to dbms.itc@gmail.com. Repository issues and pull requests provide public traceability for proposed changes.

The PDF, PP-Module, PP-Configuration, and Supporting Document artifacts are authoritative. HTML editions and the requirements-map application are provided to improve navigation and review.