Introduction

This page identifies the PP-Modules that the DBMS-iTC has defined for use with the collaborative Protection Profile for Database Management Systems (Version 2.0) in PP-Configurations. The Version 0.5 review set is organized around Crypto + Cloud and Crypto + DBaaS composition families. This page records their compatibility relationships; it does not itself replace a formal PP-Configuration when one is required by a scheme or publication package.

Use the DBMS issue templates for a specific composition or document change and DBMS-iTC Discussions for a broader architecture topic. See the public-review-process.html[participation tutorial] for step-by-step instructions.

Current Compatible Components

Table 1. Current compatible components
Component Version / Date Status Responsible iTC Use in PP-Configurations

collaborative PP-Module for DBMS Cryptographic Functions

Version 0.5, 2026-07-20

Full module review set

DBMS-iTC

May be claimed with the DBMS Base PP as cPP_DBMS + DBMS Cryptographic Functions Module. Required by both the Crypto + Cloud and Crypto + DBaaS composition families.

collaborative PP-Module for DBMS in the Cloud

Version 0.5, 2026-07-20

Full module review set

DBMS-iTC

May be claimed only in a PP-Configuration that includes the DBMS Base PP and the DBMS Cryptographic Functions Module: cPP_DBMS + DBMS in the Cloud Module + DBMS Cryptographic Functions Module.

collaborative PP-Module for Database-as-a-Service (DBaaS)

Version 0.5, 2026-07-20

Full module review set

DBMS-iTC

May be claimed only in a PP-Configuration that includes the DBMS Base PP and the DBMS Cryptographic Functions Module: cPP_DBMS + DBMS DBaaS Module + DBMS Cryptographic Functions Module. This provider-operated family is mutually exclusive with the tenant-operated DBMS in the Cloud Module.

Public Review PP-Configurations

Formal Public Review Draft 1 PP-Configuration documents for the DBMS module set are available at DBMS PP-Modules Version 0.5 Public Review Draft 1.

Table 2. Public review PP-Configurations
PP-Configuration Version / Date Links

PP-Configuration for cPP_DBMS and DBMS Cryptographic Functions Module

Version 0.5, 2026-07-20

PDF
HTML
AsciiDoc

PP-Configuration for cPP_DBMS, DBMS in the Cloud Module, and DBMS Cryptographic Functions Module

Version 0.5, 2026-07-20

PDF
HTML
AsciiDoc

PP-Configuration for cPP_DBMS, DBMS DBaaS Module, and DBMS Cryptographic Functions Module

Version 0.5, 2026-07-20

PDF
HTML
AsciiDoc

Components Under Development

No additional DBMS PP-Modules are currently listed outside the full Version 0.5 review set.

Configuration Notes

DBMS Cryptographic Functions Module

The DBMS Cryptographic Functions Module is the common cryptographic component of both the Crypto + Cloud and Crypto + DBaaS composition families. It defines the DBMS-specific requirements for key management, data-at-rest encryption, and data-in-transit protection while formally consuming applicable CCDB-018 Catalogue components. Every PP-Configuration supports the General-Purpose Cryptographic Deployment use case and may additionally claim the Enterprise Enhanced use case. Enterprise Enhanced constrains Catalogue selections for FIPS 140-3, NIAP, and CNSA 2.0 alignment but does not create a separate PP-Configuration.

DBMS in the Cloud Module

The DBMS in the Cloud Module addresses tenant-operated DBMS deployments on cloud infrastructure or platform services. It requires the DBMS Cryptographic Functions Module so that data-at-rest and data-in-transit protection remain TOE-enforced requirements rather than environmental assumptions.

DBMS DBaaS Module

The DBMS DBaaS Module addresses provider-operated managed database services. It is included in the full module review release as the Crypto + DBaaS family. A TOE should claim either the DBMS in the Cloud Module or the DBMS DBaaS Module according to whether the tenant or provider operates the DBMS.

Archived Components

No DBMS PP-Configuration components have been archived.