Skip to content

Comment

Security for Satellites under the Cyber Resilience Act: The answer Already Exists

Proven safety standards as the basis for CRA-compliant satellite systems

As space systems become more industrialized, cybersecurity can no longer remain mission-specific. The Cyber Resilience Act is introducing new assurance requirements for security-critical products and components. Before creating new frameworks, it is worth asking whether proven approaches such as Common Criteria already provide an answer.

Satellit umkreist die Erde
Essen | 27 August 2026

The space sector is experiencing rapid growth and increasing commercialisation. The trend is shifting away from mission-specific designs towards scalable and reusable product platforms, with increasing reliance on off-the-shelf technologies (COTS) and complex supply chains. At the same time, space systems are becoming an integral part of critical infrastructure and must command the trust of operators, customers and regulatory authorities alike.

As discussions surrounding the cyber security of space systems gather pace, there is growing pressure to develop entirely new security frameworks specifically tailored to the space sector. The intention is understandable. Space systems are unique, but before additional standards, frameworks and certification mechanisms are created, it is worth asking a simpler question: do we already have tried-and-tested approaches that solve a large part of the problem today?

CRA for Space Systems

One of the most significant regulatory developments in this context is the European Cyber Resilience Act (CRA), which sets out cybersecurity requirements for products with digital elements placed on the European market. It introduces product classes with different security requirements depending on their criticality, and many components used in space systems fall into higher classes, which means that an independent assessment becomes mandatory. This is, incidentally, in line with the inclusion of the space sector within the scope of NIS2 and underlines its importance for critical infrastructure and essential services.

In practice, only a few components determine the security of a satellite system, including cryptographic modules, interface units, the on-board computer and the communications subsystem. Together, they are responsible for the authentication of commands, the protection of communications, the verification of software integrity and the management of cryptographic keys. If these functions are compromised, the trustworthiness of the entire system is also at risk. Therefore, focusing on these crucial components has a disproportionately large impact on overall security and should consequently be the primary objective of the security assessment.

CC as a Framework

In line with the CRA’s risk-based approach, the security level should be proportionate to the impact of a security incident. Given the critical role of many space systems and their safety functions, assessment methods offering a high level of security are required, which is why the Common Criteria represent the obvious choice. The Common Criteria provide a structured framework for describing security objectives, identifying relevant threats, specifying the necessary security functions, and independently assessing whether these functions have been correctly implemented. This includes defining a clearly delineated Target of Evaluation (TOE) comprising only the security-relevant components and functions.

With EUCC, the European cybersecurity certification scheme based on the Common Criteria, this approach becomes part of a European certification framework designed to ensure harmonised and mutually recognised security for ICT products across the EU.

Creating a Protection Profile to set a Standard

Security profiles are a key component of the Common Criteria and can serve as a de facto standard within a product class. They define a set of common assumptions, threats, security objectives and security requirements against which products are assessed. For the space industry, this means that security requirements do not need to be redefined for every mission; instead, components can be assessed against a common and reusable benchmark.

A practical next step would be to define protection profiles within the space industry for the security-relevant components that are commonly found in satellite systems. Based on the components that have already been identified as primary assessment targets, common assumptions, threats, safety objectives and safety requirements could be defined once and reused across missions and platforms. This would create a common basis for assessment within the EUCC framework, whilst improving comparability, reusability and scalability across the industry. This would establish a common safety basis for the space industry and mark the first step towards treating safety-critical components as reusable, certifiable building blocks rather than mission-specific exceptions.

What TÜVIT can Contribute

The application of frameworks such as the Common Criteria in the space sector requires an understanding of system architectures, trust boundaries and how the scope of an assessment can be defined in a meaningful way. At TÜV Informationstechnik, we have been building up and applying this specialist knowledge for decades. We have been involved in Common Criteria assessments since the standard’s inception and are recognised as an assessment laboratory in Germany and other countries.

In addition to product assessments, we have also been involved in the development of security profiles in various fields, such as biometric systems, eHealth, database management systems and smart meters. In the space sector, TÜVIT has also contributed to the BSI’s Technical Guideline TR-03184 on information security for space systems, which defines cybersecurity measures and security requirements for both the space and ground segments. This is closely aligned with the approach outlined in this article: it defines what secure space systems should achieve, whilst the Common Criteria provide a structured way to assess and demonstrate that these requirements are met.

This combination of experience in assessment and profile development forms a practical basis for tackling similar challenges in the space sector. Supporting this transition involves working with manufacturers and system integrators to define the scope of assessments, interpret regulatory requirements and translate these into requirements that can be assessed and reused in practice.

Common Criteria


Independently tested security: TÜVIT supports you with testing and evaluation services in accordance with the Common Criteria. For transparent and internationally recognised IT security.

Cyber Resilience Act


Ready for the Cyber Resilience Act: From security requirements to obligations to provide evidence: TÜVIT supports companies on their journey towards CRA-compliant products.

Do you have any questions?

We're happy to help!