Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

What does CC EAL6+ certified mean?

TL;DR

CC EAL6+ means a chip was evaluated under the Common Criteria standard at assurance level 6 of 7, with extra requirements on top. It says the chip’s security was examined very thoroughly. It says nothing about the wallet firmware or how the device is used.

Common Criteria

Common Criteria (CC) is an international standard (ISO/IEC 15408) for evaluating the security of IT products. An independent, accredited lab tests the product against a written description of what it should protect, and a national certification body issues the certificate.

The seven levels

LevelOfficial description
EAL1Functionally tested
EAL2Structurally tested
EAL3Methodically tested and checked
EAL4Methodically designed, tested and reviewed
EAL5Semiformally designed and tested
EAL6Semiformally verified design and tested
EAL7Formally verified design and tested

A higher level means a deeper, more rigorous evaluation. It doesn’t automatically mean a product is more secure: it means the claims about it were checked more thoroughly.

What the plus means

“Augmented”: extra requirements on top of the level. For secure elements this usually includes AVA_VAN.5, resistance to attackers with “high attack potential”: well-equipped labs trying probing, fault injection and side-channel attacks.

What it covers, and what it doesn’t

  • Covers: the chip, and sometimes its operating system or crypto library, as described in its certificate.
  • Doesn’t cover: the wallet’s firmware, the app on your computer, how the seed was generated, or your backups.

A wallet can use an EAL6+ chip and still have a firmware bug. That’s why the guide uses three brands, and why verifiable firmware matters too.

Which devices

The Ledger Nano S Plus uses an ST33K1M5 (EAL6+ per Ledger). The Trezor Safe 5 and BitBox02 Nova use an Infineon OPTIGA Trust M V3 (EAL6+). More on the chip itself in what is a secure element.