TL;DR
CC EAL6+ means a chip was evaluated under the Common Criteria standard at assurance level 6 of 7, with extra requirements on top. It says the chip’s security was examined very thoroughly. It says nothing about the wallet firmware or how the device is used.
Common Criteria
Common Criteria (CC) is an international standard (ISO/IEC 15408) for evaluating the security of IT products. An independent, accredited lab tests the product against a written description of what it should protect, and a national certification body issues the certificate.
The seven levels
| Level | Official description |
|---|---|
| EAL1 | Functionally tested |
| EAL2 | Structurally tested |
| EAL3 | Methodically tested and checked |
| EAL4 | Methodically designed, tested and reviewed |
| EAL5 | Semiformally designed and tested |
| EAL6 | Semiformally verified design and tested |
| EAL7 | Formally verified design and tested |
A higher level means a deeper, more rigorous evaluation. It doesn’t automatically mean a product is more secure: it means the claims about it were checked more thoroughly.
What the plus means
“Augmented”: extra requirements on top of the level. For secure elements this usually includes AVA_VAN.5, resistance to attackers with “high attack potential”: well-equipped labs trying probing, fault injection and side-channel attacks.
What it covers, and what it doesn’t
- Covers: the chip, and sometimes its operating system or crypto library, as described in its certificate.
- Doesn’t cover: the wallet’s firmware, the app on your computer, how the seed was generated, or your backups.
A wallet can use an EAL6+ chip and still have a firmware bug. That’s why the guide uses three brands, and why verifiable firmware matters too.
Which devices
The Ledger Nano S Plus uses an ST33K1M5 (EAL6+ per Ledger). The Trezor Safe 5 and BitBox02 Nova use an Infineon OPTIGA Trust M V3 (EAL6+). More on the chip itself in what is a secure element.