Product Certifications - Check Point Software
Product Certifications
Check Point products consistently meet and exceed the stringent requirements established by internationally recognized standards, approval processes and independent security industry tests.
Need information for software security certifications (Common Criteria, FIPS 140, IPv6)? Contact us.
For other SOC, ISO, IEEE or hardware certifications please use your official channels through the sales organization.
For information on HW engineering certifications: EMC, EMI, Radio, Electrical Safety, click here.
Common Criteria
Common Criteria is an internationally recognized standard and an ISO standard (ISO-IEC15408) for evaluating the security claims of IT products and systems. Certification provides customers with a higher level of assurance that the security of a product as evaluated meets the standards for security requirements. Check Point has certified its Security Gateway and Management products to EAL4+ and later to the most current Protection Profiles.
IPv6
Security Gateway R82 Firewall is certified to US Government Standard USGv6R1 standard Certification and SDoC are published here. Check Point Force and Check Point Force Maestro is certified for:
NPP:
- FW Conformance v1.1 (UNH-IOL/38537)
- IDS Conformance v1.2 (UNH-IOL/38539)
- IPS Conformance v1.1 (UNH-IOL/38538)
Router:
- Core Interoperability v1.4 (UNH-IOL/38534)
- Core Conformance v1.4 (UNH-IOL/38533)
- SLAAC Interoperability v1.4 (UNH-IOL/38534)
- SLAAC Conformance v1.2 (UNH-IOL/38533)
- Addr Arch Interoperability v1.2 (UNH-IOL/38536)
- Addr Arch Conformance v1.2 (UNH-IOL/38535)
FIPS 140-2
FIPS 140-2 defines security requirements for cryptographic modules for US and Canadian governments in NSTISSP #11.
Check Point Force is certified on R81.20 and R82
SMB Spark is certified on R81.10.10
C5
Cloud Computing Compliance Controls Catalog (C5) is a German Government-backed attestation scheme introduced in Germany by the Federal Office for Information Security (BSI) to help organizations demonstrate operational security against common cyber-attacks when using cloud services within the context of the German Government’s “Security Recommendations for Cloud Providers.
SOC 2
A SOC 2 compliance report demonstrates to customers that a respected third party has examined a provider’s services and those services meet a set of high security standards for security, availability, processing integrity, confidentiality and privacy. Check Point has achieved SOC 2 compliance for Check Point Dome9, Threat Emulation and Mobile Threat Defense services.
ISO
Leveraging our world-class security program, we were awarded certifications such as ISO/IEC 27000-series, ensuring information assets such as financial info, intellectual property, and employee details, are safe and secure.
NSS Labs
NSS Labs, Inc. is recognized globally as the most trusted source for independent, fact-based cybersecurity guidance. Check Point actively participates in NSS Labs tests, excelling in the industry’s most comprehensive third-party firewall, NGFW, Breach Prevention Systems and intrusion prevention system (IPS) group testing to date.
DESC
DESC stands for the Dubai Electronic Security Center. It is a Dubai government entity responsible for implementing and developing cybersecurity practices, setting standards, and combating cyber threats across the emirate. DESC also collaborates with other government entities and organizations to strengthen Dubai’s position in cybersecurity innovation and safety.
Section 508
Section 508 of the Rehabilitation Act of 1973 (29 USC § 794d) requires that when U.S. Federal government agencies develop, procure, or maintain, information and communication technology (ICT), that it is accessible to persons with disabilities. Check Point complies with Section 508, and is compatible with assistive technology.
NIAPC*
The NATO Information Assurance Product Catalogue (NIAPC) established under Directive AC/322-D(2010)0042 (22-09-2010), provides NATO nations, and NATO civil and military bodies with a catalogue of Information Assurance (IA) products, Protection Profiles and Packages that are in use or available for procurement to meet operational requirements.
CSfC
NSA/CSS’s Commercial Solutions for Classified (CSfC) Program has been established to enable commercial products to be used in layered solutions protecting classified NSS data. This will provide the ability to securely communicate based on commercial standards in a solution that can be fielded in months, not years.
Cyber Essentials Plus
Launched in 2014, the Cyber Essentials Scheme serves as part of the National Cyber Security Strategy to help British organizations bolster their defenses against cyber-attack. The CESG NCSC Cyber Essentials Plus accreditation offers a higher level of assurance by externally testing an organization’s cyber security approach with an in-depth analysis of the information systems.
ICSA Labs
ICSA Labs provides third-party testing and certification of security and health IT products, as well as network-connected devices, to measure product compliance, reliability and performance for most of the world’s top technology vendors. Independent testing and certifications for Firewall and IPSec, including the security functions of data source authentication, data integrity and confidentialities.
- NATO has suspended the NIAPC due to internal funding constraints. Check Point’s previous listing under the NIAPC were based upon Common Criteria certifications (NIAP Protection Profile and EAL4+). In the absence of the NIAPC, we recommend that agencies refer to these and check with NATO staff.