Symantec Data Center Security 6.10 Earns Common Criteria EAL2+ Certification
What Happened — Symantec’s Data Center Security (DCS) 6.10 received Common Criteria (ISO/IEC 15408) certification at Evaluation Assurance Level 2+ (EAL2+). An accredited third‑party lab independently validated both the product’s security functions and the secure development practices behind them. The certificate is effective from May 21 2026 through May 21 2031.
Why It Matters for Compliance & Audit Readiness —
- The certification supplies independent, verifiable evidence that maps directly to SOC 2 security criteria, streamlining audit preparation.
- Continuous‑compliance programs can ingest the certification report as immutable proof of control effectiveness, reducing the need for duplicate assessments.
- Control‑mapping teams gain a trusted benchmark for aligning DCS controls with internal policies, risk registers, and the Trust Services Criteria.
Who Is Affected — Enterprises that protect critical workloads in private or hybrid clouds, especially in technology/SaaS, cloud‑infrastructure, and financial‑services environments.
Recommended Actions —
- Add the Common Criteria report to your SOC 2 evidence repository and map its control assertions to the relevant Trust Services Criteria.
- Verify that your secure development lifecycle continues to meet the CC requirements to maintain the certification’s validity.
- Deploy a control‑mapping solution to continuously monitor the certification status and any future re‑evaluations. Source: Broadcom Symantec Blog
Technical Notes — The evaluation covered product security functions, vulnerability‑management processes, and secure coding practices; no specific CVEs were disclosed. Source: [Broadcom Symantec Blog]