HomeIntelligenceBrief
BREACH BRIEF⚪ Informational Advisory

Symantec Data Center Security 6.10 Earns Common Criteria EAL2+ Certification, Validating Controls for SOC 2 Audits

Symantec’s Data Center Security (DCS) 6.10 has been awarded Common Criteria (ISO/IEC 15408) certification at Evaluation Assurance Level 2+ (EAL2+). The independent assessment validates both the product’s security functions and its secure development lifecycle, offering organizations a trusted benchmark for control assurance. For SOC 2‑ready enterprises, the certification provides concrete evidence to map security controls and streamline audit readiness.

LiveThreat™ Intelligence · 📅 July 10, 2026· 📰 security.com
Severity
Informational
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
security.com

Symantec Data Center Security 6.10 Earns Common Criteria EAL2+ Certification

What Happened — Symantec’s Data Center Security (DCS) 6.10 received Common Criteria (ISO/IEC 15408) certification at Evaluation Assurance Level 2+ (EAL2+). An accredited third‑party lab independently validated both the product’s security functions and the secure development practices behind them. The certificate is effective from May 21 2026 through May 21 2031.

Why It Matters for Compliance & Audit Readiness

  • The certification supplies independent, verifiable evidence that maps directly to SOC 2 security criteria, streamlining audit preparation.
  • Continuous‑compliance programs can ingest the certification report as immutable proof of control effectiveness, reducing the need for duplicate assessments.
  • Control‑mapping teams gain a trusted benchmark for aligning DCS controls with internal policies, risk registers, and the Trust Services Criteria.

Who Is Affected — Enterprises that protect critical workloads in private or hybrid clouds, especially in technology/SaaS, cloud‑infrastructure, and financial‑services environments.

Recommended Actions

  • Add the Common Criteria report to your SOC 2 evidence repository and map its control assertions to the relevant Trust Services Criteria.
  • Verify that your secure development lifecycle continues to meet the CC requirements to maintain the certification’s validity.
  • Deploy a control‑mapping solution to continuously monitor the certification status and any future re‑evaluations. Source: Broadcom Symantec Blog

Technical Notes — The evaluation covered product security functions, vulnerability‑management processes, and secure coding practices; no specific CVEs were disclosed. Source: [Broadcom Symantec Blog]

📰 Original Source
https://www.security.com/product-insights/humble-brag-symantec-data-center-security-achieves-common-criteria-certification

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →