IT Security Evaluations

The evaluation framework ensures that every product or solution undergoes a structured and transparent assessment process. Covering surface evaluation, screening, and detailed pre-deployment checks, it safeguards ICT infrastructure against potential risks.

No Category Surface Evaluation (Bidding Phase) Screening Detailed Evaluation (Pre-deployment Phase)
1. Description Basic/Initial evaluation, provision of product/documents is essential to conduct surface evaluation. Comprehensive hardware screening to identify potential supply chain attacks embedded within hardware, software, or firmware components. This will be carried out after the completion of the surface evaluation prior to deployment of the solution in intended ICT Infrastructure.
2. Evaluation Timelines 15 working days 10 working days 3~6 Months
May vary depending upon the scope and complexity of the evaluation
3. Additional Requirements Document-based evaluation Sample-Based, Product/Solution must be delivered in Lab Deployment of complete solution in Lab(s) environment (on-site)
4. List of Documents As per NASCEL Guidebook
5. Evaluation Scope & Fee May vary depending upon the scope and complexity of the evaluation
6. Pre-requisites Submission of product or Annex A documents and Payment confirmation

IT Security Evaluations Documents List

Surface Evaluation Screening Detailed Evaluation
  1. Administrative / Installation Manual (Installation, Configuration, Operations)
  2. User / End-User Manual
  3. Developer / API / SDK Guide (if applicable)
  4. Upgrade, Patch & Lifecycle Management Guide
  5. End-of-Sale (EOS) / End-of-Life (EOL) Information
  6. Product Release Date & Version History
  7. Supported Operating Systems / Platforms / Firmware Versions
  8. Product Model, Type & Category
  9. Available Features & Functional Specifications
  10. Performance Benchmarks (with and without advanced features enabled)
  11. Supported Security Protocols & Standards
  12. Publicly Known Vulnerabilities (CVE/Advisory) — Exploit Reports (if any)
  13. Security Certifications (e.g., CC, NIST, FIPS, ISO, etc.)
  14. Industry Rankings / References (e.g., Gartner, Forrester, NSS Labs, etc.)
  15. Vendor Legitimacy Status (if applicable)
  16. Cryptographic Specifications (Encryption, VPN, SSL/TLS etc.)
  17. Proposed Deployment Scenario
  18. Any other product/solution-specific documentation as applicable
  1. Administrative / Installation Manual (Installation, Configuration, Operations)
  2. User / End-User Manual
  3. Security Hardening & Compliance documentation
  4. Operating Systems / Platforms / Firmware Versions
  5. Product Datasheet (Model, Firmware Type, Category)
  6. Product Datasheet
  7. Chipset / Processor details with manufacturer info
  8. Mil-Std (If Claimed)
  9. Chipset / Architecture Details
  10. Bill of Materials (BOM) — major ICs, controllers, memory modules
  11. End-of-Sale (EOS) & End-of-Life (EOL) dates
  12. Certificates:
    1. FCC ID / Certification
    2. CE Marking compliance
    3. RoHS (Restriction of Hazardous Substances) Certificate/report
    4. EnergyStar / Green IT Certification
  13. Country-specific safety & EMI/EMC compliance reports

All documents required in Surface Evaluation, plus the additional documents below:

  1. High-Level Design (HLD)
  2. Low-Level Design (LLD)
  3. Deployment Architecture Diagram
  4. Data Flow Diagram
  5. Process Flow Diagrams
  6. Network & Security Architecture Documents
  7. System Integration Documentation
  8. Test Cases & Test Reports
  9. Technical Compliance Matrix
  10. Audit & Penetration Testing Reports (if available)
  11. Security Hardening & Compliance Guide
  12. Interactive sessions and support deemed necessary during evaluation