Version 202 1-01 ® TÜV, TUEV and TUV are ® TÜV, TUEV and TUV are registered trademarks. Any use or application requires prior approval. Certificate Standard Common Criteria for Information Technology Security Evaluation (CC), Version 3.1 Revision 5 Parts 1, 2 & 3 (ISO/IEC 15408-1, ISO/IEC 15408-2 & ISO/IEC 15408-3) Certificate number CC-22-0289060 TÜV Rheinland Nederland B.V. certifies: Certificate holder Veridos GmbH Truderinger Straße 15, 81677 Munich, Germany Developer Giesecke+Devrient Mobile Security GmbH Prinzregentenstraße 159, 81677 Munich, Germany Product and assurance level Sm@rtCafé® Expert 8.0 C1 Assurance Package: EAL6 augmented with ALC_FLR.1 Protection Profile Conformance: Java Card System- Open Configuration Protection Profile, version 3.1, April 2020, registered under the reference BSI-CC- PP-0099-V2-2020 Project number 0289060 Evaluation facility Common Criteria Recognition Arrangement for components up to EAL2 and ALC_FLR.3 SOGIS Mutual Recognition Agreement for components up to EAL 7 and ALC_FLR.3 SGS Brightsight BV located in Delft, the Netherlands Applying the Common Methodology for Information Technology Security Evaluation (CEM), Version 3.1 Revision 5 (ISO/IEC 18045) The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation version 3.1 Revision 5 for conformance to the Common Criteria for IT Security Evaluation version 3.1 Revision 5. This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete certification report. The evaluation has been conducted in accordance with the provisions of the Netherlands scheme for certification in the area of IT security [NSCIB] and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced. This certificate is not an endorsement of the IT product by TÜV Rheinland Nederland B.V. or by other organisation that recognises or gives effect to this certificate, and no warranty of the IT product by TÜV Rheinland Nederland B.V. or by any other organisation that recognises or gives effect to this certificate, is either expressed or implied. Validity Date of 1st issue : 01-09-2022 Certificate expiry : 01-09-2027 Accredited by the Dutch Council for Accreditation R.L. Kruit, LFM Systems TÜV Rheinland Nederland B.V. Westervoortsedijk 73, 6827 AV Arnhem P.O. Box 2220, NL-6802 CE Arnhem The Netherlands