Menu

SUSE Earns Highest Level Accreditation for its SLES Linux Distribution, Doubles Down on Security

The News: SUSE has earned the highest level accreditation for its flagship SLES Linux distribution. Announced this week, the Common Criteria EAL 4+ certification for the SUSE Linux Enterprise Server (SLES) 15 SP2 is now EAL 4+ level certified for IBM Z, Arm, and x86-64 architectures, signifying compliance with the most demanding security requirements for mission critical infrastructure. Read the full press release from SUSE here.

SUSE Earns Highest Level Accreditation for its SLES Linux Distribution, Doubles Down on Security

Analyst Take: The news that SUSE has earned the highest level accreditation for its SLES Linux distribution was welcome news. With the daily headlines filled with high profile hacking attacks, and the reality that ransomware is focused on critical infrastructure, security has never been more of a hot button issue. Against this backdrop, the announcement by SUSE concerning the security certification for the company’s SLES Linux distribution is incredibly timely.

What is Common Criteria?

Common Criteria (CC) is an international set of guidelines with 17 certificate authorizing member nations and 14 certificate consuming countries that provide specifications developed for evaluating information security products. These specifications are specifically designed to ensure they meet an agreed-upon security standard for government deployments. Given the provenance and widespread adoption of these specifications, many security focused organizations in Finance, Telco, Retail, and those focused on securing personally identifiable information (PII) use these specifications as a way to evaluate solutions

The Common Criteria specifications are broken into two areas: Protection Profiles and Evaluation Assurance Levels. A Protection Profile (PPro) defines a standard set of security requirements for a specific type of product. The Evaluation Assurance Level (EAL) specification defines the thoroughness of product testing.

Evaluation Assurance Levels range from 1-7, with seven being the highest-level of evaluation. Despite what you may think, a higher evaluation level does not mean the product has a higher level of security, only that the product went through more tests. The graphic below provides a quick overview of the EAL levels:

overview of the EAL levels
Image Credit: Common Criteria

In order to submit a solution for evaluation, the submitting vendor must complete a Security Target (ST) description. This vendor submission includes an overview of the product and the product’s security features, along with the vendor’s self-assessment detailing how the product is designed to conform to the relevant Protection Profile at the EAL the vendor chooses to be tested against. Following the vendor submission, the next step is for the laboratory to test the product to verify the product’s security features. The results of a successful evaluation form the basis for an official certification of the product.

In a Strategic Move, SUSE Doubling Down on Security is Smart

This is without question an indicator that SUSE is doubling down on security — which is smart strategy. As more and more organizations deploy Linux into mission critical environments, and UNIX deployments correspondingly decrease, the need for highly secure operating systems is becoming more prevalent. Against this backdrop, it is somewhat surprising that SUSE is currently the only provider of a general purpose Linux operating system with a secure software supply chain that is certified Common Criteria EAL 4+ for the IBM Z, Arm and x86-64 architectures given how prevalent these platforms are in governments and financial services organizations. Given their market leadership, it will be interesting to see when Red Hat receives this same certification.

Commenting on the announcement, Thomas Di Giacomo, SUSE Chief Technology and Product Officer said, “In today’s age of advanced hacking and service disruption, Common Criteria EAL 4+ level certification for SLES provides confidence to critical service providers such as governments, finance and banking companies, healthcare organizations, water and power companies, telecommunications providers, and others innovating at the edge.”

SUSE Linux Enterprise Server 15 SP2 was also certified by BSI, Germany’s Federal Office for Information Security, full details of that certification can be found here.

The Significance of SUSE’s EAL Certification

As vendors look to increase the security posture of their offerings and solutions, I expect to see a stronger focus on industry standards and specifications such as EAL as these independent specifications allow customers to make purchasing decisions based on independent verification. While the Common Criteria evaluation criteria are not a hard and fast insurance policy, they do form a basis for vendor evaluations and would form the basis for a series of questions in any Request For Information or Request For Proposal.

As deployment models become more fragmented — with solutions spanning IoT, edge, on-premises datacenter and increasingly hybrid and public cloud models — customers need a way to evaluate solutions and make informed decisions. Approaches such as Common Criteria and EAL address this requirement and will therefore become a key part of how vendors start to describe their offerings to potential customers.

SUSE taking a leadership position in certifying the ARM, IBM Z & LinuxONE and Intel x86-64 platforms is good for the Linux market as a whole, as it will force vendors such as Red Hat with RHEL and Canonical with Ubuntu to follow suit. I would expect these vendors to not be far behind in getting their Linux distributions certified. However, if Red Hat and Canonical do delay in getting their distributions certified, I would expect to see SUSE leverage their first mover advantage to drive further adoption in customer segments that will be focused on EAL ratings.

Disclosure: Futurum Research is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Other insights from Futurum Research:

Salesforce Rolls Out Its Slack-First Customer 360 Strategy 

With The Argus System, Microsoft Research And Collaborators Seek To Leverage Ethereum To Prevent Piracy

Qualcomm Spoke Partnership Brings C-V2X To Bicycles, Expands Smart Transportation Safety Ecosystem

Image Credit: Linux and Mainframe

Author Information

Steven engages with the world’s largest technology brands to explore new operating models and how they drive innovation and competitive edge.

Related Insights
AWS re:Invent 2025: Wrestling Back AI Leadership
December 5, 2025

AWS re:Invent 2025: Wrestling Back AI Leadership

Futurum analysts share their insights on how AWS re:Invent 2025 redefines the cloud giant as an AI manufacturer. We analyze Nova models, Trainium silicon, and AI Factories as AWS moves...
Pure Storage Q3 FY 2026 Results Revenue Up 16% YoY, Guidance Raised
December 4, 2025

Pure Storage Q3 FY 2026 Results: Revenue Up 16% YoY, Guidance Raised

Futurum Research analyzes Pure Storage’s Q3 FY 2026 results, highlighting enterprise platform adoption, hyperscaler momentum, and Portworx-led modernization....
NetApp Q2 FY 2026 Earnings Mix Shift Lifts Margins, AI Momentum Builds
November 26, 2025

NetApp Q2 FY 2026 Earnings: Mix Shift Lifts Margins, AI Momentum Builds

Futurum Research analyzes NetApp’s Q2 FY 2026 results, highlighting AI data platform traction, first-party cloud storage growth, and all-flash mix that lifted margins, alongside raised FY EPS and margin guidance....
Commvault’s Strategic Shift Redefining Resilience as a Strategic Imperative
November 25, 2025

Commvault’s Strategic Shift: Redefining Resilience as a Strategic Imperative

Fernando Montenegro, VP and Practice Lead at Futurum, shares insights on Commvault Shift 2025, highlighting the new Cloud Unity platform and the strategic shift to ResOps to unify IT, security,...
Microsoft Ignite 2025 AI, Agent 365, Anthropic on Azure & Security Advances
November 21, 2025

Microsoft Ignite 2025: AI, Agent 365, Anthropic on Azure & Security Advances

Analysts Nick Patience, Mitch Ashley, Fernando Montenegro, and Keith Kirkpatrick share insights on Microsoft's shift to agent-centric architecture, cementing the role of Agent 365 as the operational control plane and...
Cisco Q1 FY 2026 AI Demand Lifts Outlook and Orders
November 14, 2025

Cisco Q1 FY 2026: AI Demand Lifts Outlook and Orders

Futurum Research analyzes Cisco’s Q1 FY 2026 results, highlighting AI infrastructure demand, campus refresh momentum, and a cloud-first security transition that lifts recurring revenue visibility into the second half of...

Book a Demo

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.