Open Community Experience (OCX)

Unlocking product security certifications: Transparency through open source with sec-certs

28:14 · 21 Apr 2026 – 23 Apr 2026 · YouTube

About this talk

This talk, presented by Vashek Matyáš from Masaryk University and Jaroslav Reznik from Red Hat, explores the complexities of security certification ecosystems through the lens of the sec-certs project. It focuses on the analysis of security certifications such as Common Criteria (ISO 15408), EUCC, and FIPS 140, explaining how they evaluate ICT products using various documentation like security targets and evaluation reports. The speakers discuss how the sec-certs project enhances transparency by extracting and structuring data from thousands of certification documents, utilizing advanced parsing techniques and machine learning to create a searchable dataset accessible via API. They also highlight the importance of modeling dependencies among certified products to analyze vulnerabilities and systemic risks across the tech ecosystem, ultimately facilitating better procurement and compliance decisions.