
Indonesia’s digital economy is expanding rapidly, with financial services, telecoms, and government agencies increasingly reliant on secure digital platforms. To safeguard this growth, the Badan Siber dan Sandi Negara (BSSN), the State Cyber and Crypto Agency has introduced new regulations under Peraturan No. 7 Tahun 2024. These rules set clear expectations for IT security evaluations, requiring products protecting vital national infrastructure to achieve certification based on the Common Criteria (CC) standard
Why BSSN Matters
As Indonesia strengthens its national cyber resilience, BSSN has emerged as the primary authority guiding how technology providers safeguard critical systems. By mandating Common Criteria evaluations, BSSN ensures that only proven, rigorously tested solutions are deployed in sectors deemed critical to national security, economic stability, and public trust.
BSSN requires IT products protecting vital national infrastructure to be certified at a minimum of Common Criteria EAL3. For other IT products, certification is voluntary and may apply at lower levels, such as EAL2. This is a step up from the previously fragmented certification framework, giving enterprises and regulators a consistent benchmark for assessing security.
What the New Requirement Means for Industry
For businesses operating in financial services, telecom, healthcare, and government, BSSN’s framework is more than just a compliance requirement, it is a license to operate. Companies must now demonstrate that their IT products meet CC certification, supported by independent testing and ongoing audits. Certificates are valid for five years, with mandatory surveillance to ensure continuous security
Failure to comply may not only expose organizations to regulatory penalties but also to reputational damage, as partners and customers increasingly expect adherence to global standards. Importantly, Indonesia also recognizes certificates issued abroad under international agreements, reinforcing the credibility of certified solutions across regional and global markets.
V-Key Driving Trusted Security
V-Key is uniquely positioned to help organizations meet and exceed BSSN’s requirements. Our V-OS Virtual Secure Element is the world’s first and only software-based technology certified to Common Criteria EAL3+, going beyond the minimum EAL2/EAL3 requirements set by BSSN. This patented innovation delivers military-grade protection for cryptographic keys, sensitive data, and application logic without relying on dedicated hardware.
By embedding this tamper-resistant technology into all our mobile security offerings, V-Key enables enterprises to achieve compliance while supporting innovation and scale. Our solutions, powered by V-OS, are trusted across 20 countries and protect over 500 million devices.
Compliance-Ready Solutions from V-Key:
All V-Key solutions are powered by the V-OS Virtual Secure Element (CC EAL3+ certified), ensuring compliance with BSSN’s requirements while addressing specific security and business needs:
- V-Key ID – A unified digital identity solution that binds users, devices, and apps, streamlining compliance across digital ecosystem.
- V-OS Mobile App Protection – Guards against tampering, cloning, and malware attacks to keep applications secure and compliant.
- V-OS Smart Token – A software-based alternative to OTP tokens, delivering strong authentication aligned with regulatory expectations.
With V-Key’s certified technology, organizations in Indonesia can meet BSSN’s Common Criteria requirements confidently while gaining the flexibility to scale digital services securely across banking, telecom, and government platforms.
Connect with us to discover how V-Key helps your organization stay ahead of BSSN’s compliance requirements.