-
Introduction
NCDC-Ready program intends to qualify various user-cryptographic-hardware (USB Tokens
/ Smartcards), Hardware Security Modules (HSMs), applications, etc. for use with
the Saudi PKI Infrastructure.
The purpose of such qualification is to be selective in the usage of hardware /
software in the Saudi PKI from a security viewpoint. NCDC may conduct appropriate
testing to ensure that the hardware / software used in the Saudi PKI meets stringent
security requirements and helps mitigate risks associated with the usage of such
devices/applications.
At the current stage, the program only includes qualification for user-cryptographic-hardware,
such as Cryptographic USB Tokens and/or Smartcards.
A cryptographic hardware such as a USB token or a smartcard is a hardware device
with a built-in key store implementation that generates and securely stores private
keys. Tokens are tamper-evident, cannot be duplicated, and the PIN is stored encrypted,
all of which helps protecting the user's digital ID from theft.
NCDC utilizes such hardware to be able to perform cryptographic operations such
as digital signatures and encryption for privacy purposes, authentication for e-commerce
and e-government transactions.
NCDC started receiving requests from USB token vendors to be a part from current
list of approved and qualified user-cryptographic-hardware in NCDC. Such hardware
should meet the NCDC evaluation criteria in different aspects:
- Cryptographic and Security compliance requirements.
- Application integration and development requirements.
After passing the required tests as mandated by the NCDC-Ready program evaluation
criteria, and after measuring compliance to the mandatory requirements, an executive
report will be submitted to the management for their review and approval.
The approved token will be list in the NCDC website as a qualified token to be use
with the Saudi PKI Infrastructure.
This is a lite version of NCDC-Ready Program document describes the Ready program
and general process and phases to be done to qualify such a token.
-
NCDC Ready Program Unsupported Configurations Policy
An unsupported product configuration is defined as any product configuration that
is not explicitly indicated as supported in the NCDC-Ready list.
NCDC performs comprehensive engineering and verification of Entrust products with
operating systems and third-party products which are available for viewing in the
NCDC-Ready list.
NCDC policy for the support of product configurations
A product configuration may be unsupported if:
- NCDC or Entrust or a third-party vendor has knowledge that the combination of an
Entrust product and a third-party product does not function properly.
- No NCDC-sponsored configuration testing has occurred.
- The product configuration was initially supported but such configuration has been
superseded by a more recent release of either an Entrust product or a third-party
product, resulting in the combination of the Entrust product and the third party
product no longer functioning together properly.
Notes
As NCDC, Entrust and third-party products evolve, changes may arise such that the
integration may stop functioning. It is important that you take note of the specific
versions of the software that are indicated in the NCDC-Ready list.
If you would like NCDC to support a product configuration that is currently unsupported:
Contact ready@ncdc.gov.sa and submit a request
for the required product configuration.
-
FAQ
-
What does the NCDC Ready enable?
The NCDC Ready will enable the vendor’s token to be qualified to be used within
the Saudi PKI cloud.
-
Why Should I Join?
The NCDC will allow only the qualified tokens to be used within the Saudi PKI cloud.
-
What if my company is not ready for NCDC Ready?
This is a good opportunity to the company to know about the NCDC Ready program and
it’s requirements. Also, to know how the NCDC Ready program qualification process
to be done to be qualified in the future.
-
If my product is still in development, but I am hoping to become NCDC Ready upon
its release?
This is a good opportunity to the company to speed up the process to meet all the
NCDC Ready program requirements to be qualified in the future.
-
We’re ready to get started. How do we join the NCDC Ready Program?
It’s our pleasure to join the NCDC-Ready Program. Just contact
ready@ncdc.gov.sa and they will help you to start the program. Also, you
can visit our website
www.ncdc.gov.sa for more
information.
-
How long does it take NCDC Ready program to process my application?
There is no guarantee to finish the process within a certain time, because it depends
on meeting the NCDC Ready Program requirements. But, usually around 3 months to
get the qualification result.
-
With the program changes, does my company need to enter into a new agreement?
NCDC Ready program try to be consistence. But, duo to security reasons or management
views, the NCDC Ready program has the right to change in its requirements. Of course,
the current qualified tokens will be notified about any change and its reflections.
-
Does NCDC Ready verification provide a warranty or guarantee related to NCDC Ready
used products?
The NCDC Ready program will not provide any sort of warranty or guarantee related
to NCDC Ready used products.
-
How do I know if a product is NCDC Ready?
All the qualified tokens will be published in the NCDC website.
-
Where can I find answers to questions not addressed here?
It’s our pleasure to answer any questions or inquiries related to NCDC-Ready Program.
Just contact
ready@ncdc.gov.sa or you can
visit our website
www.ncdc.gov.sa for more
information.
-
Contact us
Tel: +966-1-452-2197
Fax: +966-1- 452-2034
ready@ncdc.gov.sa