Choosing a Hardware Wallet: Understanding Security Certifications
When picking out a crypto hardware wallet, most people naturally focus on the obvious features—supported coins, screen size, connectivity options, price, and recovery backups. But one of the most critical details is often hidden deeper in the spec sheet: the security certification of the device's Secure Element.
You've probably seen labels like CC EAL5+, CC EAL6+, or EAL7 stamped on product pages, box packaging, or security whitepapers. Demystifying these ratings gives you a much clearer picture of the actual security architecture keeping your private keys safe.
CC stands for Common Criteria—it’s essentially the global benchmark used to test and verify how secure tech hardware actually is.
Then there's EAL, or Evaluation Assurance Level, which tells you how thoroughly a product was tested against those criteria. The scale goes from EAL1 up to EAL7—the higher the number, the more intense and strict the testing process was.
But here’s the catch: you shouldn't look at an EAL rating as a simple overall "security score" for an entire hardware wallet. In most crypto wallets, that certification only applies to the Secure Element—the dedicated, locked-down chip designed specifically to protect sensitive data like your private keys.
Ledger, for instance, points out that the Secure Elements inside their devices are certified at EAL5+ or EAL6+, depending on which model you pick up.
This is why users may see different ratings across hardware wallets. Several devices use CC EAL6+, including models such as the Ledger Flex, Ledger Stax, OneKey Pro, Tangem Wallet, Tangem Ring, and Trezor Safe 3, Safe 5, and Safe 7. Other devices, including the Ledger Nano X and several SafePal models, use CC EAL5+. The difference does not mean that an EAL5+ wallet is automatically unsafe or that an EAL6+ wallet is automatically the best choice. Instead, it indicates a different level of evaluated assurance for the certified security component.
The “+” after EAL5 or EAL6 is also important. It does not mean that EAL6+ has become EAL7. Whenever you see a "+" tacked onto the end, it simply means the chip passed extra security tests beyond the standard baseline for that EAL tier. Take Trezor, for example—its EAL6+ Secure Element includes added defenses specifically designed to ward off physical threats like fault injection and side-channel attacks.
Another term users may encounter is JIL, or Joint Interpretation Library. JIL is closely related to vulnerability assessment within Common Criteria. Microchip explains that JIL scoring focuses on how well sensitive cryptographic keys are protected in a Secure Element. Its explanation associates JIL Enhanced Basic with EAL4, JIL Moderate with EAL5, and JIL High with EAL6 and EAL7 in the relevant assessment context.
This makes JIL particularly interesting when evaluating the security of hardware wallets, because protecting private keys is one of the central functions of a Secure Element. Nevertheless, users should remember that a certification describes the evaluated component and scope of the assessment. The complete security of a hardware wallet also depends on its firmware, transaction-verification system, physical design, supply chain, recovery process, and how the user operates the device.
EAL7 represents the highest level in the Common Criteria EAL scale. Among the hardware wallets listed in our comparison, we did not find a model carrying an advertised CC EAL7 certification. Modern devices such as the Trezor Safe 7, for example, use an EAL6+ Secure Element alongside another independently auditable Secure Element rather than claiming an EAL7 wallet certification.
Therefore, when reading the box or technical specifications of a cold wallet, EAL5+, EAL6+, and related security markings are useful indicators of the evaluated security of its hardware components. They should be treated as one part of the security picture—not as a single number that determines the security of the entire cryptocurrency wallet.



