IT Brief Ireland - Technology news for CIOs & IT decision-makers
Ireland
Hitachi Vantara wins Common Criteria storage certification

Hitachi Vantara wins Common Criteria storage certification

Tue, 6th Oct 2026 (Yesterday)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Hitachi Vantara has secured Common Criteria certification for its VSP One Block storage platform, with the accreditation applying to systems assessed under the international security standard.

The certification covers cryptographic support, identification and authentication, security management, and trusted communications. Hitachi Vantara said the result is intended to give government agencies and organisations in regulated sectors greater assurance when assessing infrastructure for sensitive and mission-critical data.

Common Criteria, formally known as ISO/IEC 15408, is used to evaluate information technology products against defined security requirements. The certified VSP One Block systems were assessed against the collaborative Protection Profile for Network Devices Version 3.0e.

The evaluation covered security auditing, as well as controls for authentication, encryption, management, and communications. The certification was issued under the Japan IT Security Evaluation and Certification Scheme, administered by Japan's Information-technology Promotion Agency, following evaluation by ECSEC Labouratory.

Under the Common Criteria Recognition Arrangement, certificates issued by participating schemes can be recognised across member nations. The certified product is the VSP One B20 model, and the certification remains valid through 2031.

Regulated sectors

The move comes as technology buyers in government and heavily regulated industries face growing scrutiny over how suppliers protect critical data. Concerns about data sovereignty, cyber risk, and compliance have pushed independent validation higher in procurement and vendor assessment processes.

Hitachi Vantara cited industry research showing that many organisations still lack mature sovereignty governance and technical architecture. The same research found that technical hurdles have become a more prominent obstacle over the past year.

Against that backdrop, third-party certifications that provide external evidence of product testing against established requirements are drawing greater attention. For storage and infrastructure suppliers, such certifications can play a role in bids where buyers need formal assurance rather than vendor claims alone.

"Organisations are under immense pressure to demonstrate that the technology supporting their most critical data has been proven to meet rigorous security standards," said Octavian Tanase, Chief Product Officer, Hitachi Vantara.

"Common Criteria provides independent validation of the critical security capabilities of VSP One Block, and it is another proof point in the broader data and cyber resilience solutions we have built across the VSP One portfolio, helping customers protect critical information, reduce risk and strengthen organisational resilience across operational, financial and governance priorities," Tanase said.

Broader security push

Hitachi Vantara is positioning the certification as part of a broader security and resilience strategy for its storage portfolio. Its approach aligns with the NIST Cybersecurity Framework 2.0 and includes tools to protect systems, identify weaknesses, detect intrusions, and support recovery after an attack.

The company also said its development practices have previously been assessed against the US government's Secure Software Development Framework through a third-party attestation process confirmed by the Cybersecurity and Infrastructure Security Agency. Hitachi Vantara is also a signatory to the agency's Secure by Design pledge.

Alongside certification and software development controls, Hitachi Vantara highlighted data protection features within VSP One Block, including immutable data protection and ransomware detection using CyberSense. These functions are designed to help organisations identify suspicious activity and locate clean data for recovery.

The company also offers commercial assurances tied to the platform, including a 100% data availability guarantee and, for qualifying systems, a cyber resilience guarantee covering a clean recovery point after a cyberattack. Such guarantees are increasingly used by infrastructure vendors to differentiate support commitments in a crowded market.

Federal interest

Security certifications can carry particular weight in the public sector, where procurement teams often require independent evidence that products meet established standards. That is especially true for systems involved in critical services or sensitive workloads.

Mark Serway, President and CEO of Hitachi Federal, linked the certification to those public sector requirements.

"Government organisations need confidence that the infrastructure supporting critical missions has been evaluated against recognised security requirements," said Mark Serway, President and CEO, Hitachi Federal.

"Independent certifications such as Common Criteria provide another important source of assurance during technology evaluation, while Hitachi Vantara's broader cyber resilience capabilities help agencies protect access to critical data and maintain continuity when disruptions occur," Serway said.