Abstract. Besides the pure technical features, the usability of a PKIenabled application plays a crucial role since the best security application will fail in practice if its usability is insufficient. We present a generic framework to evaluate the usability and utility of PKI-enabled applications with respect to their security features. Our approach is modeled on the Common Criteria methodology and consists of 15 evaluation categories that cover all the relevant topics, namely deployment, ergonomics, and technical features.