To best secure IoT-connected systems in critical infrastructures, the highest Cybersecurity is required in addition to functional Safety. The leading standard is Common Criteria (CC), which is a worldwide recognized standard supported by many countries. Using compliance matrices, it is easy to achieve the levels of industry standards such as DO-356A/ED-203A, IEC 62443 or ISO/SAE 21434. The presentation introduces the CC model, explains its functional and assurance components and, using the example of a secure gateway, explains how to proceed during development, what to look out for and what value an EAL 5+ certified RTOS offers in such applications.