General Information

Abstract

This document provides the minimum requirements for the knowledge and skills of assessment body testers and validators performing testing activities and validating activities for a conformance scheme using ISO/IEC 19790 and ISO/IEC 24759.

Status
Published
Public Enquiry End Date
30-Jan-2025
Publication Date
26-Aug-2026
Technical Committee
ITC - Information technology
Current Stage
6060 - National Implementation/Publication (Adopted Project)
Start Date
24-Feb-2026
Due Date
01-May-2026
Completion Date
27-Aug-2026

Buy Documents

Standard

SIST EN ISO/IEC 19896-2:2026

English language (25 pages)
Preview
Preview
e-Library read for
1 day

Overview

SIST EN ISO/IEC 19896-2:2026 establishes internationally recognized requirements for the competence of personnel involved in IT security conformance assessment, specifically testers and validators working within schemes based on ISO/IEC 19790 and ISO/IEC 24759. Developed by CEN, this standard defines the minimum knowledge and skills that professionals must demonstrate to perform effective testing and validation of cryptographic modules under these core security standards.

The standard supports comparability, consistency, and quality across validation schemes, ensuring that assessment outcomes are reliable and accepted globally. It is highly relevant for organizations seeking laboratory accreditation, validation authorities, and professionals providing cryptographic module certification services.

Key Topics

  • Knowledge Requirements for Testers and Validators

    • Educational prerequisites: Associates, bachelor, or higher degree in relevant IT or security fields, or equivalent experience.
    • Technical specializations: Cryptographic concepts, engineering disciplines (electrical, computer, cybersecurity), software/hardware development, operating systems, and more.
    • Specialty topics: Programming, debugging, cryptographic algorithms (symmetric/asymmetric, hashing, random bit generation), hardware security, operational environments, audit mechanisms, self-test procedures, and countermeasure strategies.
  • Familiarity with Key Standards

    • In-depth understanding of ISO/IEC 19790 (security requirements for cryptographic modules).
    • Proficiency regarding ISO/IEC 24759 (test requirements for cryptographic modules).
    • Awareness of additional standards relevant to non-invasive attacks, conformance testing, random bit generators, and laboratory competence (such as ISO/IEC 17825, 18367, 20085, 20543, and 23532-2).
  • Operation within Validation Programs

    • Comprehension of validation program structures, legal mandates, communication channels, documentation, and specific tools provided for testing and validation.
    • Adherence to program-specific policies regarding confidentiality, evidence management, problem resolution, and reporting.
  • Skills Requirements

    • Testers and validators must demonstrate practical abilities in:
      • Testing of cryptographic algorithms and physical security features.
      • Identifying and analyzing side-channel attacks.
      • Applying a variety of environmental and operational tests.
      • Utilizing specialized test tools and equipment.

Applications

Implementing SIST EN ISO/IEC 19896-2:2026 supports organizations and individuals in:

  • Accreditation and Recognition

    • Achieving or maintaining accreditation for security testing laboratories and validation authorities, as required by regulatory bodies or clients.
    • Demonstrating personnel competence as part of certification processes under leading conformance schemes for cryptographic modules.
  • Quality Assurance in Security Testing

    • Standardizing the knowledge and skills expected from testers and validators to ensure rigorous, repeatable, and objective assessment practices.
    • Enhancing the trustworthiness of security evaluations for products handling sensitive or regulated data.
  • Professional Development

    • Providing a benchmark for training programs and professional certifications targeting IT security testers and validators.
    • Informing personnel development strategies for organizations in cybersecurity, information security, and privacy protection sectors.

Related Standards

The following international standards are referenced or closely associated with SIST EN ISO/IEC 19896-2:2026:

  • ISO/IEC 19790: Security requirements for cryptographic modules.
  • ISO/IEC 24759: Test requirements for cryptographic modules.
  • ISO/IEC 17825: Testing methods for mitigation of non-invasive attack classes.
  • ISO/IEC 18367: Cryptographic algorithms and security mechanisms conformance testing.
  • ISO/IEC 20085 (Parts 1 & 2): Test tool requirements and calibration methods for non-invasive attack mitigation.
  • ISO/IEC 20543: Test and analysis methods for random bit generators.
  • ISO/IEC 23532-2: Competence requirements for IT security testing laboratories.
  • ISO/IEC 19896-1: Introduction and general requirements for the competence of information security testers and evaluators.

These standards together form a comprehensive framework for the reliable testing and validation of cryptographic modules, supporting robust information security, cybersecurity, and privacy protection in digital systems.

Relations

Effective Date
01-Sep-2026
Effective Date
11-Feb-2026
Effective Date
11-Feb-2026
Effective Date
11-Feb-2026
Effective Date
11-Feb-2026
Effective Date
28-Jan-2026
Effective Date
28-Jan-2026

Buy Documents

Standard

SIST EN ISO/IEC 19896-2:2026

English language (25 pages)
Preview
Preview
e-Library read for
1 day

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

SIST EN ISO/IEC 19896-2:2026 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Information security, cybersecurity and privacy protection - Requirements for the competence of IT security conformance assessment body personnel - Part 2: Knowledge and skills requirements for testers and validators according to ISO/IEC 19790 and ISO/IEC 24759 (ISO/IEC 19896-2:2026)". This standard covers: This document provides the minimum requirements for the knowledge and skills of assessment body testers and validators performing testing activities and validating activities for a conformance scheme using ISO/IEC 19790 and ISO/IEC 24759.

This document provides the minimum requirements for the knowledge and skills of assessment body testers and validators performing testing activities and validating activities for a conformance scheme using ISO/IEC 19790 and ISO/IEC 24759.

SIST EN ISO/IEC 19896-2:2026 is classified under the following ICS (International Classification for Standards) categories: 03.100.30 - Management of human resources; 35.030 - IT Security. The ICS classification helps identify the subject area and facilitates finding related standards.

SIST EN ISO/IEC 19896-2:2026 has the following relationships with other standards: It is inter standard links to SIST EN ISO/IEC 19896-2:2023, SIST EN ISO 15653:2018, oSIST prEN ISO 14907-1:2026, SIST EN 16980-1:2021, SIST EN 1953:2025, SIST EN ISO 4254-20:2026, SIST EN ISO 25119-4:2023. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

SIST EN ISO/IEC 19896-2:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


SLOVENSKI STANDARD
01-oktober-2026
Nadomešča:
SIST EN ISO/IEC 19896-2:2023
Informacijska varnost, kibernetska varnost in varstvo zasebnosti - Zahteve za
usposobljenost osebja za ugotavljanje skladnosti z varnostjo IT- 2. del: Zahteve za
znanje in spretnosti za preizkuševalce in potrjevalce ISO/IEC 19790 in ISO/IEC
24759 (ISO/IEC 19896-2:2026)
Information security, cybersecurity and privacy protection - Requirements for the
competence of IT security conformance assessment body personnel - Part 2: Knowledge
and skills requirements for testers and validators according to ISO/IEC 19790 and
ISO/IEC 24759 (ISO/IEC 19896-2:2026)
Informationssicherheit, Cybersicherheit und Schutz der Privatsphäre - Anforderungen an
die Kompetenz des Personals von Konformitätsbewertungsstellen für IT-Sicherheit - Teil
2: Anforderungen an die Kenntnisse und Fähigkeiten von Testern und Validierern nach
ISO/IEC 19790 (ISO/IEC 19896-2:2026)
Sécurité de l'information, cybersécurité et sécurité de la vie privée - Exigences relatives
aux compétences du personnel des organismes d'évaluation de la conformité de la
sécurité TI - Partie 2: Exigences en matière de connaissances et de compétences pour
les testeurs et les validateurs conformément à la série ISO/IEC 19790 et à l'ISO/IEC
24759 (ISO/IEC 19896-2:2026)
Ta slovenski standard je istoveten z: EN ISO/IEC 19896-2:2026
ICS:
03.100.30 Vodenje ljudi Management of human
resources
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

EUROPEAN STANDARD EN ISO/IEC 19896-2

NORME EUROPÉENNE
EUROPÄISCHE NORM
January 2026
ICS 35.030
Supersedes EN ISO/IEC 19896-2:2023
English version
Information security, cybersecurity and privacy protection
- Requirements for the competence of IT security
conformance assessment body personnel - Part 2:
Knowledge and skills requirements for testers and
validators according to ISO/IEC 19790 and ISO/IEC 24759
(ISO/IEC 19896-2:2026)
Sécurité de l'information, cybersécurité et sécurité de Informationssicherheit, Cybersicherheit und Schutz
la vie privée - Exigences relatives aux compétences du der Privatsphäre - Anforderungen an die Kompetenz
personnel des organismes d'évaluation de la des Personals von Konformitätsbewertungsstellen für
conformité de la sécurité TI - Partie 2: Exigences en IT-Sicherheit - Teil 2: Anforderungen an die
matière de connaissances et de compétences pour les Kenntnisse und Fähigkeiten von Testern und
testeurs et les validateurs conformément à la série Validierern nach ISO/IEC 19790 (ISO/IEC 19896-
ISO/IEC 19790 et à l'ISO/IEC 24759 (ISO/IEC 19896- 2:2026)
2:2026)
This European Standard was approved by CEN on 4 January 2026.

CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for
giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.

CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.

CEN-CENELEC Management Centre:
Rue de la Science 23, B-1040 Brussels
© 2026 CEN/CENELEC All rights of exploitation in any form and by any means Ref. No. EN ISO/IEC 19896-2:2026 E
reserved worldwide for CEN national Members and for
CENELEC Members.
Contents Page
European foreword . 3

European foreword
This document (EN ISO/IEC 19896-2:2026) has been prepared by Technical Committee ISO/IEC JTC 1
"Information technology" in collaboration with Technical Committee CEN-CENELEC/ JTC 13
“Cybersecurity and Data Protection” the secretariat of which is held by DIN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by July 2026, and conflicting national standards shall be
withdrawn at the latest by July 2026.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN-CENELEC shall not be held responsible for identifying any or all such patent rights.
This document supersedes EN ISO/IEC 19896-2:2023.
Any feedback and questions on this document should be directed to the users’ national standards
body/national committee. A complete listing of these bodies can be found on the CEN and CENELEC
websites.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Endorsement notice
The text of ISO/IEC 19896-2:2026 has been approved by CEN-CENELEC as EN ISO/IEC 19896-2:2026
without any modification.
International
Standard
ISO/IEC 19896-2
Second edition
Information security, cybersecurity
2026-01
and privacy protection —
Requirements for the competence
of IT security conformance
assessment body personnel —
Part 2:
Knowledge and skills requirements
for testers and validators according
to ISO/IEC 19790 and ISO/IEC 24759
Sécurité de l'information, cybersécurité et sécurité de la vie
privée ― Exigences relatives aux compétences du personnel des
organismes d'évaluation de la conformité de la sécurité TI —
Partie 2: Exigences en matière de connaissances et de
compétences pour les testeurs et les validateurs conformément à
la série ISO/IEC 19790 et à l'ISO/IEC 24759
Reference number
ISO/IEC 19896-2:2026(en) © ISO/IEC 2026

ISO/IEC 19896-2:2026(en)
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC 19896-2:2026(en)
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 2
4 Abbreviated terms . 2
5 Structure of this document . 3
6 Knowledge . 3
6.1 General .3
6.2 Requirements for testers.3
6.2.1 Tertiary education .3
6.2.2 Knowledge of standards .7
6.2.3 Knowledge of the validation programme.9
6.2.4 Knowledge of the requirements of ISO/IEC TS 23532-2 .10
6.3 Requirements for validators .10
6.3.1 Tertiary education .10
6.3.2 Knowledge of standard . . .11
6.3.3 Knowledge of the validation programme.11
6.3.4 Knowledge of the requirements of ISO/IEC TS 23532-2 . 12
7 Skills .12
7.1 Requirements for testers. 12
7.1.1 General . 12
7.1.2 Algorithm testing. 12
7.1.3 Physical security testing . 12
7.1.4 Side channel analysis . 12
7.1.5 Technology types . 13
7.2 Requirements for validators . 13
8 Recording a log for testers and validators .13
Annex A (informative) Example of log for testers and validators . 14
Annex B (informative) Ontology of technology types .15
Bibliography . 17

© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 19896-2:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 27, Information security, cybersecurity and privacy protection, in collaboration with the
European Committee for Standardization (CEN) Technical Committee CEN/CLC/JTC 13, Cybersecurity and
data protection, in accordance with the Agreement on technical cooperation between ISO and CEN (Vienna
Agreement).
This second edition cancels and replaces the first edition (ISO/IEC 19896-2:2018), which has been technically
revised.
The main changes are as follows:
— the document has been restructured:
— deleted subclauses related to experience, education and effectiveness;
— technical changes have been introduced:
— deleted elements of competence, experience, education and effectiveness, except for knowledge and
skill, according to comments from ISO/CASCO;
— added competence requirements for the validators;
— Annex C has been removed.
A list of all parts in the ISO/IEC 19896 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.

© ISO/IEC 2026 – All rights reserved
iv
ISO/IEC 19896-2:2026(en)
Introduction
This document specifies the specialized knowledge and skills requirements for testers and validators, who
perform security testing projects according to ISO/IEC 19790 and ISO/IEC 24759. ISO/IEC 19790 specifies
security requirements for cryptographic modules. Many validation schemes and recognition arrangements
have been developed using ISO/IEC 19790 as a basis. ISO/IEC 19790 permits comparability between the
results of independent security testing projects. ISO/IEC 24759 supports this by providing a common set of
testing requirements for testing a cryptographic module for conformance with ISO/IEC 19790.
One of the important factors in assuring comparability of the results of such validations is the knowledge
and skills requirements of the individual testers responsible for performing testing projects.
Another important factor in assuring comparability of the results of such validations is the knowledge and
skills requirements of the individual validators responsible for validating the results of testing projects.
ISO/IEC TS 23532-2, which is often specified as a standard to which the testing laboratory conforms, states
in ISO/IEC TS 23532-2:2021, 6.2 that the competence requirements for each function influencing the results
of laboratory activities are documented, including requirements for education, qualification, training,
technical knowledge, skills and experience. The document provides the requirement that the personnel
have the competence to perform laboratory activities for which they are responsible and to evaluate the
significance of deviations specified in ISO/IEC TS 23532-2:2021, 6.2.
The audience for this document includes validation authorities, testing laboratories, testers, validators and
organizations offering professional credentials and recognitions.
This document establishes a baseline for the knowledge and skills requirements of:
— testers, to ensure harmonized requirements for cryptographic module conformance testing
programmers, and
— validators, to ensure harmonized requirements for cryptographic module validation programmes.

© ISO/IEC 2026 – All rights reserved
v
International Standard ISO/IEC 19896-2:2026(en)
Information security, cybersecurity and privacy protection —
Requirements for the competence of IT security conformance
assessment body personnel —
Part 2:
Knowledge and skills requirements for testers and validators
according to ISO/IEC 19790 and ISO/IEC 24759
1 Scope
This document provides the minimum requirements for the knowledge and skills of assessment body
testers and validators performing testing activities and validating activities for a conformance scheme using
ISO/IEC 19790 and ISO/IEC 24759.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 17825, Information technology — Security techniques — Testing methods for the mitigation of non-
invasive attack classes against cryptographic modules
ISO/IEC 18367, Information technology — Security techniques — Cryptographic algorithms and security
mechanisms conformance testing
ISO/IEC 19790:2025, Information security, cybersecurity and privacy protection — Security requirements for
cryptographic modules
ISO/IEC 19896-1, Information security, cybersecurity and privacy protection — Requirements for the
competence of IT security conformance assessment body personnel — Part 1: Overview and concepts
ISO/IEC 20085-1, IT Security techniques — Test tool requirements and test tool calibration methods for use in
testing non-invasive attack mitigation techniques in cryptographic modules — Part 1: Test tools and techniques
ISO/IEC 20085-2, IT Security techniques — Test tool requirements and test tool calibration methods for use in
testing non-invasive attack mitigation techniques in cryptographic modules — Part 2: Test calibration methods
and apparatus
ISO/IEC 20543, Information technology — Security techniques — Test and analysis methods for random bit
generators within ISO/IEC 19790 and ISO/IEC 15408
ISO/IEC TS 23532-2:2021, Information security, cybersecurity and privacy protection — Requirements for the
competence of IT security testing and evaluation laboratories — Part 2: Testing for ISO/IEC 19790
ISO/IEC 24759:2025, Information security, cybersecurity and privacy protection — Test requirements for
cryptographic modules
© ISO/IEC 2026 – All rights reserved
ISO/IEC 19896-2:2026(en)
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 19896-1, ISO/IEC TS 23532-2
and ISO/IEC 19790 apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
runtime environment
environment in which a program or application is executed
Note 1 to entry: It can pertain to the operating system itself, or the software that runs beneath it. The primary purpose
is to accomplish the objective of “platform independent” programming.
[SOURCE: ISO/IEC 19790:2025, 3.121]
3.2
split knowledge
process by which a cryptographic key is split into multiple key components, individually sharing no
knowledge of the original key, which can be subsequently input, or output from, a cryptographic module by
separate operators and combined to recreate the original key
Note 1 to entry: All or a subset of the components are required to recover the original split-key.
[SOURCE: ISO/IEC 19790:2025, 3.144]
3.3
user
operator that accesses a cryptographic module in order to perform general security services, including
cryptographic operations and other approved security function
[SOURCE: ISO/IEC 19790:2025, 3.154]
Note 1 to entry: a user is an operator who assumes the user role
3.4
vendor
entity, group or association that submits the cryptographic module for testing and validation
[SOURCE: ISO/IEC 19790:2025, 3.156]
4 Abbreviated terms
DPA differential power analysis
DEMA differential electromagnetic analysis
IUT implementation under test
RSA Rivest-Shamir-Adleman
SEMA simple electromagnetic analysis
SPA simple power analysis
© ISO/IEC 2026 – All rights reserved
ISO/IEC 19896-2:2026(en)
5 Structure of this document
This document is divided into the following clauses:
— Knowledge (Clause 6), and
— Skills (Clause 7).
Each clause corresponds to an aspect of the knowledge and skills requirements of personnel performing
testing activities or validating activities as introduced in ISO/IEC 19896-1 for a conformance scheme using
ISO/IEC 19790 and ISO/IEC 24759.
6 Knowledge
6.1 General
6.2 and 6.3 provide knowledge requirements that a tester or a validator knows and describe th
...