Overview
EN ISO/IEC 19896-2:2026 establishes internationally recognized requirements for the competence of personnel involved in IT security conformance assessment, specifically testers and validators working within schemes based on ISO/IEC 19790 and ISO/IEC 24759. Developed by CEN, this standard defines the minimum knowledge and skills that professionals must demonstrate to perform effective testing and validation of cryptographic modules under these core security standards.
The standard supports comparability, consistency, and quality across validation schemes, ensuring that assessment outcomes are reliable and accepted globally. It is highly relevant for organizations seeking laboratory accreditation, validation authorities, and professionals providing cryptographic module certification services.
Key Topics
-
Knowledge Requirements for Testers and Validators
- Educational prerequisites: Associates, bachelor, or higher degree in relevant IT or security fields, or equivalent experience.
- Technical specializations: Cryptographic concepts, engineering disciplines (electrical, computer, cybersecurity), software/hardware development, operating systems, and more.
- Specialty topics: Programming, debugging, cryptographic algorithms (symmetric/asymmetric, hashing, random bit generation), hardware security, operational environments, audit mechanisms, self-test procedures, and countermeasure strategies.
-
Familiarity with Key Standards
- In-depth understanding of ISO/IEC 19790 (security requirements for cryptographic modules).
- Proficiency regarding ISO/IEC 24759 (test requirements for cryptographic modules).
- Awareness of additional standards relevant to non-invasive attacks, conformance testing, random bit generators, and laboratory competence (such as ISO/IEC 17825, 18367, 20085, 20543, and 23532-2).
-
Operation within Validation Programs
- Comprehension of validation program structures, legal mandates, communication channels, documentation, and specific tools provided for testing and validation.
- Adherence to program-specific policies regarding confidentiality, evidence management, problem resolution, and reporting.
-
Skills Requirements
- Testers and validators must demonstrate practical abilities in:
- Testing of cryptographic algorithms and physical security features.
- Identifying and analyzing side-channel attacks.
- Applying a variety of environmental and operational tests.
- Utilizing specialized test tools and equipment.
Applications
Implementing EN ISO/IEC 19896-2:2026 supports organizations and individuals in:
Related Standards
The following international standards are referenced or closely associated with EN ISO/IEC 19896-2:2026:
- ISO/IEC 19790: Security requirements for cryptographic modules.
- ISO/IEC 24759: Test requirements for cryptographic modules.
- ISO/IEC 17825: Testing methods for mitigation of non-invasive attack classes.
- ISO/IEC 18367: Cryptographic algorithms and security mechanisms conformance testing.
- ISO/IEC 20085 (Parts 1 & 2): Test tool requirements and calibration methods for non-invasive attack mitigation.
- ISO/IEC 20543: Test and analysis methods for random bit generators.
- ISO/IEC 23532-2: Competence requirements for IT security testing laboratories.
- ISO/IEC 19896-1: Introduction and general requirements for the competence of information security testers and evaluators.
These standards together form a comprehensive framework for the reliable testing and validation of cryptographic modules, supporting robust information security, cybersecurity, and privacy protection in digital systems.