Overview
SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers operating under the ISO/IEC 15408 (Common Criteria) series and ISO/IEC 18045. This European and international standard is essential for establishing a harmonized baseline of competence, helping ensure consistent, reliable, and comparable results in IT product security evaluations and reviews.
By providing specialized competence requirements, this document enables testing laboratories, accreditation bodies, certification authorities, and organizations globally to identify, develop, and assess the qualifications of professionals responsible for IT product security assessment processes.
Key Topics
-
Knowledge Requirements for Evaluators and Reviewers
- Understanding the core concepts and terminology of ISO/IEC 15408 and ISO/IEC 18045.
- Gaining familiarity with security functional requirements, security assurance requirements, and evaluation frameworks.
- Knowing the principles of information security, threat modeling, secure development lifecycle, and cryptographic fundamentals.
- Acquiring relevant knowledge of specific technology types (e.g., networks, operating systems, smart cards).
-
Skills Requirements for Effective Assessments
- Applying basic and advanced evaluation and review skills to assess compliance with Common Criteria and associated methodologies.
- Using appropriate evaluation methods and techniques for various security assurance classes and types of IT products.
- Preparing, conducting, and managing IT security testing according to recognized methodologies and scheme requirements.
- Documenting findings and producing standardized reports in accordance with ISO/IEC guidelines.
-
Conformance with Broader Accreditation Standards
- Recognizing the relationship with conformity assessment bodies operating under ISO/IEC 17025 (testing laboratories) and ISO/IEC 17065 (certification bodies).
- Ensuring personnel fit within schemes that require recognized laboratory management systems, quality controls, and competence frameworks.
Applications
SIST EN ISO/IEC 19896-3:2026 brings practical value to a broad spectrum of stakeholders across the information security, cybersecurity, and privacy sectors:
-
Testing Laboratories:
- Establish structured training and competence development programs for evaluators and testers in IT security.
- Meet the requirements of accreditation and regulatory frameworks such as ISO/IEC 17025.
-
Certification Authorities:
- Recruit, assess, and authorize reviewers with proven knowledge and expertise aligned with internationally accepted standards.
- Maintain consistency, quality, and mutual recognition of certifications within national and international schemes.
-
Product Manufacturers and Developers:
- Understand expectations and competence levels from assessment personnel to streamline evaluation processes for products seeking Common Criteria certification or similar approvals.
-
Regulators and Accreditation Bodies:
- Audit and verify the competence of IT security assessment workforce as part of scheme oversight and quality assurance mandates.
-
Scheme Owners:
- Harmonize competence frameworks across diverse technical domains including biometric devices, smart cards, network systems, and data protection solutions.
This standard supports organizations in ensuring that IT product security evaluations are performed by qualified specialists, providing assurance to the market and end-users regarding security claims and certifications.
Related Standards
SIST EN ISO/IEC 19896-3:2026 is closely linked to a set of foundational standards and schemes in IT security assessment, including:
- ISO/IEC 15408 Series (Common Criteria):
- Framework for IT security evaluation criteria, including general models, security functional components, and assurance components.
- ISO/IEC 18045:
- Methodology for IT security evaluation, codifying the evaluation methods for Common Criteria-based assessments.
- ISO/IEC 17025:
- General requirements for the competence of testing and calibration laboratories, often applicable to evaluation organizations.
- ISO/IEC 17065:
- Requirements for certification bodies certifying products, processes, and services.
Organizations engaged in conformance assessment should consult these standards in conjunction to establish robust, comprehensive, and harmonized security assessment programs.
Keywords: information security, cybersecurity, privacy protection, IT security evaluation, Common Criteria, ISO/IEC 15408, ISO/IEC 18045, competence requirements, evaluation personnel, conformance assessment, testing laboratories, certification bodies, security assurance, reviewer skills, ISO standards.