EN ISO/IEC 19896-2:2026 PDF
Information security, cybersecurity and privacy protection - Requirements for the competence of IT security conformance assessment body personnel - Part 2: Knowledge and skills requirements for testers and validators according to ISO/IEC 19790 and ISO/IEC 24759 (ISO/IEC 19896-2:2026)
Information security, cybersecurity and privacy protection - Requirements for the competence of IT security conformance assessment body personnel - Part 2: Knowledge and skills requirements for testers and validators according to ISO/IEC 19790 and ISO/IEC 24759 (ISO/IEC 19896-2:2026)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 39
- Дата публикации:
- 28 января 2026 г.
- Издание:
- CEN/CENELEC EN 19896 edition 2 version 1
- ICS:
- 35.030
This document provides the minimum requirements for the knowledge and skills of assessment body testers and validators performing testing activities and validating activities for a conformance scheme using ISO/IEC 19790 and ISO/IEC 24759.
Abstract
Overview
EN ISO/IEC 19896-2:2026 establishes internationally recognized requirements for the competence of personnel involved in IT security conformance assessment, specifically testers and validators working within schemes based on ISO/IEC 19790 and ISO/IEC 24759. Developed by CEN, this standard defines the minimum knowledge and skills that professionals must demonstrate to perform effective testing and validation of cryptographic modules under these core security standards.
The standard supports comparability, consistency, and quality across validation schemes, ensuring that assessment outcomes are reliable and accepted globally. It is highly relevant for organizations seeking laboratory accreditation, validation authorities, and professionals providing cryptographic module certification services.
Key Topics
-
Knowledge Requirements for Testers and Validators
- Educational prerequisites: Associates, bachelor, or higher degree in relevant IT or security fields, or equivalent experience.
- Technical specializations: Cryptographic concepts, engineering disciplines (electrical, computer, cybersecurity), software/hardware development, operating systems, and more.
- Specialty topics: Programming, debugging, cryptographic algorithms (symmetric/asymmetric, hashing, random bit generation), hardware security, operational environments, audit mechanisms, self-test procedures, and countermeasure strategies.
-
Familiarity with Key Standards
- In-depth understanding of ISO/IEC 19790 (security requirements for cryptographic modules).
- Proficiency regarding ISO/IEC 24759 (test requirements for cryptographic modules).
- Awareness of additional standards relevant to non-invasive attacks, conformance testing, random bit generators, and laboratory competence (such as ISO/IEC 17825, 18367, 20085, 20543, and 23532-2).
-
Operation within Validation Programs
- Comprehension of validation program structures, legal mandates, communication channels, documentation, and specific tools provided for testing and validation.
- Adherence to program-specific policies regarding confidentiality, evidence management, problem resolution, and reporting.
-
Skills Requirements
- Testers and validators must demonstrate practical abilities in:
- Testing of cryptographic algorithms and physical security features.
- Identifying and analyzing side-channel attacks.
- Applying a variety of environmental and operational tests.
- Utilizing specialized test tools and equipment.
- Testers and validators must demonstrate practical abilities in:
Applications
Implementing EN ISO/IEC 19896-2:2026 supports organizations and individuals in:
-
Accreditation and Recognition
- Achieving or maintaining accreditation for security testing laboratories and validation authorities, as required by regulatory bodies or clients.
- Demonstrating personnel competence as part of certification processes under leading conformance schemes for cryptographic modules.
-
Quality Assurance in Security Testing
- Standardizing the knowledge and skills expected from testers and validators to ensure rigorous, repeatable, and objective assessment practices.
- Enhancing the trustworthiness of security evaluations for products handling sensitive or regulated data.
-
Professional Development
- Providing a benchmark for training programs and professional certifications targeting IT security testers and validators.
- Informing personnel development strategies for organizations in cybersecurity, information security, and privacy protection sectors.
Related Standards
The following international standards are referenced or closely associated with EN ISO/IEC 19896-2:2026:
- ISO/IEC 19790: Security requirements for cryptographic modules.
- ISO/IEC 24759: Test requirements for cryptographic modules.
- ISO/IEC 17825: Testing methods for mitigation of non-invasive attack classes.
- ISO/IEC 18367: Cryptographic algorithms and security mechanisms conformance testing.
- ISO/IEC 20085 (Parts 1 & 2): Test tool requirements and calibration methods for non-invasive attack mitigation.
- ISO/IEC 20543: Test and analysis methods for random bit generators.
- ISO/IEC 23532-2: Competence requirements for IT security testing laboratories.
- ISO/IEC 19896-1: Introduction and general requirements for the competence of information security testers and evaluators.
These standards together form a comprehensive framework for the reliable testing and validation of cryptographic modules, supporting robust information security, cybersecurity, and privacy protection in digital systems.
Технические детали
- Технический комитет
- CEN/CLC/TC 13 - Cybersecurity and Data Protection
- SKU
- EN ISO/IEC 19896-2:2026
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 17825:2024
ДействующийInformation technology. Security techniques. Testing methods for the mitigation of non-invasive attack classe…
ISO/IEC 18367:2016
ДействующийInformation technology — Security techniques — Cryptographic algorithms and security mechanisms conformance t…
Overview ISO/IEC 18367:2016 - Information technology - Security techniques - Cryptographic algorithms and security mechanisms conformance testing - provides authoritative guidelines for verifying the…
ISO/IEC 20085-1:2019
ДействующийIT Security techniques — Test tool requirements and test tool calibration methods for use in testing non-inva…
Overview ISO/IEC 20085-1:2019 specifies test tool requirements and techniques for measuring and analysing side-channel leakage when assessing non-invasive attack mitigations in cryptographic modules.…
ISO/IEC 20543:2019
ДействующийInformation technology — Security techniques — Test and analysis methods for random bit generators within ISO…
Overview ISO/IEC 20543:2019 specifies a methodology for the evaluation, testing and analysis of random bit generators (RBGs) used in cryptographic applications. It is an implementation‑agnostic stand…
SIST EN ISO/IEC 19896-1:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-1:2026 provides a comprehensive framework to understand and define the competency requirements for personnel involved in IT security conformance assessment. Developed c…