Overview
EN ISO/IEC 19896-3:2025 defines the specialized knowledge and skills requirements for personnel who perform IT product security evaluations and reviews in accordance with the ISO/IEC 15408 series (Common Criteria) and ISO/IEC 18045 (evaluation methodology). Part 3 of the ISO/IEC 19896 series establishes a baseline for minimum competence for evaluators and certifiers working in conformance assessment bodies, test laboratories and certification schemes to support comparable, repeatable security evaluation results.
Key topics and technical requirements
- Scope and purpose
- Competence demonstration for individuals carrying out ISO/IEC 15408 evaluations and certifications.
- Supports comparability and mutual recognition of evaluation outcomes.
- Knowledge areas
- ISO/IEC 15408 & ISO/IEC 18045 concepts, assurance paradigm and evaluation methodology.
- Information security fundamentals: security principles, properties, threats and vulnerabilities.
- Technology and architecture: understanding TOE (Target of Evaluation) technologies and interactions.
- Testing & lifecycle: testing techniques, tools, test planning and product development lifecycle awareness.
- Laboratory and scheme context: laboratory management systems and scheme-specific processes.
- Skills
- Basic and core evaluation skills: test design, TOE-specific test/method definition, evidence assessment.
- Skills for evaluating specific assurance classes and security functional requirement classes.
- Certification and review skills for certifiers and reviewers assessing evaluation outputs.
- Supporting material
- Informative annexes (technology types, example knowledge/skills for assurance and functional classes) that illustrate practical competence expectations.
- Context note
Applications and practical value
- Ensures consistent competence criteria for organizations implementing Common Criteria-based evaluation schemes.
- Helps certification bodies, laboratories and accreditation bodies define training, hiring and credentialing programs for evaluators and certifiers.
- Improves repeatability and comparability of security evaluation results - a foundation for mutual recognition across schemes and jurisdictions.
- Useful for developing job profiles, assessment checklists and professional credential curricula for cybersecurity evaluators.
Who should use this standard
- Certification authorities, testing laboratories and accreditation bodies
- Evaluation scheme operators and conformity assessment bodies
- Security evaluators, test engineers, reviewers and certifiers
- Training providers and organizations building evaluator competency frameworks
Related standards
Keywords: Information security, cybersecurity, privacy protection, ISO/IEC 15408, ISO/IEC 18045, evaluator competence, certification body, IT product security evaluation, conformance assessment.