Overview
ISO/IEC 19896-1:2025 - Information security, cybersecurity and privacy protection - Requirements for the competence of IT security conformance assessment body personnel - Part 1: Overview and concepts - defines the foundational concepts and relationships needed to understand competency requirements for personnel involved in IT security conformance testing, evaluation, validation and review. This second edition (2025) reorganizes and updates the framework used across the ISO/IEC 19896 series to establish a shared vocabulary and conceptual basis for assessing information security competence.
Key topics and requirements
- Scope and purpose: Sets an organized set of concepts to support consistent interpretation of competence requirements across the ISO/IEC 19896 series.
- Terms and definitions: Standardized definitions for roles and concepts such as competence, conformance‑tester, evaluator, validator, reviewer, evaluation laboratory, knowledge, and skill.
- Conceptual framework: Relationships among competence elements and how competence supports conformity in testing and evaluation processes.
- Elements of competence: Focus on knowledge and skills as measurable elements (experience and education clauses were removed or revised in this edition).
- Competency levels: Defined competency levels (1–3) for testers and evaluators and for validators and reviewers, with level descriptions to support personnel classification.
- Measurement and recording: Guidance on measuring knowledge and skills and on recording elements of competence; includes example records and a framework for describing requirements (Annex A and Annex B).
- Informative annexes: Annex A - framework for describing competence requirements; Annex B - example records of experience and competence.
Applications and users
ISO/IEC 19896-1:2025 is intended for organizations and professionals involved in IT product security assessment and conformance activities, including:
- Evaluation laboratories and testing laboratories (e.g., ITSEFs, CCTLs)
- Validation authorities and review bodies that issue validation certificates or review evaluation results
- Conformance testers, evaluators, validators, and reviewers seeking to align skills and knowledge with international practice
- Vendors and technology providers preparing products for conformance testing or evaluation
- Organizations offering professional credentials for cybersecurity assessment personnel
Practical uses include defining job profiles, structuring training and certification programs, establishing personnel competency matrices, and harmonizing assessment practices across jurisdictions.
Related standards
Keywords: ISO/IEC 19896-1:2025, information security competence, IT security conformance, cybersecurity personnel competence, evaluation laboratory, competency levels, validators and reviewers.