Overview - ISO/IEC 19896-3:2025 (Knowledge & Skills for Evaluators and Reviewers)
ISO/IEC 19896-3:2025 defines the knowledge and skills requirements for personnel who perform IT product security evaluations and reviews according to the ISO/IEC 15408 series (Common Criteria) and ISO/IEC 18045 (CEM). This part of the ISO/IEC 19896 series establishes a baseline competence profile to promote comparable, repeatable evaluation results and support mutual recognition among evaluation schemes. It covers specialist requirements for both evaluators and reviewers, and complements broader competence concepts in ISO/IEC 19896-1.
Key technical topics and requirements
- Scope of competence: Detailed knowledge and practical skills that evaluators and reviewers must demonstrate to assess Targets of Evaluation (TOEs) against Common Criteria criteria.
- Knowledge areas:
- The ISO/IEC 15408 series and ISO/IEC 18045 framework and terminology.
- The assurance paradigm, security assurance classes and functional components.
- Information security principles: threats, vulnerabilities, security properties.
- Technology-specific knowledge relevant to the evaluated product (technical domains).
- Information security testing techniques and test types.
- Skill areas:
- Basic and core evaluation/review skills (planning, interpreting security targets, assessment activities).
- Designing and executing TOE-specific tests and test plans.
- Skills for evaluating specific security assurance classes and security functional requirement classes.
- Review competencies for independent assessment of evaluation work products.
- Supporting materials and annexes: Informative annexes describe technology types, example knowledge/skills for assurance and functional requirement classes, and bibliography for further guidance.
- Conformity context: Recognizes that evaluators/testers may operate under ISO/IEC 17025 and reviewers may operate under ISO/IEC 17065.
Practical applications and who uses this standard
- Testing laboratory accreditation bodies - to define personnel competence criteria for accreditation of IT security evaluation labs.
- Evaluation scheme developers and conformity assessment bodies - to harmonize training and qualification programs for Common Criteria-based evaluations.
- Security evaluation laboratories and reviewers - to benchmark required knowledge, build job profiles, and design internal training.
- Professional credentialing organizations - to map certification schemes to internationally recognized competence requirements.
- Vendors and procurement teams - to understand the competence expected from independent evaluators who validate product security claims.
Related standards and references
Keywords: ISO/IEC 19896-3:2025, Common Criteria, ISO/IEC 15408, ISO/IEC 18045, evaluator competence, IT product security evaluation, security assurance, information security testing.