Overview
ISO/IEC 24759:2025 - Information security, cybersecurity and privacy protection - Test requirements for cryptographic modules (ISO, 2025) defines the test methods that independent testing laboratories must use to verify that a cryptographic module conforms to the security requirements in ISO/IEC 19790:2025. The standard is designed to increase objectivity and consistency across laboratories, and it also specifies the supporting evidence vendors must supply. Vendors can use the document to self‑check their products before formal testing.
Key Topics and Requirements
ISO/IEC 24759:2025 organizes test requirements across the full lifecycle and internal structure of cryptographic modules. Major technical topics include:
- Cryptographic module specification and boundary - tests to confirm the defined module, its type, and physical/logical boundary.
- Interfaces and data paths - test cases for module interfaces, plaintext trusted paths, and protected internal paths.
- Roles, services, and authentication - verification of role separation, services provided, and authentication mechanisms.
- Software/firmware security and security levels - tests for modifiable/non‑modifiable firmware, and requirements mapped to security levels.
- Operational environment - evaluation of host OS and modifiable environments where applicable.
- Physical security and environmental failure protection - tests covering physical embodiments and resistance to tampering and environmental attacks.
- Non‑invasive and side‑channel resistance - test methods addressing power, timing and other non‑invasive attack vectors.
- Sensitive Security Parameter (SSP) management - verification of key generation, RNGs, storage, zeroization, and secure entry/output.
- Self‑tests and lifecycle assurance - procedures for pre‑operational and conditional self‑tests, configuration management, design/development and vendor testing.
- Documentation and cryptographic module security policy - required evidence, user and administrative documentation, and the module security policy content.
Applications and Who Uses It
ISO/IEC 24759:2025 is practical for organizations involved in the design, testing, certification and procurement of cryptographic modules:
- Testing laboratories and certification bodies - to apply consistent, objective test methods for product evaluation.
- Vendors and product engineers - to prepare evidence packages and perform pre‑testing against ISO/IEC 19790:2025.
- Security architects and compliance teams - to ensure deployed HSMs, TPMs, smart cards, encryption appliances and IoT cryptographic modules meet validated requirements.
- Procurement and risk officers - to specify testable security requirements in acquisition contracts.
Use this standard to streamline certification, reduce testing variability, and demonstrate conformity of cryptographic modules in regulated and high‑security environments.
Related Standards
- ISO/IEC 19790:2025 - cryptographic module security requirements (normative reference).
- Comparable standards and references often considered: NIST FIPS 140‑3 (US cryptographic module validation).