Overview
SIST EN ISO/IEC 19896-1:2026 provides a comprehensive framework to understand and define the competency requirements for personnel involved in IT security conformance assessment. Developed collaboratively by ISO/IEC and CEN, this standard serves as the foundation for shared understanding among organizations, laboratories, evaluators, and certification bodies working in the areas of information security, cybersecurity, and privacy protection. It establishes core concepts and relationships essential for the assessment and validation of IT product security, focusing on the knowledge and skills required by testers, evaluators, validators, and reviewers engaged in conformance-testing and evaluation processes.
Key Topics
- Competence in IT Security: Defines competence as the ability to apply knowledge and skills to achieve intended results in IT security testing, evaluation, validation, and review settings.
- Roles and Definitions: Clarifies the roles of conformance-testers, evaluators, validators, and reviewers, along with the functions of evaluation laboratories, validation authorities, and review bodies.
- Core Elements of Competence: Identifies knowledge and skills as the central elements required, with examples spanning technology areas, testing methods, security standards, and industry-specific considerations.
- Competency Levels:
- Level 1: Basic knowledge with support roles under supervision.
- Level 2: Ability to work independently in specific areas, with some need for supervision.
- Level 3: Full competence in all aspects of conformance assessment for at least one technology, including supervision, communication, and project management capabilities.
- Monitoring and Documentation: Stresses maintaining records of education, training, authorizations, and performance monitoring to ensure consistent competence across personnel.
Applications
SIST EN ISO/IEC 19896-1:2026 is directly applicable to:
- Conformance Testing Laboratories: Establishes clear criteria for the competence of testers and evaluators, supporting reliable and repeatable results in IT product security assessments.
- Validation Authorities and Review Bodies: Offers guidance on competence requirements for personnel responsible for validation and review, ensuring decisions are based on rigorous, standard-aligned methodologies.
- IT Product Vendors & Technology Providers: Assists in understanding the qualification standards expected from personnel conducting independent assessments or evaluations of their products.
- Credentialing and Training Providers: Supports the creation of targeted training, certification, and continuing education programs to align with recognized international standards.
- Regulatory and Accreditation Schemes: Provides a baseline for regulatory authorities or program managers setting requirements for IT security assessment bodies or certifying laboratories.
Related Standards
- ISO/IEC 19896-2: Specifies minimum competence requirements for conformance testers and validators working with standards such as ISO/IEC 19790 and ISO/IEC 24759.
- ISO/IEC 19896-3: Outlines competencies for evaluators and reviewers handling the ISO/IEC 15408 series (Common Criteria) and ISO/IEC 18045.
- ISO/IEC 17025: General requirements for the competence of testing and calibration laboratories, forms a procedural foundation for laboratory accreditation.
- ISO/IEC 23532: Focuses on requirements for IT security testing and evaluation laboratories, complementing personnel competence considerations.
- ISO/IEC 15408: Common Criteria for Information Security Evaluation, referenced for evaluation standards.
- ISO/IEC 19790 and ISO/IEC 24759: Define criteria and methodologies for testing cryptographic modules and their conformance.
By providing a structured approach to defining and evaluating competence in information security and cybersecurity roles, SIST EN ISO/IEC 19896-1:2026 strengthens confidence in IT security product certifications and supports mutual recognition across international markets. Organizations can leverage this standard to build a highly qualified workforce, meet regulatory requirements, and ensure the robustness of IT product security assessments.