Overview
CEN/CLC ISO/IEC/TS 23532-2:2024 is a Technical Specification that defines competence requirements for IT security testing and evaluation laboratories performing tests against ISO/IEC 19790 (cryptographic modules). Adopted from ISO/IEC TS 23532-2:2021 and published for provisional application in 2024, this document supplements ISO/IEC 17025:2017 by giving specific guidance for labs conducting cryptographic and IT security testing. It addresses laboratory impartiality, confidentiality and the technical processes needed to produce reliable, traceable test results.
Key topics and technical requirements
The specification covers practical and technical elements essential to laboratory competence, including:
- General requirements: impartiality, confidentiality and structural safeguards.
- Resource requirements: personnel competence, facilities and environmental conditions, equipment and calibration.
- Metrological traceability: principles and annex guidance to ensure measurement traceability for security tests.
- Process requirements: review of requests/contracts, selection/verification/validation of test methods (including methods derived from ISO/IEC 19790 and ISO/IEC 24759), sampling, handling of test items and maintenance of technical records.
- Ensuring validity of results: measurement uncertainty evaluation, controls to ensure result validity and reproducibility.
- Reporting: common and specific requirements for test reports, calibration certificates, statements of conformity and interpretations.
- Management system options: implementation choices aligned with ISO/IEC 17025-style systems, internal audits, corrective actions and management reviews.
- Informative annexes on metrological traceability, management system options and the relationship to standards used in cryptographic module testing.
Applications and who should use it
This Technical Specification is intended for:
- IT security testing and evaluation laboratories performing cryptographic module testing to ISO/IEC 19790.
- Laboratory managers and quality managers implementing or maintaining competence and accreditation evidence.
- Accreditation bodies and assessors evaluating conformity with ISO/IEC 17025 for IT security-specific tests.
- Vendors, integrators and certification schemes that depend on reliable cryptographic testing and clear reporting.
Practical benefits include stronger lab competence, consistent test method validation, improved traceability of measurements, and clearer, more credible test reports for cybersecurity and privacy protection activities.
Related standards
- ISO/IEC 19790 - Security requirements for cryptographic modules (primary test target).
- ISO/IEC 24759 - Test requirements related to cryptographic modules.
- ISO/IEC 17025:2017 - General requirements for the competence of testing and calibration laboratories (core referenced standard).
Keywords: information security, cybersecurity, privacy protection, IT security testing, cryptographic module testing, ISO/IEC 19790, ISO/IEC 17025, laboratory competence, metrological traceability, measurement uncertainty.