Overview
SIST-TS CEN/TS 18212-3:2026 defines a comprehensive methodology for evaluating the functionality of biometric products used in personal identification. Developed by the Slovenian Institute for Standardization (SIST) within the CEN/TS 18212 series, this technical specification establishes a generic, scenario-driven framework for setting and evaluating requirements for diverse biometric technologies. The methodology covers multiple biometric modes and is designed to ensure products comply with varied application profiles, are robust against attacks, and handle personal data responsibly.
Compliant with international standards such as ISO/IEC 19795 (biometric performance testing), ISO/IEC 30107 (presentation attack detection), and aligned with regulations like GDPR and the EU Cybersecurity Act, this standard serves as a key point of reference for certification bodies, product manufacturers, and organizations deploying biometric solutions. It supports rigorous testing for both functionality and resistance to attacks in a mode-independent manner.
Key Topics
- Evaluation Types: Specifies both technology-driven and scenario-based evaluations, encompassing performance verification and attack resistance (presentation attacks).
- Terminology & Parameters: Introduces clear definitions for testing elements such as Subject, Operator, Attempt, Artefact, Trial, and more-helping ensure consistency in evaluation.
- Application Profiles (APs): Provides a mechanism to tailor requirements and tests to specific application scenarios, enabling sector-specific evaluations at different levels of assurance (Basic, Substantial, High).
- Test Data Management: Stresses the need for using representative and, when permissible, anonymized or synthetic data, ensuring both statistical relevance and data protection in compliance with the GDPR.
- Workflow & Execution Flows: Details distinct phases for evaluation:
- Phase 2: Evaluates product behaviour and operational performance.
- Phase 3: Assesses robustness against various attack types, with special attention to high-assurance requirements.
- Machine Learning Considerations: Outlines additional methodology for machine-learning-based biometric systems, including continuous improvement and recurrent evaluation.
Applications
The functionality evaluation methodology defined in SIST-TS CEN/TS 18212-3:2026 is applicable across sectors where secure biometric identification is critical, such as:
- Electronic Identity and Authentication: Ensuring biometric systems used for secure login, eID issuance, and digital services are reliable and robust.
- Financial Services: Supporting biometric authentication in banking and payments to meet regulatory and operational requirements.
- Public Sector and eGovernment: Facilitating identity verification for public administration portals, in line with national and EU-specific regulations (see eIDAS, BSI TR-03121, Cybersecurity Act).
- Mobile & Remote Services: Evaluating performance and security of biometrics on smartphones, tablets, and remote onboarding systems.
- Certification and Conformity Assessment: Enabling testing laboratories and certification bodies to assess if biometric products meet required functional and security benchmarks.
- Product Development: Guiding manufacturers in designing biometric products that conform to recognized standards and are certifiable for various sectors.
Related Standards
For comprehensive coverage and interoperability, SIST-TS CEN/TS 18212-3:2026 references and aligns with several key standards:
- CEN/TS 18212-1: Personal identification - General requirements and application profile definition
- CEN/TS 18212-2: Personal identification - Interoperability tests
- ISO/IEC 19795 Series: Information technology - Biometric performance testing and reporting
- ISO/IEC 30107 Series: Biometric presentation attack detection methodology
- ISO/IEC 2382-37: Biometrics terminology and vocabulary
- ISO/IEC 30108 Series: Identity attributes verification services
- BSI TR-03121: Technical guideline for biometrics in the public sector
- EN ISO/IEC 15408-1: Common Criteria for security evaluation
- EU Regulation 2019/881 (Cybersecurity Act): Sectoral requirements and levels of assurance
SIST-TS CEN/TS 18212-3:2026 empowers stakeholders to validate their biometric products with a structured, internationally recognized approach, ensuring functional reliability, attack resistance, and legal compliance in all deployment contexts.