ISO/IEC 19790
ISO/IEC 19790 is an international standard, issued jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), that sets security requirements for cryptographic modules used to protect sensitive information. A cryptographic module is the hardware, software, or firmware component that performs encryption and related security functions within a system. The standard is intended to help ensure that such modules meet defined levels of security, though readers should confirm which revision and requirements apply to their specific situation.
ISO/IEC 19790 is an ISO/IEC standard specifying security requirements for cryptographic modules that protect sensitive information in information and communications systems. In the 2012 revision, the standard specifies four security levels across 11 requirement areas, with each successive security level generally increasing the rigor of security over the preceding one; a later revision was published as ISO/IEC 19790:2025. Conformance testing methods for assessing whether a cryptographic module meets these requirements are addressed in a companion standard, ISO/IEC 24759, which specifies the methods used by testing laboratories. Practitioners should note that ISO/IEC 19790 defines requirements for the module itself and is distinct from the testing and certification processes; the specific requirement areas, security levels, and certification schemes should be verified against the current authoritative ISO/IEC text and the applicable revision, and this entry does not address how the standard maps to any particular national validation program or agency requirement.
Why it matters
Cryptographic modules are the components that actually perform encryption, key management, and related security functions, so the assurance that a module behaves correctly and resists tampering is foundational to protecting sensitive information. ISO/IEC 19790 matters because it provides an internationally recognized, structured way to express what "secure" means for such a module, specifying tiered security levels across defined requirement areas rather than leaving that determination to ad hoc judgment. For organizations that procure, build, or deploy encryption technology, referencing a common standard helps compare products against a consistent baseline instead of relying solely on vendor claims.
Because the standard is issued jointly by ISO and IEC, it functions as a point of alignment across jurisdictions and vendors, which can reduce fragmentation when products cross national boundaries. It is important to recognize, however, that conformance to ISO/IEC 19790 concerns the requirements for the module itself and is distinct from the testing and certification processes used to demonstrate that conformance; the companion standard ISO/IEC 24759 addresses the methods testing laboratories use. Treating a claim of alignment with the standard as equivalent to independent validation would be a mistake an expert would correct.
Readers in defense and public sector environments should be cautious about assuming that international conformance to ISO/IEC 19790 automatically satisfies a specific national validation program or agency requirement. This entry does not establish how the standard maps to any particular program, and the applicable revision matters: the 2012 revision and a later 2025 revision exist, and requirement areas, security levels, and certification schemes should be verified against the current authoritative ISO/IEC text before relying on them for a compliance decision.
Who it's relevant to
Inside ISO/IEC 19790
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 19790.