Skip to main content
Category: Cryptography & Encryption

ISO/IEC 19790

Also known as: ISO/IEC 19790:2012, ISO/IEC 19790:2025
Simply put

ISO/IEC 19790 is an international standard, issued jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), that sets security requirements for cryptographic modules used to protect sensitive information. A cryptographic module is the hardware, software, or firmware component that performs encryption and related security functions within a system. The standard is intended to help ensure that such modules meet defined levels of security, though readers should confirm which revision and requirements apply to their specific situation.

Formal definition

ISO/IEC 19790 is an ISO/IEC standard specifying security requirements for cryptographic modules that protect sensitive information in information and communications systems. In the 2012 revision, the standard specifies four security levels across 11 requirement areas, with each successive security level generally increasing the rigor of security over the preceding one; a later revision was published as ISO/IEC 19790:2025. Conformance testing methods for assessing whether a cryptographic module meets these requirements are addressed in a companion standard, ISO/IEC 24759, which specifies the methods used by testing laboratories. Practitioners should note that ISO/IEC 19790 defines requirements for the module itself and is distinct from the testing and certification processes; the specific requirement areas, security levels, and certification schemes should be verified against the current authoritative ISO/IEC text and the applicable revision, and this entry does not address how the standard maps to any particular national validation program or agency requirement.

Why it matters

Cryptographic modules are the components that actually perform encryption, key management, and related security functions, so the assurance that a module behaves correctly and resists tampering is foundational to protecting sensitive information. ISO/IEC 19790 matters because it provides an internationally recognized, structured way to express what "secure" means for such a module, specifying tiered security levels across defined requirement areas rather than leaving that determination to ad hoc judgment. For organizations that procure, build, or deploy encryption technology, referencing a common standard helps compare products against a consistent baseline instead of relying solely on vendor claims.

Because the standard is issued jointly by ISO and IEC, it functions as a point of alignment across jurisdictions and vendors, which can reduce fragmentation when products cross national boundaries. It is important to recognize, however, that conformance to ISO/IEC 19790 concerns the requirements for the module itself and is distinct from the testing and certification processes used to demonstrate that conformance; the companion standard ISO/IEC 24759 addresses the methods testing laboratories use. Treating a claim of alignment with the standard as equivalent to independent validation would be a mistake an expert would correct.

Readers in defense and public sector environments should be cautious about assuming that international conformance to ISO/IEC 19790 automatically satisfies a specific national validation program or agency requirement. This entry does not establish how the standard maps to any particular program, and the applicable revision matters: the 2012 revision and a later 2025 revision exist, and requirement areas, security levels, and certification schemes should be verified against the current authoritative ISO/IEC text before relying on them for a compliance decision.

Who it's relevant to

Government contractors and product vendors
Organizations that build or supply hardware, software, or firmware cryptographic modules use ISO/IEC 19790 as a reference for the security requirements their products should meet. Vendors should distinguish between designing a module to align with the standard's requirements and obtaining independent validation through a testing laboratory under ISO/IEC 24759, and should confirm which revision their claims reference.
Compliance officers and ISSMs
Those responsible for evaluating whether encryption technology meets defined assurance criteria may encounter ISO/IEC 19790 when assessing product claims or procurement documentation. They should not assume that international conformance to this standard automatically satisfies a specific national validation program or agency requirement, and should verify how, if at all, the standard maps to their governing obligations.
Auditors and assessors
Auditors reviewing cryptographic implementations can use the standard's tiered structure of security levels and requirement areas as a framework, but must recognize the distinction between the requirements defined in ISO/IEC 19790 and the testing methods specified in ISO/IEC 24759. Assessment against the standard is not the same as authorization to operate any system that incorporates the module.
Testing laboratories and certification bodies
Laboratories that evaluate cryptographic modules rely on the companion standard ISO/IEC 24759 for the methods used to test conformance to ISO/IEC 19790, and certification bodies may operate schemes built on this framework. These stakeholders should track revisions of both standards and confirm the applicable certification scheme against current authoritative sources.

Inside ISO/IEC 19790

Security Requirements for Cryptographic Modules
ISO/IEC 19790 is an international standard that specifies security requirements for cryptographic modules used to protect sensitive information. It addresses the design and implementation of such modules across defined areas of security.
Security Levels
The standard generally organizes its requirements into progressive security levels, with higher levels imposing more stringent protections. Practitioners should confirm the specific level definitions against the current authoritative text of the applicable edition.
Defined Security Areas
The standard addresses multiple security areas relevant to a cryptographic module, such as the module specification, ports and interfaces, roles and authentication, physical security, and self-tests. The exact enumeration and terminology should be verified against the governing edition.
Relationship to FIPS 140 in U.S. Federal Contexts
ISO/IEC 19790 is closely related to the U.S. FIPS 140 line of cryptographic module validation requirements maintained under the NIST-administered Cryptographic Module Validation Program (CMVP). The two are distinct publications issued by different bodies, and their alignment has evolved across revisions; readers should verify the current relationship rather than assume identity.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 19790.

Is ISO/IEC 19790 the same standard as FIPS 140-3?
No, though the two are closely related and frequently confused. FIPS 140-3, issued by NIST as a U.S. federal standard, references ISO/IEC 19790 as its basis for cryptographic module security requirements. ISO/IEC 19790 is the international standard maintained through ISO/IEC, while FIPS 140-3 is the mandatory federal implementation used for U.S. government cryptographic module validation. Readers should verify the current relationship and any U.S.-specific tailoring against the applicable NIST publications, because the federal adoption may add or modify requirements relative to the base international standard.
Does meeting ISO/IEC 19790 automatically mean a cryptographic module is validated for U.S. federal use?
Not necessarily. Conformance to ISO/IEC 19790 as an international standard is distinct from formal validation under the U.S. federal program that governs cryptographic module acceptance for government systems. Validation generally involves testing by an accredited laboratory and issuance of a validation certificate under the applicable federal program, which relies on the FIPS implementation rather than the international standard alone. Confirm the specific validation status and program requirements against current NIST program documentation before relying on a module for federal use.
How do the security levels defined in ISO/IEC 19790 affect module selection?
ISO/IEC 19790 generally defines multiple security levels intended to reflect increasing rigor of cryptographic module protections. Selecting an appropriate level typically depends on the sensitivity of the information the module protects, the deployment environment, and applicable agency or system requirements. The standard describes the levels conceptually; it does not dictate which level a given system must use. Readers should confirm the specific level requirements against their system's authorization requirements and current authoritative guidance.
Where does ISO/IEC 19790 fit within a Risk Management Framework (RMF) authorization effort?
Cryptographic module requirements associated with ISO/IEC 19790, as implemented through the applicable federal standard, generally support control implementation for protecting information confidentiality and integrity within an RMF authorization package. It informs the selection and validation of cryptographic mechanisms but is only one input; it does not by itself satisfy the broader control catalog, assessment, or authorization steps. Confirm how validated cryptography maps to your specific controls against current NIST control guidance and your authorizing official's expectations.
Who performs testing against ISO/IEC 19790 or its federal implementation?
Testing is generally performed by accredited laboratories operating under the relevant conformity assessment or validation program rather than by the vendor or the acquiring agency directly. The specific accreditation requirements and laboratory roles are defined by the governing program documentation. Because program structures and accreditation requirements can change, readers should verify the current testing and accreditation arrangements against the authoritative program sources before planning a validation effort.
How should procurement teams document a requirement for cryptographic modules aligned to ISO/IEC 19790?
Procurement language should generally reference the applicable federal validation requirement and specify the required security level and validation status rather than citing the international standard in isolation, since federal systems typically rely on the FIPS implementation and formal validation. Because a validation certificate is tied to specific module versions and configurations, teams should require evidence of current validation applicable to the exact module and version being acquired. Confirm the precise contractual and validation wording against current official program and acquisition guidance.

Common misconceptions

ISO/IEC 19790 and FIPS 140 are the same standard and are interchangeable.
They are distinct publications maintained by different bodies. ISO/IEC 19790 is an international standard, while FIPS 140 is a U.S. federal standard validated under the NIST-administered CMVP. Although their content has been aligned across revisions, U.S. federal, defense, and national security use cases generally depend on the specific FIPS validation status rather than on ISO/IEC 19790 conformance by itself. Confirm the applicable requirement against current official sources.
Conformance with ISO/IEC 19790 automatically satisfies U.S. government cryptographic requirements.
Meeting an international standard does not, on its own, establish that a module satisfies agency-specific or DoD cryptographic requirements. Federal and defense procurement generally look to validated modules recognized through the applicable U.S. program. Practitioners should verify which validation is required for their system category and impact level.
Using an ISO/IEC 19790-aligned cryptographic module makes a system compliant and secure.
A validated or standard-conformant cryptographic module addresses only the module itself and does not by itself make a broader system compliant or secure. Correct configuration, key management, integration, and continuous monitoring within the overall authorization boundary remain the operator's responsibility.

Best practices

Verify the specific edition or revision of ISO/IEC 19790 that applies to your context, since requirements and security-level definitions can change across editions.
Confirm the applicable cryptographic validation requirement for your system category and impact level with current authoritative sources rather than assuming ISO/IEC 19790 conformance alone is sufficient.
Where U.S. federal, defense, or national security systems are involved, verify the module's validation status through the applicable NIST-administered program instead of relying on international conformance by itself.
Distinguish the cryptographic module boundary from the broader system, and ensure configuration, key management, and integration are handled correctly outside the module's validated scope.
Treat module validation as one element of overall system security, not a substitute for the full authorization and continuous monitoring processes.
Consult current official publications to resolve any agency-specific interpretation before relying on a module for a particular system or contract.