ISO/IEC 19790 Evaluation
STQC IT – ERTL(N) provides independent evaluation and testing services for cryptographic modules in accordance with the requirements of ISO/IEC 19790 for Security Levels 1 to 4. The evaluation activities are performed in conjunction with ISO/IEC 24759, which specifies the associated testing requirements, evaluation procedures, and validation methodology for cryptographic modules. The services are intended to support vendors, developers, integrators, and solution providers seeking independent assessment of cryptographic modules against internationally recognized security requirements.
Evaluation Scope
The evaluation services cover cryptographic functionalities implemented within security products and systems that may be categorized, as identified in ISO/IEC 19790, as:
- Hardware cryptographic modules
- Software cryptographic modules
- Firmware cryptographic modules
- Hybrid cryptographic modules
The evaluation may be applicable to products such as (but is not limited to) IoT and Embedded Security Devices, Security Appliances and Gateways, Cryptographic Libraries and Security Software, Network Security Products etc.
Evaluation Activities
The evaluation process includes, but is not limited to, the following activities:
- Review of security documentation, module specification, and architecture
- Verification of cryptographic services, approved algorithms, and security functions
- Validation and/or verification of the cryptographic mechanisms implemented by the TOE
- Assessment of roles, services, access control, and authentication mechanisms
- Evaluation of key management processes and protection mechanisms
- Verification of software/firmware integrity and trusted initialization controls
- Assessment of physical security and operational environment requirements
- Verification of self-tests, integrity tests, and error handling mechanisms
- Review of life-cycle assurance, configuration management, and secure delivery procedures
- Vulnerability analysis and verification of mitigation mechanisms against applicable attack vectors
Evaluation Outcome
A cryptographic module may be considered compliant when all applicable requirements of ISO/IEC 19790 are satisfactorily met, the implemented security functions operate as claimed, Sensitive Security Parameters (SSPs) are adequately protected, and identified vulnerabilities have been appropriately addressed within the claimed operational environment.
Deliverables
The evaluation process may include the following deliverables, as applicable:
- Evaluation Test Plan
- Observation and Non-Conformity Reports
Evaluation Technical Report (ETR)







