ISO/IEC 25791-1:2026 defines a baseline security profile based on OpenID Connect FAPI Security Profile 1.0. It addresses how applications obtain OAuth tokens, identify users through OpenID Connect, and access REST APIs at a moderate security level. This page summarizes the standard's recorded facts, scope, and compliance context for engineers and procurement teams. Readers who need the authoritative text should obtain it from official IEC or ISO distribution channels.

Standard Information

ISO/IEC 25791-1:2026 is a current international standard published on 2026-09-04 by joint technical committee ISO/IEC JTC 1. It specifies baseline requirements within the OpenID Connect FAPI Security Profile 1.0 framework. The document concerns information technology security, covering token acquisition, customer identification through OpenID Connect, and secure REST API access for applications handling protected data. - Designation: ISO/IEC 25791-1:2026
- Full title: Information technology - OpenID Connect FAPI Security Profile 1.0 - Part 1: Baseline
- Status: Current
- Publication date: 2026-09-04
- ICS classification: 35, 35.030
- Technical committee: ISO/IEC JTC 1

Scope and Application

The document specifies a method for an application to obtain OAuth tokens in a moderately secure manner for access to protected data. Token issuance is therefore treated as a defined process rather than an implementation choice left entirely to the integrator. The profile constrains how an application requests and receives authorization credentials. Identification of the customer, meaning the end user, is handled through OpenID Connect (OIDC). The standard describes how an application uses OIDC to establish who the user is before granting access to protected resources. A third element covers the use of tokens to access REST APIs in a moderately secure manner. Application areas include any software system in the information technology domain where OAuth tokens, OIDC user identification, and REST API access must operate under a common baseline security profile, consistent with the ICS 35.030 classification covering IT security techniques.

Products and Materials Covered

As an information technology standard, this document does not cover physical products, equipment, or materials in the traditional sense. The objects in scope are software artifacts and protocol implementations: applications that obtain OAuth tokens, OpenID Connect identity functions used to identify the customer, and REST API interfaces accessed with those tokens. Under the ICS classification 35 (information technology) and 35.030 (IT security techniques), the relevant product families include identity and access management software, authorization servers and client applications implementing OAuth and OIDC flows, and API gateways or REST interfaces protecting data. Conformity therefore applies to the behavior of these software components and their protocol exchanges, not to hardware, materials, or chemical composition. No physical test specimens are associated with this standard.

Testing and Compliance Considerations

Conformity assessment for a security profile of this type is typically performed through functional verification of protocol behavior. A laboratory or assessment team examines whether an application's token acquisition flow, OIDC identification process, and API access exchanges match the requirements stated in the standard. Evidence is collected from observed protocol exchanges, configuration documentation, and implementation descriptions supplied by the developer. Acceptance verification generally follows the structure of the profile: each specified method — token issuance, user identification, and API access — is checked separately, and results are recorded in a test report. Because no pass or fail values can be cited beyond the standard itself, assessment teams derive their verdicts directly from the published requirements. Retest triggers include software updates that alter authentication or authorization flows, changes to the identity provider or token endpoint configuration, and reported security incidents affecting token handling. Organizations should keep documentation of assessed versions so that later changes can be traced and re-evaluated where needed.

Related Standards and Series Context

The designation ISO/IEC 25791-1:2026 reveals its structure. The prefix ISO/IEC indicates a standard developed jointly by ISO and IEC through their joint technical committee, ISO/IEC JTC 1. The number 25791 identifies the standard series; the suffix "-1" marks this document as Part 1 of that series. The final segment, 2026, is the publication year of this edition. The "Part 1: Baseline" element in the title indicates the position of this document within a multi-part structure, with the baseline profile forming the foundational layer. Where additional parts exist, they would carry successive part numbers under the same series number. Readers should confirm the current status of any related documents through official ISO or IEC catalogues rather than assuming their content from the numbering alone.

Quick Answers

Frequently Asked Questions

01

When

is retesting required after certification to ISO/IEC 25791-1:2026 – Information technology - OpenID Connect FAPI Security Profile 1.0 - Part 1: Baseline?
Retesting is generally required when the certified implementation undergoes changes affecting its security profile conformance, such as modifications to authorization flows, client authentication, or token handling. Disputed test results may also trigger retesting under agreed procedures between the client and the testing laboratory.

02

What

is the turnaround time and how are reports for ISO/IEC 25791-1:2026 FAPI Security Profile 1.0 Baseline testing delivered?
Turnaround depends on the scope of conformance testing, product complexity, and laboratory scheduling, and is confirmed in the service agreement. Upon completion, the laboratory issues a formal test report covering compliance with the baseline requirements, delivered in the format and language specified in the contract.

03

What

sample requirements apply when submitting products for ISO/IEC 25791-1:2026 Part 1 Baseline conformity testing?
Since this standard addresses software-based security profiles rather than physical materials, submissions typically involve deployed implementations or test instances of the OpenID Connect FAPI environment, along with configuration documentation and access arrangements needed for the laboratory to perform conformance testing.

← Previous Article Seat belt testing
Next Article → Security door testing

Ready to Discuss Your Testing Needs?

Contact our team for a customized quote and expert consultation on your ISO/IEC 25791-1:2026 – Information technology - OpenID Connect FAPI Security Profile 1.0 - Part 1: B testing requirements.

Contact Our Team