ISO/IEC 29128-2:2026 defines evaluation methods and activities for cryptographic protocols. It extends the framework set out in ISO/IEC 15408-4 and maps work items to concrete evaluation actions. The document also introduces a four-level security assurance classification based on cryptographic assessment performed by automated provers. The sections below summarise its scope, application context and practical use in testing programmes.
Standard Information
ISO/IEC 29128-2:2026 is a current international standard published under the joint ISO/IEC technical committee responsible for information security, cybersecurity and privacy protection techniques. It addresses the verification of cryptographic protocols through defined evaluation methods and activities. As Part 2 of its series, it builds on an established evaluation framework rather than standing alone. - Designation: ISO/IEC 29128-2:2026
- Full title: Information security, cybersecurity and privacy protection - Verification of cryptographic protocols - Part 2: Evaluation methods and activities for cryptographic protocols
- Status: Current
- Publication date: 2026-09-01
- ICS classification: 35, 35.030
- Technical committee: ISO/IEC JTC 1/SC 27
Scope and Application
This document specifies an extension of evaluation methods and activities for cryptographic protocols based on ISO/IEC 15408-4, which supplies the underlying framework for those methods and activities. In practical terms, it takes the general evaluation framework and adapts it to the specific subject of cryptographic protocol verification. A central element is the mapping between work items for cryptographic protocol evaluation and the associated evaluation activities or evaluation methods. This mapping gives evaluators and developers a structured way to connect protocol-level work items with the concrete actions required during evaluation. The document additionally defines a security assurance classification built on cryptographic assessment performed by automated provers. Four levels of increasing assurance are distinguished, allowing the rigour of automated cryptographic verification to be graded and communicated.
Products and Materials Covered
The standard concerns cryptographic protocols themselves rather than physical products or materials. Under ICS classifications 35 and 35.030, its subject matter falls within information technology and IT security techniques, including applications of cryptography for security and privacy protection. Typical objects of evaluation are protocol specifications, protocol implementations submitted for security evaluation, and the supporting documentation that describes how a protocol meets defined security requirements. The four-level assurance classification also makes the document relevant to automated proving tools, since assurance levels derive from cryptographic assessment performed by such provers. No hardware family, material grade or manufacturing tolerance is involved. The standard belongs to the domain of security evaluation methodology, and its outputs are evaluation activities, methods and assurance classifications applied to cryptographic protocol verification.
Testing and Compliance Considerations
Laboratories working with evaluation-methodology standards of this kind typically begin by establishing which evaluation work items apply to the cryptographic protocol under review. The mapping in this document then guides the selection of corresponding activities or methods, so that each work item is addressed through a defined evaluation action. Where automated provers are used, laboratories record the assessment outcome and assign the resulting security assurance level from the four-tier classification. Documentation practices matter throughout: evaluation plans, evidence of protocol properties and prover outputs are retained so that conclusions can be traced to defined activities. Retest or re-evaluation triggers generally include changes to the protocol specification, changes to the toolchain used for automated assessment, or modification of the security target against which the protocol is evaluated. Acceptance verification in procurement contexts often references the achieved assurance level as an objective criterion. Readers who need the document itself should obtain it through official IEC or ISO channels, as this page is an interpretive overview only.
Related Standards and Series Context
The designation itself carries structural information. "ISO/IEC" indicates a jointly published international standard, and "29128" is the series number under which this multipart work is organised. The "-2" suffix identifies this document as the second part of that series, addressing evaluation methods and activities for cryptographic protocols. The year "2026" marks the publication date of this edition, following the common convention of appending the year of issue to the standard number. Within the broader ISO/IEC JTC 1 landscape, the document belongs to the committee responsible for security and privacy techniques, reflected in the ICS classifications 35 and 35.030.
Frequently Asked Questions
How is the submission process handled for ISO/IEC 29128-2:2026 – Information security, cybersecurity and privacy protection, and what are the key communication points?
Submit documentation covering the scope and application of ISO/IEC 29128-2:2026 – Information security, cybersecurity and privacy protection, along with product and material details. Key communication points include confirming covered items, agreed testing and compliance considerations, and series context with the laboratory.
What
factors affect the testing cost for ISO/IEC 29128-2:2026 – Information security, cybersecurity and privacy protection?
Costs depend on the scope and application of ISO/IEC 29128-2:2026 – Information security, cybersecurity and privacy protection, the products and materials covered, and the depth of testing and compliance considerations required. Complexity of related standards and series context also influences the overall effort.
How are retesting and data disputes handled under ISO/IEC 29128-2:2026 – Information security, cybersecurity and privacy protection?
Retesting follows the same testing and compliance considerations defined for ISO/IEC 29128-2:2026 – Information security, cybersecurity and privacy protection. Data disputes are resolved by reviewing the original scope, application, and documented procedures, with communication between applicant and laboratory determining whether retesting is warranted.