ISO/IEC 23837:2023
The ISO/IEC standard for evaluating quantum key distribution modules under the Common Criteria: part 1 sets the security problem and the baseline security functional requirements (the protocol and post-processing family FTP_QKD, 22 conventional network requirements and two optical ones), part 2 the evaluation activities that test them (sifting, post-processing and parameter adjustment, nine transmitter and ten receiver optical tests, parameter-adjustment attacks) and the assurance supplements up to EAL 5 augmented. Built from the BSI previews of both parts (part 2 held to 7.3), the project editor's presentation and the ETSI QKD protection profile; the rest of the body is not held.
ISO/IEC 23837:2023 is a compliance framework from International (ISO/IEC JTC 1/SC 27); adopted as BS ISO/IEC 23837-1 and -2:2023 and, for part 1, GSO ISO/IEC 23837-1:2024 (Bahrain Decision No. 34 of 2025) with 13 domains and 79 controls that map to 240 other frameworks. The largest domains are Part 1 9.2: SFRs for conventional network components – ISO/IEC 23837:2023 (22 controls), Part 2 Clauses 10 and 11: conventional components and SARs – ISO/IEC 23837:2023 (11 controls), Part 2 Clause 7: EAs for transmitter optical components – ISO/IEC 23837:2023 (10 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (13)
Part 1 9.2: SFRs for conventional network components – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::1-9.2.1 | Part 1, 9.2.1 FAU_GEN.1 Audit data generation |
| iso-iec-23837-2023::1-9.2.10 | Part 1, 9.2.10 FIA_UID.1 Timing of identification |
| iso-iec-23837-2023::1-9.2.11 | Part 1, 9.2.11 FMT_LIM.1 Limited capabilities |
| iso-iec-23837-2023::1-9.2.12 | Part 1, 9.2.12 FMT_LIM.2 Limited availability |
| iso-iec-23837-2023::1-9.2.13 | Part 1, 9.2.13 FMT_MSA.1 Management of security attributes |
| iso-iec-23837-2023::1-9.2.14 | Part 1, 9.2.14 FMT_MTD.1 Management of TSF data |
| iso-iec-23837-2023::1-9.2.15 | Part 1, 9.2.15 FMT_SMF.1 Specification of management functions |
| iso-iec-23837-2023::1-9.2.16 | Part 1, 9.2.16 FMT_SMR.1 Security roles |
| iso-iec-23837-2023::1-9.2.17 | Part 1, 9.2.17 FPT_EMS.1/Convention Emanation of TSF and user data |
| iso-iec-23837-2023::1-9.2.18 | Part 1, 9.2.18 FPT_FLS.1 Failure with preservation of secure state |
| iso-iec-23837-2023::1-9.2.19 | Part 1, 9.2.19 FPT_ITC.1 Inter-TSF confidentiality during transmission |
| iso-iec-23837-2023::1-9.2.2 | Part 1, 9.2.2 FCS_CKM.6 Timing and event of cryptographic key destruction |
| iso-iec-23837-2023::1-9.2.20 | Part 1, 9.2.20 FPT_ITI.1 Inter-TSF detection of modification |
| iso-iec-23837-2023::1-9.2.21 | Part 1, 9.2.21 FPT_RCV.2 Automated recovery |
| iso-iec-23837-2023::1-9.2.22 | Part 1, 9.2.22 FPT_TST.1 TSF self-testing |
| iso-iec-23837-2023::1-9.2.3 | Part 1, 9.2.3 FCS_COP.1 Cryptographic operation |
| iso-iec-23837-2023::1-9.2.4 | Part 1, 9.2.4 FCS_RNG.1 Random number generation |
| iso-iec-23837-2023::1-9.2.5 | Part 1, 9.2.5 FDP_ACC.1 Subset access control |
| iso-iec-23837-2023::1-9.2.6 | Part 1, 9.2.6 FDP_ACF.1 Security attribute-based access control |
| iso-iec-23837-2023::1-9.2.7 | Part 1, 9.2.7 FDP_IRC.1 Information retention control |
| iso-iec-23837-2023::1-9.2.8 | Part 1, 9.2.8 FDP_ITC.1 Import of user data without security attributes |
| iso-iec-23837-2023::1-9.2.9 | Part 1, 9.2.9 FIA_UAU.2 User authentication before any action |
Part 1 9.4: SFRs for quantum optical components – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::1-9.4.2 | Part 1, 9.4.2 FPT_EMS.1/Quantum Emanation of TSF and user data |
| iso-iec-23837-2023::1-9.4.3 | Part 1, 9.4.3 FPT_PHP.3 Resistance to physical attack |
Part 1 Clause 10: Conformance statement – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::1-10.2 | Part 1, 10.2 Conformance statement specific to the security problem definition |
| iso-iec-23837-2023::1-10.3 | Part 1, 10.3 Conformance statement specific to the security functional requirements |
Part 1 Clause 7: Security problem definition – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::1-7.2 | Part 1, 7.2 Security assumptions |
| iso-iec-23837-2023::1-7.3 | Part 1, 7.3 Assets analysis |
| iso-iec-23837-2023::1-7.4.2 | Part 1, 7.4.2 Threats from network-based classical attacks |
| iso-iec-23837-2023::1-7.5.2 | Part 1, 7.5.2 Threats exploiting optical source flaws |
| iso-iec-23837-2023::1-7.5.3 | Part 1, 7.5.3 Threats exploiting optical detection vulnerabilities |
| iso-iec-23837-2023::1-7.5.4 | Part 1, 7.5.4 Threats exploiting parameter adjustment vulnerabilities |
Part 1 Clause 8 and 9.3: the FTP_QKD family – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::1-9.3.2 | Part 1, 9.3.2 FTP_QKD.1 QKD protocol and raw data generation |
| iso-iec-23837-2023::1-9.3.3 | Part 1, 9.3.3 FTP_QKD.2 QKD post-processing |
Part 1 Clauses 5 and 6: QKD protocols and implementation modules – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::1-5.4 | Part 1, 5.4 Architecture: evaluation scope and merged parties |
| iso-iec-23837-2023::1-6.2.2 | Part 1, 6.2.2 The quantum channel interface |
| iso-iec-23837-2023::1-6.4 | Part 1, 6.4 TOE scope for QKD modules |
Part 2 Clause 12: Conformance statement – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::2-12.2 | Part 2, 12.2 Conformance statement specific to evaluation activities for SFRs |
| iso-iec-23837-2023::2-12.3 | Part 2, 12.3 Conformance statement specific to EAs for SARs |
Part 2 Clause 5: The evaluation method – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::2-5.3.1 | Part 2, 5.3.1 EAs for SFRs: content, inputs and calibration |
| iso-iec-23837-2023::2-5.3.3 | Part 2, 5.3.3 EAs for optical components and parameter adjustment: criteria and statistics |
| iso-iec-23837-2023::2-5.3.5 | Part 2, 5.3.5 Thresholds and input parameters |
| iso-iec-23837-2023::2-5.4 | Part 2, 5.4 Overview of evaluation activities for SARs |
Part 2 Clause 6: EAs for FTP_QKD – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::2-6.2 | Part 2, 6.2 EA to test quantum state transmission and sifting procedures |
| iso-iec-23837-2023::2-6.3 | Part 2, 6.3 EA to test other post-processing procedures |
| iso-iec-23837-2023::2-6.4 | Part 2, 6.4 EA to test parameter adjustment procedure(s) |
Part 2 Clause 7: EAs for transmitter optical components – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::2-7.1 | Part 2, 7.1 General conditions for transmitter EAs |
| iso-iec-23837-2023::2-7.10 | Part 2, 7.10 EA to test the robustness of the TX module against laser injection |
| iso-iec-23837-2023::2-7.2 | Part 2, 7.2 EA to test the photon-number distribution of optical pulses |
| iso-iec-23837-2023::2-7.3 | Part 2, 7.3 EA to test the mean photon number and stability of optical pulses |
| iso-iec-23837-2023::2-7.4 | Part 2, 7.4 EA to test the independence of the intensities of optical pulses |
| iso-iec-23837-2023::2-7.5 | Part 2, 7.5 EA to test the accuracy of state encoding |
| iso-iec-23837-2023::2-7.6 | Part 2, 7.6 EA to test the indistinguishability of encoded states |
| iso-iec-23837-2023::2-7.7 | Part 2, 7.7 EA to test the uniform distribution of the global phase of optical pulses |
| iso-iec-23837-2023::2-7.8 | Part 2, 7.8 EA to test the degree of optical isolation of the TX module |
| iso-iec-23837-2023::2-7.9 | Part 2, 7.9 EA to test the sensitivity of the injected light monitor in the TX module |
Part 2 Clause 8: EAs for receiver optical components – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::2-8.10 | Part 2, 8.10 EA to test the detection limits of homodyne detectors in the RX module |
| iso-iec-23837-2023::2-8.11 | Part 2, 8.11 EA to test the appropriateness of double-click event handling |
| iso-iec-23837-2023::2-8.2 | Part 2, 8.2 EA to test the consistency of detection probability in the RX module |
| iso-iec-23837-2023::2-8.3 | Part 2, 8.3 EA to test information leakage of back-flashes from the RX module |
| iso-iec-23837-2023::2-8.4 | Part 2, 8.4 EA to test the degree of optical isolation of the RX module |
| iso-iec-23837-2023::2-8.5 | Part 2, 8.5 EA to test the sensitivity of the injected light monitor in the RX module |
| iso-iec-23837-2023::2-8.6 | Part 2, 8.6 EA to test the robustness of the RX module against bright light blinding |
| iso-iec-23837-2023::2-8.7 | Part 2, 8.7 EA to test the appropriateness of dead time settings of SPDs |
| iso-iec-23837-2023::2-8.8 | Part 2, 8.8 EA to test the temporal profile of the detection efficiency for SPDs |
| iso-iec-23837-2023::2-8.9 | Part 2, 8.9 EA to test the robustness of the RX module against laser injection |
Part 2 Clause 9: EAs for parameter adjustment – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::2-9.2 | Part 2, 9.2 EA to test the inducibility of detection probability mismatch |
| iso-iec-23837-2023::2-9.3 | Part 2, 9.3 EA to test the correctness of shot noise alignment |
Part 2 Clauses 10 and 11: conventional components and SARs – ISO/IEC 23837:2023
| Code | Title |
|---|---|
| iso-iec-23837-2023::2-10.2 | Part 2, 10.2 Evaluation activities for FCS-related SFRs |
| iso-iec-23837-2023::2-10.3 | Part 2, 10.3 Evaluation activities for other SFRs |
| iso-iec-23837-2023::2-11.2 | Part 2, 11.2 Supplementary activities for Class APE: Protection Profile evaluation |
| iso-iec-23837-2023::2-11.3 | Part 2, 11.3 Supplementary activities for Class ASE: Security Target evaluation |
| iso-iec-23837-2023::2-11.4.1 | Part 2, 11.4.1 Supplementary activities for ADV_ARC |
| iso-iec-23837-2023::2-11.4.2 | Part 2, 11.4.2 Supplementary activities for ADV_FSP |
| iso-iec-23837-2023::2-11.5.1 | Part 2, 11.5.1 Supplementary activities for AGD_OPE |
| iso-iec-23837-2023::2-11.5.2 | Part 2, 11.5.2 Supplementary activities for AGD_PRE |
| iso-iec-23837-2023::2-11.6.1 | Part 2, 11.6.1 Supplementary activities for ATE_FUN |
| iso-iec-23837-2023::2-11.6.2 | Part 2, 11.6.2 Supplementary activities for ATE_IND |
| iso-iec-23837-2023::2-11.7 | Part 2, 11.7 Supplementary activities for Class AVA: Vulnerability assessment |
Your Compliance Coverage
If you comply with ISO/IEC 23837:2023, you already cover:
SLSA
4%
5 controls mapped
Compare →SIG (Shared Assessments)
4%
5 controls mapped
Compare →PTES
4%
5 controls mapped
Compare →+ 237 more: OWASP Top 10:2025 (4%), OWASP SAMM (4%)
See all 240 mapped frameworks ↓Maps to 240 other frameworks
Coverage is not the same as your position
This page shows what ISO/IEC 23837:2023 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is ISO/IEC 23837:2023 and who does it apply to?
ISO/IEC 23837:2023 is a compliance framework from International (ISO/IEC JTC 1/SC 27); adopted as BS ISO/IEC 23837-1 and -2:2023 and, for part 1, GSO ISO/IEC 23837-1:2024 (Bahrain Decision No. 34 of 2025) with 13 domains and 79 controls. The ISO/IEC standard for evaluating quantum key distribution modules under the Common Criteria: part 1 sets the security problem and the baseline security functional requirements (the protocol and post-processing family FTP_QKD, 22 conventional network requirements and two optical ones), part 2 the evaluation activities that test them (sifting, post-processing and parameter adjustment, nine transmitter and ten receiver optical tests, parameter-adjustment attacks) and the assurance supplements up to EAL 5 augmented. Built from the BSI previews of both parts (part 2 held to 7.3), the project editor's presentation and the ETSI QKD protection profile; the rest of the body is not held. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 23837:2023 actually require?
ISO/IEC 23837:2023 has 79 controls organised across 13 domains. The largest domains are Part 1 9.2: SFRs for conventional network components – ISO/IEC 23837:2023 (22 controls), Part 2 Clauses 10 and 11: conventional components and SARs – ISO/IEC 23837:2023 (11 controls), Part 2 Clause 7: EAs for transmitter optical components – ISO/IEC 23837:2023 (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 23837:2023 do I already cover?
ISO/IEC 23837:2023 maps to 240 other compliance frameworks. The top mapping partners are SLSA (4% coverage), SIG (Shared Assessments) (4% coverage), PTES (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 23837:2023?
Start your ISO/IEC 23837:2023 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 23837:2023 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 79 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 705 frameworks.
Get Started Free →Free forever — no credit card required