Back to Frameworks

ISO/IEC 23837 - Security Requirements for Quantum Key Distribution

International (ISO/IEC)
v2023
25 domains
42 controls

ISO/IEC 23837 (Parts 1 and 2) specifies security requirements and evaluation methods for quantum key distribution modules and networks. Part 1 defines security requirements covering: QKD module security, key generation, key management, authentication, physical security, and side-channel resistance. Part 2 defines evaluation methodology. Developed by ISO/IEC JTC 1/SC 27 (Information security) in coordination with ETSI ISG QKD. Provides a Common Criteria-compatible evaluation framework for QKD implementations. Adopted by national QKD certification schemes including BSI (Germany) and ANSSI (France).

Unverified

ISO/IEC 23837 - Security Requirements for Quantum Key Distribution is a compliance framework from International (ISO/IEC) with 25 domains and 42 controls that map to 167 other frameworks. The largest domains are Clause 1-3: Introductory Provisions (6 controls), Part 2: Evaluation and Testing Methods (4 controls), Clause 4: QKD Module Security Overview (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (25)

Assurance

1 controls
Controls in the Assurance domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-SARSecurity Assurance Requirements

Channel

1 controls
Controls in the Channel domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-CHANChannel Integrity and Authentication

Clause 1-3: Introductory Provisions

6 controls

Clause 4: QKD Module Security Overview

3 controls
Controls in the Clause 4: QKD Module Security Overview domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution3 controls
CodeTitle
23837-1.4.1QKD module structural analysis
23837-1.4.2Classification of QKD protocols
23837-1.4.3Security problems analysis

Clause 5: Security Functional Requirements for Conventional Network Components

3 controls
Controls in the Clause 5: Security Functional Requirements for Conventional Network Components domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution3 controls
CodeTitle
23837-1.5.1Network component SFRs overview
23837-1.5.2Cryptographic module requirements
23837-1.5.3Network device testing requirements

Clause 6: Security Functional Requirements for Quantum Optical Components

3 controls
Controls in the Clause 6: Security Functional Requirements for Quantum Optical Components domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution3 controls
CodeTitle
23837-1.6.1Quantum optical component SFRs
23837-1.6.2Photon source security
23837-1.6.3Quantum channel security

Clause 7: Security Functional Requirements for QKD Protocol Implementation

3 controls
Controls in the Clause 7: Security Functional Requirements for QKD Protocol Implementation domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution3 controls
CodeTitle
23837-1.7.1Protocol implementation SFRs
23837-1.7.2Key distillation process security
23837-1.7.3Authentication and classical post-processing

Guidance

1 controls
Controls in the Guidance domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-GUIGuidance Documentation

Incident

1 controls
Controls in the Incident domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-INCIncident Handling

Integration

1 controls
Controls in the Integration domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-NETNetwork Integration

Key Management

1 controls
Controls in the Key Management domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-KEYMGTOutput Key Management

Lifecycle

1 controls
Controls in the Lifecycle domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-LCMLife-cycle Management

Operations

1 controls
Controls in the Operations domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-MONOperational Monitoring

Part 2: Evaluation and Testing Methods

4 controls
Controls in the Part 2: Evaluation and Testing Methods domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution4 controls
CodeTitle
23837-2.1Evaluation activities for protocol implementation
23837-2.2Evaluation activities for quantum optical components
23837-2.3Evaluation activities for conventional network components
23837-2.4Evaluation assurance levels

Physical Layer

1 controls
Controls in the Physical Layer domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-SRCSource and Detector Characterisation

Physical Security

1 controls
Controls in the Physical Security domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-PHYPhysical Security of Modules

Post-processing

2 controls
Controls in the Post-processing domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution2 controls
CodeTitle
23837-ECError Correction Parameters
23837-PAPrivacy Amplification

Proof

1 controls
Controls in the Proof domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-PROOFSecurity Proof Mapping

Randomness

1 controls
Controls in the Randomness domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-RNGRandom Number Generation

Requirements

1 controls
Controls in the Requirements domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-SFRSecurity Functional Requirements

SDLC

1 controls
Controls in the SDLC domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-DEVDevelopment Process Assurance

Scope

1 controls
Controls in the Scope domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-TOETarget of Evaluation Definition

Side-channels

1 controls
Controls in the Side-channels domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-SIDESide-channel Resistance

Testing

1 controls
Controls in the Testing domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-TESTTest Methods and Evaluation

Vulnerability

1 controls
Controls in the Vulnerability domain of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution1 controls
CodeTitle
23837-VULNVulnerability Analysis

Your Compliance Coverage

If you comply with ISO/IEC 23837 - Security Requirements for Quantum Key Distribution, you already cover:

Maps to 167 other frameworks

36 total controls
W3C Verifiable Credentials (VC) Data Model 2.0
3 source controls mapped|2 target controls covered
8%
SLSA
3 source controls mapped|2 target controls covered
8%
Sigstore - Software Artifact Signing and Verification
3 source controls mapped|2 target controls covered
8%
SIG (Shared Assessments)
3 source controls mapped|2 target controls covered
8%
Secure by Design: A Guide for Manufacturers (CISA)
3 source controls mapped|2 target controls covered
8%
PTES
3 source controls mapped|2 target controls covered
8%
OWASP Top 10:2025
3 source controls mapped|3 target controls covered
8%
OWASP SAMM
3 source controls mapped|1 target controls covered
8%
OWASP MASVS
3 source controls mapped|3 target controls covered
8%
OWASP ASVS
3 source controls mapped|3 target controls covered
8%
OWASP API Security Top 10 - 2023
3 source controls mapped|2 target controls covered
8%
OpenSSF Scorecard
3 source controls mapped|2 target controls covered
8%
Oman National Cybersecurity Framework
3 source controls mapped|2 target controls covered
8%
O-RAN WG11 Security Specification
3 source controls mapped|2 target controls covered
8%
NIST SP 800-92
3 source controls mapped|1 target controls covered
8%
NIST SP 800-88
3 source controls mapped|2 target controls covered
8%
8%
NIST SP 800-66
3 source controls mapped|1 target controls covered
8%
NIST SP 800-63-4
3 source controls mapped|2 target controls covered
8%
NIST SP 800-61
3 source controls mapped|2 target controls covered
8%
NIST SP 800-146
3 source controls mapped|1 target controls covered
8%
NIST SP 800-145
3 source controls mapped|1 target controls covered
8%
NIST SP 800-144
3 source controls mapped|2 target controls covered
8%
NIST SP 800-137
3 source controls mapped|2 target controls covered
8%
NIST SP 800-123
3 source controls mapped|2 target controls covered
8%
NIST Privacy Framework
3 source controls mapped|2 target controls covered
8%
NIS2 Directive Implementing Acts
3 source controls mapped|2 target controls covered
8%
NAIC Insurance Data Security Model Law (MDL-668)
3 source controls mapped|2 target controls covered
8%
MTCS (Singapore)
3 source controls mapped|2 target controls covered
8%
MITRE D3FEND
3 source controls mapped|1 target controls covered
8%
MITRE ATT&CK
3 source controls mapped|2 target controls covered
8%
MDS2 (Medical Device)
3 source controls mapped|2 target controls covered
8%
MARS-E
3 source controls mapped|4 target controls covered
8%
ISMAP (Japan)
3 source controls mapped|2 target controls covered
8%
HL7 FHIR Security Framework
3 source controls mapped|2 target controls covered
8%
Ghana Cybersecurity Act
3 source controls mapped|2 target controls covered
8%
FTC GLBA Safeguards Rule (16 CFR Part 314)
3 source controls mapped|1 target controls covered
8%
FISMA
3 source controls mapped|2 target controls covered
8%
FIDO2 / WebAuthn
3 source controls mapped|2 target controls covered
8%
FedRAMP Rev 5
3 source controls mapped|2 target controls covered
8%
FDA 21 CFR Part 11
3 source controls mapped|2 target controls covered
8%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|5 target controls covered
8%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
3 source controls mapped|5 target controls covered
8%
ISO/SAE 21434
3 source controls mapped|4 target controls covered
8%
ISO 27799
3 source controls mapped|3 target controls covered
8%
ISO 13485
3 source controls mapped|4 target controls covered
8%
UK Open Banking Standard
3 source controls mapped|4 target controls covered
8%
NIST SP 800-53 Rev 5
3 source controls mapped|5 target controls covered
8%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
3 source controls mapped|2 target controls covered
8%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
3 source controls mapped|4 target controls covered
8%
ASD Strategies to Mitigate Cyber Security Incidents
3 source controls mapped|3 target controls covered
8%
Belgium CyberFundamentals
3 source controls mapped|2 target controls covered
8%
South Korea ISMS-P
3 source controls mapped|2 target controls covered
8%
ISO 27017
3 source controls mapped|2 target controls covered
8%
ISO 19011
3 source controls mapped|3 target controls covered
8%
8%
NIST SP 800-190
3 source controls mapped|2 target controls covered
8%
ISO/IEC 27400:2022
3 source controls mapped|2 target controls covered
8%
ISO 27018
3 source controls mapped|2 target controls covered
8%
3GPP 5G Security Architecture (TS 33.501)
3 source controls mapped|2 target controls covered
8%
ISO 27043
3 source controls mapped|4 target controls covered
8%
TISAX - Trusted Information Security Assessment Exchange
3 source controls mapped|3 target controls covered
8%
BSI IT-Grundschutz
3 source controls mapped|2 target controls covered
8%
Virginia CDPA
2 source controls mapped|1 target controls covered
6%
Vietnam PDPD
2 source controls mapped|1 target controls covered
6%
Uruguay DPL
2 source controls mapped|1 target controls covered
6%
Turkey KVKK
2 source controls mapped|1 target controls covered
6%
Texas Data Privacy Act
2 source controls mapped|1 target controls covered
6%
Taiwan PDPA
2 source controls mapped|1 target controls covered
6%
PSD2 SCA
2 source controls mapped|1 target controls covered
6%
Qatar DPL
2 source controls mapped|1 target controls covered
6%
Privacy Act 2020
2 source controls mapped|1 target controls covered
6%
Privacy Act 1988 (Australia)
2 source controls mapped|1 target controls covered
6%
POPIA
2 source controls mapped|1 target controls covered
6%
Peru DPL
2 source controls mapped|1 target controls covered
6%
Personal Data Act (personopplysningsloven)
2 source controls mapped|1 target controls covered
6%
PDPA Thailand
2 source controls mapped|1 target controls covered
6%
PDPA Singapore
2 source controls mapped|1 target controls covered
6%
OSFI B-13
2 source controls mapped|1 target controls covered
6%
Oregon Consumer Privacy Act
2 source controls mapped|1 target controls covered
6%
Open Banking Security
2 source controls mapped|1 target controls covered
6%
NIST SP 800-122
2 source controls mapped|1 target controls covered
6%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
2 source controls mapped|3 target controls covered
6%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
2 source controls mapped|1 target controls covered
6%
Nigeria Data Protection Regulation (NDPR)
2 source controls mapped|1 target controls covered
6%
Nigeria Data Protection Act 2023 (NDPA)
2 source controls mapped|2 target controls covered
6%
Nebraska Data Privacy Act
2 source controls mapped|2 target controls covered
6%
New Zealand Information Security Manual (NZISM)
2 source controls mapped|1 target controls covered
6%
New Jersey Data Privacy Act
2 source controls mapped|1 target controls covered
6%
New Hampshire Data Privacy Act
2 source controls mapped|1 target controls covered
6%
Montana Consumer Data Privacy Act
2 source controls mapped|1 target controls covered
6%
Monetary Authority of Singapore Technology Risk Management Guidelines
2 source controls mapped|1 target controls covered
6%
Minnesota Consumer Data Privacy Act
2 source controls mapped|1 target controls covered
6%
Mexico LFPDPPP
2 source controls mapped|1 target controls covered
6%
Mauritius DPA
2 source controls mapped|1 target controls covered
6%
Maryland Online Data Privacy Act of 2024
2 source controls mapped|1 target controls covered
6%
Malaysia PDPA 2010
2 source controls mapped|1 target controls covered
6%
Liechtenstein DPA
2 source controls mapped|1 target controls covered
6%
LGPD
2 source controls mapped|1 target controls covered
6%
Ley Orgánica de Protección de Datos Personales (LOPDP)
2 source controls mapped|1 target controls covered
6%
Law No. 172-13 on the Protection of Personal Data
2 source controls mapped|1 target controls covered
6%
Kentucky Consumer Data Protection Act
2 source controls mapped|1 target controls covered
6%
Jamaica Data Protection Act 2020
2 source controls mapped|1 target controls covered
6%
Iowa Consumer Data Protection Act
2 source controls mapped|1 target controls covered
6%
Indonesia PDP Law
2 source controls mapped|1 target controls covered
6%
Indiana Consumer Data Protection Act
2 source controls mapped|1 target controls covered
6%
India DPDP Act
2 source controls mapped|1 target controls covered
6%
6%
HKMA SPM
2 source controls mapped|1 target controls covered
6%
HKMA Cyber Resilience Assessment Framework (C-RAF)
2 source controls mapped|1 target controls covered
6%
HITECH Act
2 source controls mapped|1 target controls covered
6%
GLBA
2 source controls mapped|1 target controls covered
6%
Family Educational Rights and Privacy Act (FERPA)
2 source controls mapped|1 target controls covered
6%
FBI CJIS Security Policy
2 source controls mapped|2 target controls covered
6%
NSA Guidance for Transition to Quantum-Resistant Cryptography
2 source controls mapped|3 target controls covered
6%
IEC 62351 - Power Systems Communication Security
2 source controls mapped|1 target controls covered
6%
Saudi Arabia PDPL
2 source controls mapped|1 target controls covered
6%
ISO 31000:2018
2 source controls mapped|1 target controls covered
6%
ISO/IEC 27011:2024
2 source controls mapped|1 target controls covered
6%
US ITAR and EAR - Export Control and Data Security
2 source controls mapped|2 target controls covered
6%
FFIEC IT Examination Handbook
2 source controls mapped|1 target controls covered
6%
Bahrain PDPL
2 source controls mapped|1 target controls covered
6%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
2 source controls mapped|1 target controls covered
6%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
2 source controls mapped|1 target controls covered
6%
PCI SSF
2 source controls mapped|1 target controls covered
6%
APPI
2 source controls mapped|1 target controls covered
6%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
2 source controls mapped|1 target controls covered
6%
ISO 27005
2 source controls mapped|1 target controls covered
6%
ISO 20000-1
2 source controls mapped|1 target controls covered
6%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
2 source controls mapped|1 target controls covered
6%
SOC for Cybersecurity - Cybersecurity Risk Management Examination
2 source controls mapped|1 target controls covered
6%
ISO/IEC 27010:2015
2 source controls mapped|1 target controls covered
6%
PCI PIN Security
2 source controls mapped|1 target controls covered
6%
PCI P2PE
2 source controls mapped|1 target controls covered
6%
WCAG 2.2
1 source controls mapped|1 target controls covered
3%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
3%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
3%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
3%
Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter
1 source controls mapped|1 target controls covered
3%
TSA Pipeline Cybersecurity Directives
1 source controls mapped|1 target controls covered
3%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
3%
SWIFT CSCF
1 source controls mapped|1 target controls covered
3%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
3%
OWASP Top 10 for LLM Applications 2025
1 source controls mapped|2 target controls covered
3%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|1 target controls covered
3%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|1 target controls covered
3%
GLI-33 - Gaming Laboratories International Event Wagering Systems
1 source controls mapped|1 target controls covered
3%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|2 target controls covered
3%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
1 source controls mapped|1 target controls covered
3%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|1 target controls covered
3%
UK Telecommunications (Security) Act 2021
1 source controls mapped|1 target controls covered
3%
SSAE 18 - Attestation Standards (SOC Reporting)
1 source controls mapped|1 target controls covered
3%
Armenia Law on Protection of Personal Data (2015)
1 source controls mapped|1 target controls covered
3%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|2 target controls covered
3%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
3%
NIST Cybersecurity Framework 2.0
1 source controls mapped|2 target controls covered
3%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
1 source controls mapped|1 target controls covered
3%

What is ISO/IEC 23837 - Security Requirements for Quantum Key Distribution and who does it apply to?

ISO/IEC 23837 - Security Requirements for Quantum Key Distribution is a compliance framework from International (ISO/IEC) with 25 domains and 42 controls. ISO/IEC 23837 (Parts 1 and 2) specifies security requirements and evaluation methods for quantum key distribution modules and networks. Part 1 defines security requirements covering: QKD module security, key generation, key management, authentication, physical security, and side-channel resistance. Part 2 defines evaluation methodology. Developed by ISO/IEC JTC 1/SC 27 (Information security) in coordination with ETSI ISG QKD. Provides a Common Criteria-compatible evaluation framework for QKD implementations. Adopted by national QKD certification schemes including BSI (Germany) and ANSSI (France). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/IEC 23837 - Security Requirements for Quantum Key Distribution actually require?

ISO/IEC 23837 - Security Requirements for Quantum Key Distribution has 42 controls organised across 25 domains. The largest domains are Clause 1-3: Introductory Provisions (6 controls), Part 2: Evaluation and Testing Methods (4 controls), Clause 4: QKD Module Security Overview (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/IEC 23837 - Security Requirements for Quantum Key Distribution do I already cover?

ISO/IEC 23837 - Security Requirements for Quantum Key Distribution maps to 167 other compliance frameworks. The top mapping partners are W3C Verifiable Credentials (VC) Data Model 2.0 (8% coverage), SLSA (8% coverage), Sigstore - Software Artifact Signing and Verification (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ISO/IEC 23837 - Security Requirements for Quantum Key Distribution?

Start your ISO/IEC 23837 - Security Requirements for Quantum Key Distribution compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 23837 - Security Requirements for Quantum Key Distribution requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required