ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
ISO/IEC 23837 (Parts 1 and 2) specifies security requirements and evaluation methods for quantum key distribution modules and networks. Part 1 defines security requirements covering: QKD module security, key generation, key management, authentication, physical security, and side-channel resistance. Part 2 defines evaluation methodology. Developed by ISO/IEC JTC 1/SC 27 (Information security) in coordination with ETSI ISG QKD. Provides a Common Criteria-compatible evaluation framework for QKD implementations. Adopted by national QKD certification schemes including BSI (Germany) and ANSSI (France).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (26)
Assurance
| Code | Title |
|---|---|
| 23837-SAR | Security Assurance Requirements |
Channel
| Code | Title |
|---|---|
| 23837-CHAN | Channel Integrity and Authentication |
Clause 1-3: Introductory Provisions
| Code | Title |
|---|---|
| 23837-1.1 | Scope |
| 23837-1.2 | Normative references |
| 23837-1.3 | Terms and definitions |
| 27557-1 | Scope |
| 27557-2 | Normative references |
| 27557-3 | Terms and definitions |
Clause 4: QKD Module Security Overview
| Code | Title |
|---|---|
| 23837-1.4.1 | QKD module structural analysis |
| 23837-1.4.2 | Classification of QKD protocols |
| 23837-1.4.3 | Security problems analysis |
Clause 5: Security Functional Requirements for Conventional Network Components
| Code | Title |
|---|---|
| 23837-1.5.1 | Network component SFRs overview |
| 23837-1.5.2 | Cryptographic module requirements |
| 23837-1.5.3 | Network device testing requirements |
Clause 6: Security Functional Requirements for Quantum Optical Components
| Code | Title |
|---|---|
| 23837-1.6.1 | Quantum optical component SFRs |
| 23837-1.6.2 | Photon source security |
| 23837-1.6.3 | Quantum channel security |
Clause 7: Security Functional Requirements for QKD Protocol Implementation
| Code | Title |
|---|---|
| 23837-1.7.1 | Protocol implementation SFRs |
| 23837-1.7.2 | Key distillation process security |
| 23837-1.7.3 | Authentication and classical post-processing |
Guidance
| Code | Title |
|---|---|
| 23837-GUI | Guidance Documentation |
Incident
| Code | Title |
|---|---|
| 23837-INC | Incident Handling |
Integration
| Code | Title |
|---|---|
| 23837-NET | Network Integration |
Key Management
| Code | Title |
|---|---|
| 23837-KEYMGT | Output Key Management |
Lifecycle
| Code | Title |
|---|---|
| 23837-LCM | Life-cycle Management |
Operations
| Code | Title |
|---|---|
| 23837-MON | Operational Monitoring |
Part 2: Evaluation and Testing Methods
| Code | Title |
|---|---|
| 23837-2.1 | Evaluation activities for protocol implementation |
| 23837-2.2 | Evaluation activities for quantum optical components |
| 23837-2.3 | Evaluation activities for conventional network components |
| 23837-2.4 | Evaluation assurance levels |
Physical Layer
| Code | Title |
|---|---|
| 23837-SRC | Source and Detector Characterisation |
Physical Security
| Code | Title |
|---|---|
| 23837-PHY | Physical Security of Modules |
Post-processing
| Code | Title |
|---|---|
| 23837-EC | Error Correction Parameters |
| 23837-PA | Privacy Amplification |
Proof
| Code | Title |
|---|---|
| 23837-PROOF | Security Proof Mapping |
Randomness
| Code | Title |
|---|---|
| 23837-RNG | Random Number Generation |
Requirements
| Code | Title |
|---|---|
| 23837-SFR | Security Functional Requirements |
SDLC
| Code | Title |
|---|---|
| 23837-DEV | Development Process Assurance |
Scope
| Code | Title |
|---|---|
| 23837-TOE | Target of Evaluation Definition |
Security Requirements
QKD module and network security
Side-channels
| Code | Title |
|---|---|
| 23837-SIDE | Side-channel Resistance |
Testing
| Code | Title |
|---|---|
| 23837-TEST | Test Methods and Evaluation |
Vulnerability
| Code | Title |
|---|---|
| 23837-VULN | Vulnerability Analysis |
Your Compliance Coverage
If you comply with ISO/IEC 23837 - Security Requirements for Quantum Key Distribution, you already cover:
NIS2 Directive Implementing Acts
17%
7 controls mapped
Compare →UK Telecommunications (Security) Act 2021
17%
7 controls mapped
Compare →NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
17%
7 controls mapped
Compare →+ 623 more: CIS Controls v8 (17%), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (17%)
See all 626 mapped frameworks ↓Maps to 626 other frameworks
Frequently Asked Questions
What is ISO/IEC 23837 - Security Requirements for Quantum Key Distribution?
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution is a compliance framework from International (ISO/IEC) with 26 domains and 42 controls. ISO/IEC 23837 (Parts 1 and 2) specifies security requirements and evaluation methods for quantum key distribution modules and networks. Part 1 defines security requirements covering: QKD module security, key generation, key management, authentication, physical security, and side-channel resistance. Part 2 defines evaluation methodology. Developed by ISO/IEC JTC 1/SC 27 (Information security) in coordination with ETSI ISG QKD. Provides a Common Criteria-compatible evaluation framework for QKD implementations. Adopted by national QKD certification schemes including BSI (Germany) and ANSSI (France). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 23837 - Security Requirements for Quantum Key Distribution have?
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution has 42 controls organised across 26 domains. The largest domains are Clause 1-3: Introductory Provisions (6 controls), Part 2: Evaluation and Testing Methods (4 controls), Clause 4: QKD Module Security Overview (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 23837 - Security Requirements for Quantum Key Distribution map to?
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution maps to 626 other compliance frameworks. The top mapping partners are NIS2 Directive Implementing Acts (17% coverage), UK Telecommunications (Security) Act 2021 (17% coverage), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (17% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/IEC 23837 - Security Requirements for Quantum Key Distribution compliance?
Start your ISO/IEC 23837 - Security Requirements for Quantum Key Distribution compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 23837 - Security Requirements for Quantum Key Distribution requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required