ISO Updated Global Standards for Biometric Testing

A new draft standard for biometric systems adds vulnerability testing and modern performance metrics.

Updated on Oct. 5, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a geometric iris-scanner lens, representing updated global standards for biometric security testing.
The ISO/IEC 19795-6 working group has issued an updated global standard for biometric testing, integrating vulnerability metrics and modern performance benchmarks. AI Illustration. Upload story photo >

Live Poll

Do you trust global technology standards to effectively protect your personal data and security?

JTC 1/SC 37 has released a new working draft of the ISO/IEC 19795-6 standard. This update seeks to modernize the framework for evaluating operational systems, which was last revised in 2012.

Why it matters

The previous iteration of the standard predates current biometric capabilities, necessitating a structural shift to account for modern security threats and data protection requirements. These updates aim to align international testing benchmarks with contemporary operational realities.

The draft shifts the standard from operational testing to the testing of operational systems, replacing the prior metric of system identification rate with system acceptance and rejection rates. It also formalizes new technical definitions for biometric attack and bona-fide samples.

The players

JTC 1/SC 37

An international technical committee focused on the development of standards for biometric systems and human recognition technologies.

The details

The working group is redefining how biometric performance is measured by introducing precise terminology for attack samples—attempts to bypass a system using fraudulent biometric data—and bona-fide samples, which are legitimate submissions from authorized users. By including vulnerability testing and data protection guidance, the standard shifts focus toward evaluating how complete systems handle adversarial threats. This replaces the 2012-era framework that primarily focused on basic identification rates.

Timeline

  1. 2012: The original version of ISO/IEC 19795-6 was published.

  2. 2024: The previous standard version was last confirmed.

  3. October 2026: The new working draft was released for public review.

The Tech Race

Updating the ISO/IEC 19795-6 standard is a necessary step to address evolving biometric threats, following a pattern set by previous revisions of international security benchmarks. This effort aligns global testing criteria with the rapidly maturing landscape of automated identity verification.

This draft standard will eventually set the testing benchmarks used by developers and auditors to evaluate biometric security systems. Organizations implementing biometric verification will need to adjust their compliance workflows to meet these new standards for vulnerability and data protection.

The takeaway

The move toward standardized vulnerability testing signals that biometric security is shifting from simple identification accuracy to adversarial robustness. Interested parties should track the JTC 1/SC 37 committee's feedback cycle to anticipate the final requirements for biometric system compliance.

What happens next

The working group will incorporate community feedback received after the October 2026 release into the final version of the ISO/IEC 19795-6 standard.

Further reading

For more on the current state of industry protections, explore the Cybersecurity section.

Source note: This article includes information reported by Biometric Update.

Live Poll

Do you trust global technology standards to effectively protect your personal data and security?