prCEN/CLC/TR XXX

Gaps in IT security evaluation of QKD systems and networks

General information

10.99   New project approved   Jul 24, 2025

CEN/CENELEC

CEN/CLC/JTC 22

Technical Report

Scope

The scope of this new WI covers the entire IT security evaluation and certification process of QKD systems and QKD networks according to ISO/EN 15408 “Common Criteria for IT Security Evaluation”, currently available in version CC:2022 (online: https://www.commoncriteriaportal.org/cc/index.cfm), where:
− standardized security specifications are necessary (e.g. Common Criteria Protection Profiles).
− standards are being (or need to be) referenced in security specifications, particularly:
o standards for applicable security proofs,
o standards for applicable use or random numbers,
o standardized catalogues of side channels and countermeasures (for specific technologies)
− standardized test and evaluation (T&E) methodologies need to be applied according to standards.
In addition, the entire process of IT security evaluation and certification for QKD systems and networks, including prerequisites for companies, especially SMEs, shall be described in detail.

Life cycle

NOW

IN_DEVELOPMENT
prCEN/CLC/TR XXX
10.99 New project approved
Jul 24, 2025