ISO/IEC 19989-3 and ISO/IEC 30107, what is the difference? Written on

In a Nutshell
- ISO/IEC 30107-3 is the tested foundation for presentation attack detection, and it still counts.
- Private labs added their own levels on top of it, which made vendor claims hard to compare.
- The updated ETSI TS 119 461 points to ISO/IEC 19989-3 as the evaluation to use, and requires that testing to be independently repeated every two years, which every provider must have in place from 2027.
- ISO/IEC 19989-3 adds that independent Common Criteria evaluation and a common set of levels, traced back to the attack potential reference points in ISO/IEC 19989-1 Annex F.
- So this is not one standard versus another, it is a 30107-3 foundation that eIDAS 2.0 now expects you to certify to 19989-3.
- CEN/TS 18099 sits on a separate axis, injection attacks, not a third presentation attack standard.
If you lead compliance or certification at a QTSP, you have probably tried to compare two suppliers whose liveness claims do not line up. Both say they are certified to ISO/IEC 30107-3, one adds a level, another points to ISO/IEC 19989-3, and you have to decide which of them holds up in a conformity assessment. Here is what raises the stakes. The updated ETSI TS 119 461, the standard behind remote identity proofing under eIDAS 2.0, makes ISO/IEC 30107-3 and ISO/IEC 19989-3 normative references and requires the presentation attack detection behind a QTSP's proofing to be independently tested by an accredited lab every two years, which every provider must have in place from 2027. It sets the bar by the attacker your proofing has to resist, moderate attack potential for Baseline and high for Extended, which is the Common Criteria grading that ISO/IEC 19989-3 defines. So 19989-3 is not extra polish on top of a 30107-3 certificate, it is the evaluation the standard now points to. This post gives you a plain answer to how the two standards relate, and why 19989-3 builds on a 30107-3 certificate rather than replacing it.
What does ISO/IEC 30107-3 test, and why does it still count?
ISO/IEC 30107-3 is the international standard for testing and reporting presentation attack detection, or PAD. A presentation attack is a fake shown to the camera or sensor, a printed photo, a screen replay, a silicone mask, or a deepfake played back on a display. PAD is the system's ability to tell that apart from a real person.
The standard does two things well. It defines a shared vocabulary and a shared set of metrics, so that everyone measures the same thing. The two you will see most often are APCER, the attack presentation classification error rate, which is the share of attacks wrongly accepted as genuine, and BPCER, the bona fide presentation classification error rate, which is the share of real users wrongly rejected. It also sets out how those results should be reported, so a test outcome means something to a reader who was not in the lab.
This is the tested foundation, and it is genuinely valuable. A 30107-3 result tells you a PAD system was measured against real attack instruments using a published, peer-reviewed methodology rather than a vendor's own bench. When a supplier can show certification to 30107-3, they have done the hard, evidence-based part. Nothing that comes later replaces that. It sits underneath everything else in this post.
Where did private lab levels create confusion?
Here is where it gets muddy. ISO/IEC 30107-3 defines how to test and how to report, but it does not hand you a single, official ladder of "levels" to certify against. So evaluation programs and individual test labs built their own. You have almost certainly seen "PAD Level 1" and "PAD Level 2," and sometimes "Level 3," attached to 30107-3 certificates.
Those levels are a shorthand for attack difficulty. Broadly, a higher level means the PAD was tested against attacks that take more skill, more time, and more expensive equipment to produce. The problem is that the level names were not defined in one common place, so the attack sets, the pass thresholds, and the reporting behind them could differ from one scheme to the next. Two vendors can each hold a "Level 2" certificate and have been tested against meaningfully different things.
For you, that turns a simple procurement question into detective work. The certificates look comparable on the surface, but you cannot assume "Level 2 here" equals "Level 2 there" without reading the fine print of each lab's methodology. The fix keeps 30107-3 testing, which is doing its job, and adds one evaluation framework that every vendor is held to.
What does ISO/IEC 19989-3 add?
ISO/IEC 19989-3 is that framework. It is the standard for the security evaluation of presentation attack detection under Common Criteria, the international scheme for evaluating IT security defined by the ISO/IEC 15408 series.
The key word is evaluation. Where 30107-3 measures how well a PAD subsystem performs against a set of attacks, 19989-3 assesses whether that performance holds up against a defined level of attacker, judged by an independent evaluator working to a common methodology. It does not discard the 30107-3 testing. The standard says so plainly, it builds on the presentation attack detection testing methodology described in ISO/IEC 30107-3 and adds guidance for the evaluator on top. Think of 30107-3 as the measurement and 19989-3 as the independent, structured judgment of what that measurement proves against a stated threat.
Common Criteria brings two things the private level schemes lacked. First, the evaluation is done to one shared rulebook rather than a lab's in-house scheme, so results are meant to be read the same way wherever they were produced. Second, it frames the question around attacker capability, how much time, expertise, knowledge, opportunity, and equipment a realistic attacker would need to beat the system. That is a more honest way to describe security than a bare pass or fail, and it is the language auditors and regulators are moving toward.
How do the levels work under ISO/IEC 19989-1 Annex F?
The levels in this world are not invented per lab. They come from Common Criteria, and ISO/IEC 19989-3 inherits them through its parent standard, ISO/IEC 19989-1. The relevant reference is Annex F of 19989-1, a normative annex titled attack potential and TOE resistance. The TOE, or target of evaluation, is simply the thing being evaluated, in this case the PAD subsystem.
Annex F sets out how to rate attack potential and what level of resistance a system needs to claim. Attack potential is scored across factors such as elapsed time, expertise, knowledge of the system, window of opportunity, and equipment, then mapped onto named tiers. In Common Criteria terms those tiers run from basic, through enhanced basic and moderate, up to high. A higher claim means the system was shown to resist an attacker with more of those resources.
This is where the standards connect to the regulation you answer to. ETSI TS 119 461, the standard behind eIDAS 2.0 remote identity proofing, ties its assurance levels to exactly this scale, and it now requires the evaluation to be done, not just encouraged. Its Baseline level of identity proofing expects the risk assessment to consider at least attackers with moderate attack potential, and its Extended level expects at least high attack potential. So the vague question, "is Level 2 good enough," becomes a precise one, "does the evidence show resistance to the attack potential my level of proofing requires." That is a question you can answer with evidence when an auditor asks, instead of a label you hope holds up.
Why an auditor needs a common bar
Step into the auditor's seat for a moment. Their job is not to admire a certificate, it is to confirm that your identity proofing resists the attacks your assurance level assumes, and to do it in a way that stands up if it is ever challenged.
A private level claim makes that hard. If "Level 2" means one thing at one lab and something else at another, the auditor cannot take the label at face value, and neither can the regulator relying on the audit. A Common Criteria evaluation under 19989-3 removes that ambiguity. The result states the attack potential the system was shown to resist, produced under a shared methodology by an independent evaluator, and it reads the same way to your auditor, your regulator, and your customers.
That comparability is the whole point. It is why the updated ETSI TS 119 461 now points QTSPs to this kind of evaluation, and why certification to ISO/IEC 19989-3 is the bar high-assurance biometrics are held to. That reflects the strength of a common, independently judged result, and it takes nothing away from the 30107-3 foundation underneath. If you are building toward Level of Assurance High, this is the layer that turns a good test result into evidence an auditor can sign off without caveats.
What should you ask a supplier to show?
When claims do not line up, a few precise requests will sort a real position from a hopeful one. Ask to see the evidence behind each claim.
Ask to see the actual 30107-3 test report, not just the certificate, and check which attack instruments were used and what APCER and BPCER were reported. Ask which level was tested and, more importantly, which lab methodology sat behind that level, so you know what "Level 2" meant in their case. Then ask where they are with ISO/IEC 19989-3, whether they hold a Common Criteria evaluation, are in evaluation, or are aligning toward it, and to which attack potential under ISO/IEC 19989-1 Annex F. Finally, ask them to map their evidence to the level of identity proofing you need under ETSI TS 119 461, Baseline or Extended.
A strong supplier will welcome those questions and answer them with documents. The answer you want covers both, a solid 30107-3 foundation with a clear, honest position on the 19989-3 evaluation built on top of it.
Where does CEN/TS 18099 fit?
One more standard tends to enter this conversation, and it belongs on a different axis. CEN/TS 18099 is not a third presentation attack standard. It covers injection attacks, where fraudulent data is fed straight into the verification pipeline and bypasses the camera or sensor entirely, rather than being shown to it. That is a separate threat surface, so lining it up against 30107-3 and 19989-3 would be comparing apples to oranges. It complements the other two rather than competing with them.
Where Youverse stands
We hold certification to ISO/IEC 30107-3 at Levels 1 and 2 for presentation attack detection. That is the tested foundation, and we treat it as exactly that, evidence that our liveness has been measured against real attacks under a published methodology.
We are aligned with ISO/IEC 19989-3, with certification in progress, so the same PAD is moving toward independent Common Criteria evaluation against a defined attack potential under ISO/IEC 19989-1 Annex F. On the separate injection axis, we are aligned with CEN/TS 18099 and pursuing certification to its High level. Because we carry that testing across our stack, a QTSP that builds on Youverse inherits the two-yearly evaluation rather than standing it up and recertifying it in-house.
FAQ
Does ISO/IEC 19989-3 replace ISO/IEC 30107-3?
No, it builds on it. ISO/IEC 19989-3 uses the presentation attack detection testing methodology from ISO/IEC 30107-3 and adds an independent Common Criteria security evaluation on top of it. You still need the 30107-3 testing underneath. What 19989-3 adds is a common, independently judged view of what that testing proves against a defined attacker.
What is Common Criteria evaluation of biometrics?
Common Criteria, defined in the ISO/IEC 15408 series, is an international framework for evaluating the security of IT products against defined threats and attacker capability. ISO/IEC 19989 extends it to biometric systems, adding evaluation components for things like presentation attack detection. ISO/IEC 19989-3 is the part focused on PAD, so an independent evaluator assesses the system against a stated attack potential rather than only measuring error rates.
Which level do I need for high-assurance proofing?
For Level of Assurance High under eIDAS 2.0, ETSI TS 119 461 expects your risk assessment to consider attackers with high attack potential, which it ties to its Extended level of identity proofing, while Baseline maps to moderate attack potential. That points high-assurance proofing toward the top of the attack potential scale referenced through ISO/IEC 19989-1 Annex F. Confirm the exact target with your evaluator, since it depends on your level of identity proofing.
Is a 30107-3 certification still worth holding?
Yes. It is the tested foundation that shows your PAD was measured against real attacks using a published, peer-reviewed methodology. ISO/IEC 19989-3 does not make it obsolete, it takes the 30107-3 testing methodology and evaluates it under Common Criteria, so the result is comparable across vendors.
Is CEN/TS 18099 the same kind of standard as 30107-3?
No, it covers injection attacks. ISO/IEC 30107-3 addresses presentation attacks, where a fake is shown to the camera or sensor. CEN/TS 18099 addresses injection attacks, where fraudulent data is fed straight into the pipeline and bypasses the sensor. They protect against different threat surfaces, so one does not substitute for the other.
