iBeta PAD Level 2
iBeta ISO 30107-3 Presentation Attack Detection Testing – Level 2 Certification (NVLAP-accredited)
Biometric software vendors must pass iBeta's ISO 30107-3 Level 2 testing using advanced attack instruments – 3D masks, silicone and latex replicas, and injection attacks – achieving Attack Presentation Classification Error Rate (APCER) below 5%.
What this covers
iBeta's ISO 30107-3 Presentation Attack Detection testing is the primary third-party liveness certification used in identity verification procurement. iBeta operates under NVLAP accreditation (National Voluntary Laboratory Accreditation Program), making it the de facto certification body for liveness testing against the ISO 30107-3 standard.
Level 1 testing uses basic attack materials – printed photographs, video replays on screens, flat 2D masks – that require minimal cost and skill to produce. Level 2 escalates to advanced attack instruments: 3D-printed masks, high-quality silicone and latex face replicas, and injection attacks that bypass the camera entirely. Level 2 is required for government-grade identity verification and most regulated financial services procurement.
The Level 2 thresholds require an Attack Presentation Classification Error Rate below 5% – the system must correctly reject more than 95% of presentation attacks. The Bona Fide Presentation Classification Error Rate must stay below 10%, ensuring legitimate users are not excessively rejected. Both thresholds must be met simultaneously; passing one while failing the other is a failed certification.
Critically, iBeta certifications are version-specific – they do not automatically extend to software updates. After significant algorithm changes or deployment to new hardware, re-testing is required. When evaluating vendors, request the tested software version and certification date. A certificate from two years ago referencing a prior algorithm version may not reflect the current product's performance under attack.
Frequently asked questions
What is the difference between iBeta PAD Level 1 and Level 2?
Level 1 tests against basic attacks – printed photos, video replays, and flat masks – using low-cost materials. Level 2 uses advanced instruments: 3D masks, silicone and latex face replicas, and injection attacks. Level 2 is required for government-grade identity verification and most regulated financial services procurement.
Is iBeta PAD Level 2 required by any regulation?
No regulation mandates iBeta Level 2 by name, but EU AI Act requirements, NIST SP 800-63 IAL2, and multiple national identity frameworks reference ISO 30107-3 – the standard iBeta tests against. iBeta is the primary NVLAP-accredited ISO 30107-3 testing lab, making its certification the de facto benchmark in identity verification procurement.
How long does iBeta PAD Level 2 certification remain valid?
iBeta certifications are version-specific – they don't auto-extend to software updates. After significant algorithm changes or new deployment environments, re-testing is required. Buyers should request the tested version number and certification date. A certificate referencing an older product version may not reflect current algorithm performance.
What APCER threshold does iBeta PAD Level 2 require?
Level 2 requires an Attack Presentation Classification Error Rate (APCER) below 5% – the system must correctly reject more than 95% of presentation attacks. The Bona Fide Presentation Classification Error Rate (BPCER) must stay below 10%, ensuring legitimate users are not excessively rejected during liveness checks. Both thresholds must be met simultaneously.