In short
- ISO/IEC 30107-3 does not declare a system «secure» — it defines how to measure attack resistance.
- Two metrics carry the weight: APCER (attacks that got through) and BPCER (real users wrongly rejected).
- Improving one metric degrades the other, so the result is only ever read as a pair.
Conversations about certification usually start with one question: is the system secure or not. ISO/IEC 30107-3 does not answer that. It offers something else — a shared language for measuring resistance to attacks.
What the standard actually measures
The standard defines how a presentation attack detection mechanism is tested: which artefacts are prepared, how many times they are presented, and how the result is computed.
- Attack artefact types: printed photo, screen, mask, silicone fingerprint and more.
- Test conditions: lighting, distance, device camera and number of attempts.
- Result: a separate figure per artefact type, rather than one averaged number.
APCER and BPCER
APCER is the share of attack attempts that fooled the system. BPCER is the share of genuine users who were wrongly rejected. The first measures security, the second measures user experience.
APCER
Attacks that passed
BPCER
Genuine users rejected
Level 1–2
Test difficulty levels
30107-3
Standard number
One number is easy to boast about. The standard forces you to show a pair — and that is where reality becomes visible.
What changes in practice
Once a system has been tested against the standard, thresholds can no longer be nudged by feel: every change shows up in both metrics at once. That helps during integration too — a partner picks the threshold for their flow from numbers, not from intuition.