International standards · Forensic process
ISO 21043 is the five-part Forensic sciences standard from ISO/TC 272, covering the forensic process from scene to courtroom: vocabulary, recognition and recording of items, analysis, interpretation, reporting. Parts 3, 4 and 5 were published in June 2025, completing the series. There is no ISO 21043 certificate, though Australia's NATA does accredit laboratories against Part 2.
This page covers what each of the five parts contains, why an ISO 21043 certificate does not exist while accreditation to Part 2 already does in one country, the scope carve-out that sends digital data recovery to ISO/IEC 27037, a clause-by-clause map from Part 2 to what capturing a web page as evidence actually involves, and where the standard needs a competent human that no software can replace.
By Radim Motycka · Last reviewed August 27, 2026 · Part titles, editions and publication dates verified against the ISO catalogue and the NIST OSAC standards register, accreditation status against A2LA and NATA
Most forensic standards cover one discipline: a method for DNA, a method for fingermarks, a method for digital acquisition. ISO 21043 does something different. It standardizes the process, the same way for every discipline, in the order the work actually happens. The introduction to Part 2 states the ambition directly: "This document is part of a series which, when completed, will include the different components of the forensic process from scene to courtroom." In June 2025 the series was completed.
| Part | Title | Edition | What it does |
|---|---|---|---|
| Part 1 | Vocabulary | 2nd ed., June 2025 replaces the 2018 first edition, then titled Terms and definitions |
Fixes the language of the other four parts. Every other part is normatively bound to it, so an argument about what a word means in Part 2 is settled here. The terms are also readable free of charge on the ISO Online Browsing Platform, which makes Part 1 the cheapest way to see how the series is put together. |
| Part 2 | Recognition, recording, collecting, transport and storage of items | 1st ed., August 2018 revision in committee draft |
The part that matters most outside a laboratory. Quality policies, competence, impartiality, examination strategy, recording, item handling and control, labelling, transport, storage, and a short reporting clause. Its stated purpose is to protect items from loss, degradation, contamination, and from the effects of handling on everything downstream. |
| Part 3 | Analysis | 1st ed., June 2025 | Safeguards the analysis of items of potential forensic value: methods, validation, and management of the analytical process, so that a result is reliable and repeatable rather than the product of one person's practice. |
| Part 4 | Interpretation | 1st ed., June 2025 | The step from observation to opinion: interpreting observations to reach opinions that answer the questions relevant to a decision in an investigation or in legal proceedings. Covers both investigative and evaluative interpretation, and it is the part least open to automation. |
| Part 5 | Reporting | 1st ed., June 2025 | Report content, case file review, issuance and control of reports including amendment, supplement and withdrawal, preliminary communications, and testimony. The target is a report that is accurate, clear, transparent, complete, unambiguous, impartial and suitable for its intended use. |
Part titles, edition numbers and publication dates as listed in the ISO catalogue and the NIST OSAC standards register, checked August 27, 2026. The series has also been adopted as European standards, which is why you will meet the parts as EN ISO 21043 published by DIN, BSI, UNE, AFNOR and other national bodies: EN ISO 21043-2:2020 for the 2018 part, EN ISO 21043-3, -4 and -5 dated 2025 for the rest.
Read the five titles in order, and you have the argument of the whole series: agree on words, protect the item, analyze it properly, be honest about what the analysis means, and write it down so someone else can check. Most reported failures of digital evidence trace back to one of those five points, usually the second or the fifth.
This is where marketing copy goes wrong most often, so it is worth being blunt. ISO 21043 carries no certification scheme. The American accreditation body A2LA puts the position in one sentence:
"Since ISO 21043 Parts 1-5 are not accreditation standards, forensic service providers cannot be accredited to them as stand-alone standards but can incorporate them into their quality management system."
A2LA, "Bridging the Gap: How ISO 21043 Elevates Forensic Lab Quality and Credibility"
What a provider does instead is fold the requirements into its quality management system and hold accreditation to the standards that carry it: ISO/IEC 17025 for testing and calibration laboratories, ISO/IEC 17020 for inspection bodies. NIST states the relationship in one line: ISO 21043 does not replace ISO/IEC 17025 or ISO/IEC 17020, it provides additional, specific requirements relevant to the forensic process.
NATA, Australia's national accreditation body, has gone further than anyone in naming the standard: it announced a first accreditation against ISO 21043-2 for PathWest Forensic Biology on March 11, 2024, and a second on December 10, 2025, when Victoria Police Forensics Services Department became "only the second facility in Australia to be successfully assessed against this International Standard."
It is tempting to call that an exception to A2LA's sentence. It is not. Look at what NATA's own accredited-organisation record for PathWest actually says: the accreditation is held under ISO/IEC 17025, and ISO 21043-2 appears as a statement inside the scope, that the facility "complies with the requirements of ISO 21043-2 ... (except 5.4 Health and Safety which is excluded)." That is exactly the mechanism A2LA describes, an accredited 17025 quality system with the ISO 21043 requirements built into it and assessed. Note also the exclusion: even the flagship example is not conformity to the whole of Part 2. Australia also has its own modified adoption, AS 21043.2:2024, which makes any clean "accredited to ISO 21043-2" phrasing harder still.
So the accurate phrasing is the simple one: there is no ISO 21043 certification scheme, and no accreditation body grants ISO 21043 accreditation on its own. What differs between countries is how visibly the standard is named inside a 17025 scope, not whether it can stand alone. NATA has separately said it expects the Australian standard AS 5388 parts 1 to 4 to be withdrawn once the ISO series is fully released; we have found no confirmation that this has happened.
Everything above is about a voluntary standard. There is one jurisdiction where the picture inverts, and it is the most useful fact on this page if you have cross-border exposure. The Forensic Science Regulator's statutory Code of Practice came into force on October 2, 2023 under the Forensic Science Regulator Act 2021. It binds anyone carrying on a forensic science activity in England and Wales, digital forensic activities included, and most of the listed activities require UKAS accreditation to ISO/IEC 17025. A provider without it must declare the non-compliance in the report. Note what even that does not do: the Crown Prosecution Service states that non-compliance with the Code "does not, of itself, render evidence unreliable or inadmissible." Admissibility and weight remain for the court, case by case.
Two consequences, both practical. First, there is no badge to buy: if a vendor says their product is ISO 21043 certified, they are describing something that does not exist, and accreditation is granted to a laboratory by a national accreditation body, never to a piece of software. Second, you do not need anyone's permission to use it. A small investigations firm, a law office or a compliance team can align its handling with the requirements today and say so accurately: we follow the process described in ISO 21043-2. That sentence is defensible. A certificate claim is not. Be ready for the obvious follow-up in cross-examination, though, which is who assessed that claim. If the answer is nobody, say so plainly rather than letting it be extracted.
Almost every article about ISO 21043 describes it as covering the forensic process for all disciplines and stops there. The scope of Part 2 contains a limit that changes how you use it for anything digital, and it is one sentence long:
"This document is not applicable to procedures for the recovery of data from digital storage media which is covered by ISO/IEC 27037. However, the storage medium itself can yield additional items of forensic value (e.g. fingerprints or DNA)."
ISO 21043-2:2018, Clause 1, Scope
Read carefully, that carve-out is narrower than people assume. It removes one procedure: recovering data from a storage medium. It does not remove digital work from the series. The quality clauses, the competence requirements, the recording obligations, the item handling and control clauses and the reporting clause all still apply to the process around any digital acquisition, and Parts 3, 4 and 5 apply to digital findings exactly as they apply to a fiber or a fingermark.
Now apply it to a live web page, which is the scenario that interests most readers of this page. Capturing a page that is currently published on the internet is not recovery of data from a digital storage medium. It is closer to what Part 2 calls recognition and recording: an item exists in a situational context, it may vanish, and you are documenting it before it changes. That puts a web capture squarely inside the part of ISO 21043 that people wrongly assume excludes it, while ISO/IEC 27037 still supplies the acquisition discipline of not altering what you take.
Imaging a laptop: ISO/IEC 27037 governs the acquisition, ISO 21043 governs the process wrapped around it and the report at the end.
Capturing a published web page, a social media post, a marketplace listing or a chat client open in a browser: on the better reading the carve-out does not reach it, because nothing is being recovered from a storage medium in your custody, and the recording and item handling requirements of Part 2 apply directly to what you do. ISO has not said so, and an opponent could argue the other way.
Certifying a file a client already sent you: the item entered your custody as a file, so what you can honestly record is when it reached you and that it has not changed since. Part 2 vocabulary keeps you accurate about the difference, which matters more than it sounds. Claiming a capture record for a file you did not capture is the fastest way to lose a witness.
This is the table the standard does not give you, because the standard is written for scenes and physical items. The left column is what ISO 21043-2:2018 requires. The middle column is what that requirement means when the item is a page on the internet. The right column is honest about who has to do it: a large part of this standard cannot be satisfied by any product, and it is worth knowing which part before you buy anything.
| Clause in ISO 21043-2:2018 | What it means for a web page | Who satisfies it |
|---|---|---|
| 5.1 Quality documented policies: document control, training, corrective action, monitoring, peer review, record control, roles, standard operating procedures, external providers |
A written procedure for how your office captures pages, who is allowed to do it, and what happens when a capture goes wrong. Two pages is enough for a small firm. Nothing in writing is not. | You |
| 5.5 Personnel competence shall include item handling, control, and chain of custody; competence shall be demonstrated and recorded |
The person pressing capture understands what the capture does and does not prove, and there is a record that they were trained. The standard names chain of custody as a competence, not a document. | You |
| 5.3 Impartiality information that could affect impartiality shall be recorded |
Capture what is there, including the parts that hurt your case, and do not crop the exhibit into an argument. A whole-page capture is easier to defend than a chosen region for exactly this reason. | You |
| 7.1 and 7.3 Examination systematic, impartial, planned and documented; a strategy including recording techniques to be utilized |
Decide before you capture: whole page or visible area, one page or a whole browsing session, with or without a video of the interaction. Then let the record show which was chosen. | Shared |
| 8 Recording items recorded in their situational context prior to any disturbance; records sufficient for another appropriately trained examiner to report accurately |
The page as it stood, plus its context: URL, verified time, server response headers, DNS answers, TLS details, domain registration, the HTML, the text layer, and a disclosure of every change made in order to photograph it. | Software |
| 9.1 to 9.4 Item handling, labelling control of the item, unique identification, protection from alteration |
A unique identifier for the capture, a SHA-256 hash of every file so any later alteration is detectable, and a signature over the list of hashes so the list itself cannot be edited quietly. | Software |
| 9.5 Transport and storage integrity maintained while the item moves and while it is stored |
The digital equivalent of a sealed bag is a hash plus a timestamp that predates any handling. An independent time anchor is what lets you prove the file existed in this exact form before it traveled. | Software |
| 10 Reporting expanded by Part 5: accurate, clear, transparent, complete, unambiguous, impartial, fit for purpose |
A document a reviewer can check without calling you, carrying the identifiers, the hashes, the times and the method, with observation kept separate from conclusion. | Shared |
Clause numbers and quoted requirements from ISO 21043-2:2018. The mapping to web evidence is ProofSnap's reading, not part of the standard, and ISO does not endorse it.
Count the right-hand column. Four of the eight requirement groups above are things software can produce, and four are things only the practitioner can. That ratio is the whole argument of this page. Buying a capture tool moves you halfway. The other half is a written procedure, a trained person, an impartial method, and a report you are willing to sign.
Clause 8 of Part 2 is short, and it is the clause that separates a capture record from a picture. Items are to be recorded in their situational context prior to any disturbance, recording continues throughout the examination, and the records have to be detailed enough that the examiner or another appropriately trained examiner could report accurately from them.
On a physical scene that means photograph before you touch. Online, the same instruction is harder to follow than it sounds, because a modern page cannot be photographed whole without touching it. A sticky header repeats down a stitched screenshot. A cookie wall covers the content. A recommendation feed loads new items forever as you scroll, so the page has no bottom. Every capture tool deals with this the same way: it changes the page. The difference between tools is whether they tell you.
Silent modification
The exhibit does not match the live page. Opposing counsel opens the URL, sees a cookie banner and a floating header that are missing from your screenshot, and asks the witness to explain the difference. The witness does not know, because nothing recorded it. The record has now created the doubt it was meant to remove.
Disclosed modification
The same difference exists, and the chain of custody names it: seven fixed elements hidden, six headers and one footer, one cookie overlay dismissed, animations frozen, each with the selector it applied to. The witness reads the line out. The difference is now part of the method rather than a hole in it.
This is why disclosure is not a weakness in an evidence package. Clause 8 does not require that nothing be disturbed, which would be impossible. It requires the record to be good enough that another trained examiner could report accurately from it, and an undisclosed change makes that test impossible to pass. Every layout change ProofSnap makes to fit a page into one image is written into chain_of_custody.json as its own logged operation, for the same reason a scene photographer notes that a door was opened.
Here is the part most standards explainers skip, and it is the part that decides cases. Conformity with a published standard is not a rule of admissibility in any jurisdiction. No reported decision has yet turned on ISO 21043, in any country. Where regulators have addressed the point head on they have said the same thing: the Crown Prosecution Service notes that non-compliance with the statutory Code "does not, of itself, render evidence unreliable or inadmissible." Standards conformity is material that goes to weight, and to whether your method survives cross-examination. It is not a key that opens the courtroom door.
In a US federal case the rule that does the work is one this page had no business omitting:
"Evidence describing a process or system and showing that it produces an accurate result."
Federal Rule of Evidence 901(b)(9), one of the illustrations of authentication
That is what a hash-chained, self-verifying capture package is for. It is also where the ISO material earns its keep in legal terms: a documented process aligned to a published standard is how you make the 901(b)(9) showing. Courts want a witness or a declaration explaining how the system works and why its output is accurate, not the exhibit standing on its own. That was the shape of the showing in United States v. Bansal (3d Cir. 2011) and in Specht v. Google (7th Cir. 2014).
Rules 902(13) and 902(14) let a record be self-authenticating, but only on a certification by a qualified person, meaning someone who could testify to the same facts, attesting to the hash comparison or equivalent verification, in a form that exposes the signer to penalty for a false statement. The proponent must also give the opposing party reasonable written notice and make the record available, under Rule 902(11). A software vendor cannot sign this for you. A template is a starting point; the qualification, the knowledge and the signature are yours.
Routine web capture is normally authenticated on a lay foundation under 901(b)(9), so Rule 702 and Daubert never enter. They bite the moment someone offers an opinion about the capture, for example that a page could not have been altered. The December 2023 amendment to Rule 702 made explicit that the proponent bears the burden by a preponderance and that the opinion must reflect a reliable application of the method to the facts. Know which side of that line you are on before you write the declaration.
Two traps that have nothing to do with authentication. First, hearsay: an impeccably authenticated capture of a defamatory post is still hearsay if you offer it for the truth of what the post says. Authentication and admissibility are different hurdles and clearing one does not clear the other. Second, and in your favour, the best-evidence objection people expect usually evaporates: under Rule 1001(d) a printout or other output readable by sight that accurately reflects the electronically stored information is an "original," and Rule 1003 admits duplicates on the same footing absent a genuine question of authenticity.
The four numbers people put in the same sentence answer four different questions. Confusing them is how a witness ends up claiming more than the document supports.
| Standard | Question it answers | Can you hold accreditation to it |
|---|---|---|
| ISO 21043 | Was the forensic process sound, from the scene to the testimony | No certification scheme exists. A2LA says no stand-alone accreditation; NATA accredits to Part 2 in Australia |
| ISO/IEC 27037 | Was the digital evidence identified, collected, acquired and preserved without being altered | No. It is a guideline, aimed at practitioners |
| ISO/IEC 17025 | Is this laboratory technically competent to produce valid results | Yes. This is where accreditation actually lives |
| eIDAS qualified timestamp | Did this exact data exist at this exact time, with a legal presumption behind the answer | Not you. The trust service provider is the one qualified, and it appears on the EU Trusted List |
The pairing that does the most work in practice is the last row against the first. ISO 21043 tells a court your process was sound. An eIDAS qualified timestamp from a Qualified Trust Service Provider on the EU Trusted List tells a court the data existed at a moment, with a legal presumption attached under Article 41 of Regulation (EU) 910/2014, and it does that without anyone taking your word for anything. ProofSnap issues its qualified timestamps through Disig a.s., a Qualified Trust Service Provider on the EU Trusted List. Standards describe a discipline. A timestamp is a fact.
Clause 8 asks for records sufficient for another appropriately trained examiner to report accurately. That is a test you can apply to any exhibit in front of you right now. On the left is what fails it. On the right is what the same capture also wrote, and every line is something a reviewer can check without contacting you or ProofSnap.
A bare screenshot
No identifier. No situational context. No time anyone can verify. Nothing that changes if a pixel is edited. Another examiner could report nothing from it beyond what it looks like.
The same capture, in manifest.json and chain_of_custody.json
evidence_id ps_e41dffe2-eda0-4652-bf04-76bfcd1f3ff4
url https://www.arabnews.com/node/2655769/middle-east
captured_at 2026-08-25T06:53:54.954Z
hash_algorithm SHA-256
files hashed 32 (17 of them page images)
screenshot.jpeg bf4117...fcb851
page.html ec8486...b1d9fe
metadata.json 76b387...7173a6
ntp_verification (Clause 8: when)
sources_agreed 3 consensus_offset 82 ms
dns_verification (Clause 8: where)
sources_queried 2 sources_agreed 2
all_ips_match true status verified
layout_modifications (Clause 8: disturbance, disclosed)
fixed_hidden 7 headers 6 footers 1
forensic_log (Clause 5.1: record control)
operations hash-chained 29 operation types defined
Real values from a ProofSnap capture of a news article taken on August 25, 2026, abridged and with hashes shortened. The full manifest lists all 32 files.
Clause 5.1 asks for record control. A log you can edit afterwards is not a controlled record, so each entry in forensic_log.json carries the hash of the previous entry and a running cumulative hash from a random genesis value bound to the evidence identifier. Removing or rewriting one operation breaks every hash after it, which is detectable by anyone holding the file. ProofSnap's chain of custody defines 29 operation types, from the first NTP time check to the final ZIP creation, and every operation that runs is written into that chain.
Part 5 asks for reports that are transparent and complete. A report a reviewer has to trust is neither. Every package ships verify.sh and verify.ps1, which recompute every hash and check the RSA signature offline with standard command line tools, plus a written guide for doing it by hand. Anyone challenging the exhibit can test it themselves, which is the difference between a claim and a check. The free Trust Verifier does the same thing in a browser with no account.
Almost everyone reading a page about ISO 21043 is in one of three positions, and the useful next step is different for each.
Accredited laboratory
ISO 21043 is a gap analysis against your existing system, not a new certificate to chase. Parts 4 and 5 are where the effort goes, because interpretation and reporting are where most laboratories find their documented practice is thinner than their technical practice. For web material specifically, what you need from a tool is a record your own reviewers can check without you vouching for the vendor.
Investigator or law firm
And you do not need to be. Use Part 2 as a checklist: a written capture procedure, a named trained person, capture before you disturb, disclose what you changed, keep the item's integrity provable, report so a stranger could follow. Then say accurately that your handling follows the process described in ISO 21043-2. See the investigator and OSINT page for how that reads in a file.
In-house or compliance
A supplier's published terms on a date, a competitor's claim before it was edited, a portal notice before it expired. The forensic vocabulary still helps: the value of what you keep is decided by whether it carries its own context, and a folder of screenshots does not. This is the cheapest half of the standard to adopt and the one that pays back first.
Every plan produces the full record described above; the differences are volume, the Bitcoin anchor, the eIDAS qualified timestamp and PDF branding. Plans start at $4.99 for a one-off SnapPack, and the seven-day trial requires a credit card at sign-up. The full breakdown is on the ProofSnap home page.
ISO 21043 is a five-part international standard series called Forensic sciences, developed by ISO Technical Committee 272. It covers the forensic process end to end, from a scene through analysis and interpretation to the report and the testimony given about it. Part 1 is vocabulary, Part 2 covers recognition, recording, collecting, transport and storage of items, Part 3 covers analysis, Part 4 covers interpretation and Part 5 covers reporting. Parts 1 and 2 appeared in 2018; Parts 3, 4 and 5 were published in June 2025 together with a second edition of Part 1, which completed the series. It is the first global standard that treats the whole forensic process as one chain rather than standardizing a single discipline.
No, there is no ISO 21043 certification scheme anywhere. A2LA states the position directly: "Since ISO 21043 Parts 1-5 are not accreditation standards, forensic service providers cannot be accredited to them as stand-alone standards but can incorporate them into their quality management system." One jurisdiction is further ahead than that blanket wording suggests: NATA, Australia's national accreditation body, has granted accreditation against ISO 21043-2, first to PathWest Forensic Biology, announced on March 11, 2024, and then to Victoria Police Forensics Services Department, announced on December 10, 2025, as only the second facility in Australia assessed against the standard. Everywhere else a provider holds ISO/IEC 17025 or ISO/IEC 17020 and builds the ISO 21043 requirements into that system, which is what NIST means when it says ISO 21043 does not replace those standards but adds forensic-specific requirements to them. In every case accreditation is granted to a laboratory by a national accreditation body, never to a piece of software, so a vendor claiming an ISO 21043-certified product is describing something that does not exist.
Partly, and the boundary is written into the standard. The scope of ISO 21043-2:2018 states that the document is not applicable to procedures for the recovery of data from digital storage media, which is covered by ISO/IEC 27037, while noting that the storage medium itself can still yield items of forensic value such as fingerprints or DNA. So imaging a hard drive is ISO/IEC 27037 territory. The quality, competence, recording, item handling and reporting requirements in ISO 21043 still apply to the process wrapped around that acquisition, and Parts 4 and 5 on interpretation and reporting apply to digital findings the same way they apply to any other.
No, and be careful with anyone who says their tool does. Most of ISO 21043 is about the organization, not the artifact: documented policies, defined competence, impartiality, corrective action, peer review, control of records. No software supplies those. What software can supply is the evidentiary record the standard expects to exist: the item captured in its situational context, an identifier, a verified time, a hash of every file, a documented process, disclosure of every change made in order to capture, and a report another examiner could read and check. ProofSnap produces that record automatically for a web page. The parts that require a competent human, an impartial method and a signature stay with you.
Yes. ISO 21043-2:2018 remains the current published edition, but a revision is in the committee draft stage at ISO/TC 272 and is retitled: Part 2, General requirements for the forensic process, and the recovery and management of items. The new title tells you where the series is heading, folding general process requirements into the same part as item recovery and management. Because a committee draft can still change substantially before publication, cite the 2018 edition in current work and watch the draft rather than relying on it.
That is the whole of Clause 8 in six words, and it is the one requirement you cannot satisfy retroactively. A capture takes one click and writes the context, the time, the hashes and every change it made, so a reviewer can check every claim in it without ever speaking to you.
SnapPack from $4.99 for 10 captures, one-time, no auto-renewal. The 7-day trial requires a credit card at sign-up.