Skip to content

NIST CFTT

Definition

The National Institute of Standards and Technology Computer Forensics Tool Testing programme. It publishes independent test reports for digital forensic tools, including mobile and network platforms. CFTT reports document supported features, known limitations, and error conditions for specific tool versions.

Full name
NIST Computer Forensics Tool Testing programme
Output
Independent test reports for forensic tools
Scope
Includes mobile and network forensic platforms
Report content
Supported features, limitations, error conditions

Common questions

Why do forensic labs rely on NIST CFTT reports rather than trusting vendor claims?+

CFTT tests tools against defined criteria and known reference data independently of the vendor, so its reports document actual observed behaviour, including limitations and error conditions the vendor's documentation may not mention. This independent verification supports the tool validation an examiner needs to defend a method's reliability in court.

Does a CFTT test result apply to every version of a tool?+

No. Reports are tied to specific tool versions and configurations tested at a point in time, so a later software update can change behaviour in ways the existing report does not cover. Labs track which version they used in casework against the matching report, and re-verify or seek updated reports after significant tool updates.

What should an examiner do if no CFTT report exists for the tool they are using?+

Where CFTT has not tested a specific tool, examiners typically perform their own internal validation using known reference datasets and document the results, following the same principle of demonstrating known error rates and limitations that CFTT reports provide. This keeps the tool's use defensible even without an external published report.

Related terms

Daubert Standard
The US federal evidentiary standard (Daubert v. Merrell Dow Pharmaceuticals, 1993) requiring that expert testimony be based on scientifically valid methods with...
ISO/IEC 17025
The international standard for testing and calibration laboratories, published jointly by the International Organization for Standardization and the International Electrotechnical Commission. It...
C2PA
Coalition for Content Provenance and Authenticity. A cross-industry group that has published an open technical specification for embedding cryptographically signed provenance manifests...
Device Profile
A vendor-maintained database entry describing how to communicate with a specific make, model, and firmware version of a mobile device. The profile...
Distribution Shift
In machine learning, distribution shift occurs when the statistical characteristics of data the model encounters in deployment differ from those of the...
Frye Standard
The US legal test for admissibility of scientific evidence, originating from Frye v. United States (1923), which required that a technique be...
Known Error Rate
One of the four Daubert factors. For a forensic tool, the error rate is determined by testing against reference datasets where the...
Logical Extraction
NIST SP 800-101 R1 Level 2 acquisition. Uses the OS-exposed backup APIs (Android ADB backup, iOS iTunes/Finder backup, MTP for media) to...
PCAP File
A packet capture file storing raw network frames in the libpcap format. PCAP files are the standard exchange format between network forensic...
Physical Extraction
An acquisition method that reads the raw storage medium, producing a bit-for-bit image from which allocated and deleted data can both be...
SWGDE
Scientific Working Group for Digital Evidence. A US multi-agency body that publishes consensus best-practice documents for digital forensic disciplines, including image authentication,...
Validation Test Plan
A structured document that defines the test devices, functions to be tested, expected outcomes, and pass/fail criteria before a new tool is...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.