ISO 30107-3 and PAD levels, in plain English

Every liveness vendor waves a badge — “iBeta Level 2”, “ISO 30107-3”. Very few buyers can say what those actually measure, which makes the badges hard to compare and easy to over-read. This is the short, honest version: what the standard tests, what the numbers mean, and what a certification letter does and doesn’t prove.

What ISO/IEC 30107-3 actually is

It is a testing and reporting standard for presentation-attack detection — the discipline of telling a real, live face from an artefact. It doesn’t certify a product by itself; it defines a common language — the attack categories, the metrics, and the reporting rules — so an independent lab can evaluate a system and publish a result others can interpret. The standard spans face, fingerprint, iris, voice and palm; in identity verification we care about face.

PAI species: the catalogue of attacks

A Presentation Attack Instrument (PAI) is any object or characteristic used to spoof the camera — a printed photo, a phone playing a video, a silicone mask. A PAI species is a category of these. A meaningful test states which species it covered, because “we stop attacks” means nothing without saying which.

APCER and BPCER: the only two numbers that matter

APCER — the security miss

How often an attack is wrongly accepted as a live person. Lower is safer.

BPCER — the friction cost

How often a genuine person is wrongly rejected as an attack. Lower means fewer users blocked.

These trade off: you can drive attacks to zero by rejecting everyone, which is useless. So a liveness claim with only one figure — or none — tells you almost nothing. Always ask for both, at the same operating point.

iBeta Level 1, 2 and 3

iBeta is the lab most people mean by “certified”. Its levels differ by how hard — and expensive — the attacks are allowed to be:

  • Level 1: low-cost attacks (printed photos, screen replays), each artefact capped around $30.
  • Level 2: sophisticated artefacts — custom 3D masks and the like — capped around $300 and built by a specialist.
  • Level 3: a newer, tougher tier that tightens the bona-fide error bar further.

To “pass” Levels 1–2 a system must catch the attacks while keeping BPCER within iBeta’s 15% threshold — i.e. not wreck the experience for real users in the process.

What a letter does — and doesn’t — prove

A confirmation letter is genuinely useful: it is an independent, repeatable result against a named set of attacks. But read the fine print. It reflects the specific PAI species tested, at a point in time. It typically covers physical artefacts presented to a camera — not necessarily digital-injection attacks, where synthetic frames are fed past the camera entirely, which is where much of today’s fraud has moved. And a lab pass is not a promise of how the system behaves on your users, devices and lighting. Use it as a data point, not a guarantee.

What to ask a liveness vendor

  • Which iBeta level, and can I see the actual confirmation letter (not just a logo)?
  • What are your APCER and BPCER, at the same operating point?
  • Do you test injection / deepfake attacks, and how — not just physical artefacts?
  • Passive, active, or both — and how do you handle accessibility and drop-off?
  • How often is the model retrained as new attacks appear?
Where Zanyara standsZanyara’s liveness is designed to align with ISO/IEC 30107-3, and independent iBeta evaluation is on our roadmap — we do not hold a confirmation letter today and won’t imply one. See how our liveness & PAD works, including injection defence.
How Zanyara liveness worksActive vs passive

Frequently asked questions

What is ISO/IEC 30107-3?
ISO/IEC 30107-3 is the international standard for testing and reporting the performance of presentation-attack detection (PAD). It defines the categories of attack (“PAI species”), the error metrics (APCER and BPCER), and how a test must be run and reported so results from different systems can be compared on the same terms.
What do APCER and BPCER mean?
APCER (Attack Presentation Classification Error Rate) is how often an attack is wrongly accepted as a real person — the security miss. BPCER (Bona Fide Presentation Classification Error Rate) is how often a genuine person is wrongly rejected as an attack — the friction cost. They trade off against each other, so a single number without both is close to meaningless.
What is the difference between iBeta Level 1 and Level 2?
iBeta is the best-known lab that runs ISO/IEC 30107-3 evaluations. Level 1 tests low-cost attacks — printed photos, screen replays — with each artefact capped at roughly $30. Level 2 tests sophisticated artefacts such as custom 3D masks, capped at roughly $300, made by a specialist. A newer Level 3 raises the bar further. Passing means the system kept BPCER within iBeta’s threshold (15% for Levels 1–2) while catching the attacks.
Does an iBeta letter mean a system stops deepfakes?
Not necessarily. A confirmation letter reports performance against the specific physical PAI species tested at a point in time. Injection attacks and rapidly-evolving deepfakes may fall outside the artefacts a given evaluation used, and lab results don’t guarantee field performance on your users and devices. Treat a letter as a useful, verifiable data point — not a guarantee.

© 2026 Zanyara Ltd. All rights reserved.

Questions: hello@zanyara.com · Privacy: privacy@zanyara.com

We use analytics cookies to understand how visitors use Zanyara. Declining still lets you use the site — see our Privacy Policy.