The spine of the discipline: what a competent examiner is expected to have done, written down by bodies a court will recognise. Read these first, and check for a newer revision before you cite one.
Scientific Working Group on Digital Evidence · Version 5.0, published 2026-07-09 · 2026 · SWGDE 17-F-001-5.0
SWGDE's guidance on analysing historical call detail records and cell site data to reason about where a handset was, and on the limits of that reasoning. The version verified here is 17-F-001-5.0 dated 9 July 2026; it has moved through four earlier versions since 2023, including a retitling from Recommendations to Best Practices.
Does not cover: It addresses historical records, not live tracking, and not the separate question of reverse location demands — SWGDE handles those in 22-F-004 and 23-F-002. It gives no legal analysis of the process required to obtain the records, and its companion documents on timing advance records and RF propagation surveys cover techniques it does not.
Working examinerLawyers and courts
Forensic Science Regulator (England and Wales) · Version 2, published 5 June 2025; came into force 2 October 2025 · 2025
The statutory code of practice the Forensic Science Regulator is required to publish under the Forensic Science Regulator Act 2021, setting quality standard requirements for forensic science activities relating to the investigation of crime in England and Wales. Version 2 replaced version 1 and came into force on 2 October 2025.
Does not cover: It applies only to England and Wales and only to activities designated as forensic science activities under the 2021 Act — it says nothing about civil, regulatory or internal corporate investigations. It sets requirements rather than methods: the technical how-to lives in the Regulator's separate guidance such as FSR-G-218. The earlier digital-specific appendix FSR-C-107 is marked obsolete on gov.uk.
Working examinerLawyers and courts
Ramaswamy Chandramouli, Eric Hibbard · National Institute of Standards and Technology · Revision 2, September 2025 · 2025 · NIST SP 800-88 Rev. 2
NIST's guidance on clearing, purging and destroying data on storage media, including media-specific techniques and verification. Revision 2 was published in September 2025 and supersedes Revision 1 (2014), which NIST withdrew on 26 September 2025.
Does not cover: It is a sanitization standard, not a recovery manual: it will not tell you how to carve or reconstruct data from partially wiped media, and it makes no claims about what a given commercial wiping tool actually does. Anyone citing Revision 1 after September 2025 is citing a withdrawn document.
Working examinerLawyers and courts
International Organization for Standardization · Edition 1, published 2025-06 · 2025 · ISO 21043-4:2025
A 14-page international standard on the interpretation of forensic findings, published in June 2025 as part of the ISO 21043 forensic sciences series. Parts 1 (vocabulary, 2025), 3 (analysis, 2025) and 5 (reporting, 2025) are also published; part 2 is being revised, with ISO/DIS 21043-2 at DIS stage as at September 2026.
Does not cover: It is a requirements document, not a tutorial: it will not teach you Bayesian reasoning or likelihood ratios, and it contains no digital-forensics worked examples. For those, the ENFSI evaluative reporting guideline is the practical companion.
Working examinerLawyers and courtsAdvanced
International Organization for Standardization · Edition 1, published 2025-06 · 2025 · ISO 21043-5:2025
A 10-page international standard specifying requirements for forensic reports and for the communication of findings, published June 2025 as part of the ISO 21043 series.
Does not cover: It does not satisfy any particular court's rules — in England and Wales you still need CrimPR Part 19 and the Forensic Science Regulator's FSR-G-200, and in US federal practice FRCP 26 and FRE 702. It also gives no digital-specific reporting content such as how to present hash verification or extraction limitations.
Working examinerLawyers and courts
Federal Judicial Center / National Academies of Sciences, Engineering, and Medicine · Fourth edition, published December 31, 2025 (the two volumes carry a March 2026 date) · 2025
The judiciary's own reference work on scientific and technical evidence, produced jointly by the Federal Judicial Center and the National Academies, made up of reference guides written by scientists and judges on individual fields plus chapters on the judge's gatekeeping role. The fourth edition rewrites every guide carried over from 2011 and adds new guides on eyewitness identification, computer science, and artificial intelligence.
Does not cover: It contains no reference guide on digital forensic examination as a discipline, so there is nothing in it on imaging, hashing, mobile extraction, or tool validation as practised. It is US federal, it states no state's law, and nothing in it binds any court.
Lawyers and courtsWorking examiner
Scientific Working Group on Digital Evidence · Version 2.1, published 2025-08-05 · 2025 · SWGDE 17-F-002-2.1
SWGDE's guidance on acquiring data from computers and computer storage, including write blocking, live versus dead acquisition, verification and the handling of encrypted and self-encrypting media. The version verified here is 17-F-002-2.1 dated 5 August 2025.
Does not cover: It is scoped to computers and computer storage: mobile devices are covered by separate SWGDE documents (18-F-003 and 20-F-005), and cloud sources by 23-F-004. It does not evaluate or endorse specific tools, and SWGDE disclaims any warranty as to the guidance.
Working examiner
Scientific Working Group on Digital Evidence · Version 2.0, published 2025-11-20 · 2025 · SWGDE 18-F-002-2.0
SWGDE's core on-scene collection document, covering preparation, data integrity and security, acquisition approaches, hashing and documentation. The version verified here is 18-F-002-2.0 dated 20 November 2025.
Does not cover: It is a collection document — it does not cover examination, analysis or interpretation, and it is silent on legal authority for the seizure. SWGDE's own cover page warns there is no warranty as to the work product and that readers must verify on swgde.org that they are using the current version.
Working examiner
Scientific Working Group on Digital Evidence · Version 2.0, published 2025-08-21 · 2025 · SWGDE 18-F-003-2.0
SWGDE's guidance on the front half of mobile device work: isolating and preserving a seized handset, handling power and network state, and choosing among logical, file system and physical acquisition routes. The version verified here is 18-F-003-2.0 dated 21 August 2025.
Does not cover: It does not cover analysis or interpretation of extracted data, nor does it address the legal authority for compelling passcodes or biometrics. It cannot keep pace with every handset and OS release, so device-specific limitations still have to be established and documented case by case.
Working examiner
The Sedona Conference · Post-public-comment version, October 2025 · 2025
A consensus commentary on when mobile device data is within the scope of civil discovery and how to collect and produce it proportionately, covering possession, custody or control over personal devices, targeted versus full extraction, and the form of production for message threads.
Does not cover: It is not binding and its legal analysis is US civil discovery only, with no coverage of criminal seizure or consent. It is not a technical guide: it does not evaluate extraction tools, address locked or encrypted devices as an engineering problem, or tell you how to validate an extraction. The PDF requires a free Sedona Conference account.
Lawyers and courtsWorking examiner
The Sedona Conference · Sixth edition, December 2025 (fifth edition February 2020, published in The Sedona Conference Journal, Volume 21) · 2025
A controlled vocabulary for ediscovery and digital information management, defining the terms that appear in ESI protocols, expert reports, and court orders.
Does not cover: It defines terms; it states no legal standard and resolves no dispute, and its definitions are not authoritative on any technical discipline — a forensic examiner should not treat them as substitutes for the vocabulary of a standards body. The PDF requires a free Sedona Conference account.
New to the fieldLawyers and courtsWorking examiner
Martin Herman, Michaela Iorga, Ahsen Michael Salim, Robert Jackson, Mark Hurst, Ross Leo, Anand Kumar Mishra, Nancy Landreville, Yien Wang · National Institute of Standards and Technology · July 2024 (final; initial public draft February 2023) · 2024 · NIST SP 800-201
The successor work to NISTIR 8006: a forensic reference architecture that maps the challenges onto the NIST cloud computing reference architecture and identifies where forensic readiness has to be designed in, with mitigation strategies tied to specific architectural elements. It includes a methodology plus a preliminary worked implementation.
Does not cover: It is architecture, not procedure: there are no step-by-step acquisition instructions, no AWS/Azure/GCP console walkthroughs and no tool guidance, and NIST explicitly expects organisations to adapt it rather than apply it as-is. It also does not address the legal process for compelling provider-held data.
Advanced
Scientific Working Group on Digital Evidence · Version 1.1, published 2024-02-02 · 2024 · SWGDE 23-Q-001-1.1
SWGDE's guidance for examiners who have to present digital evidence in court or other proceedings, covering preparation, exhibits, scope of testimony and staying within demonstrated competence. The version verified here is 23-Q-001-1.1 dated 2 February 2024.
Does not cover: It is written for US proceedings and does not address the admissibility tests themselves — no Daubert or Frye analysis, and nothing on English or EU procedure. It is guidance on conduct, not a substitute for witness familiarisation by instructing counsel.
Working examinerLawyers and courts
Scientific Working Group on Digital Evidence · Version 2.1, published 2024-03-07 · 2024 · SWGDE 18-Q-001-2.1
SWGDE's statement of the minimum a laboratory must do to test a tool before using it in casework, including what to record about the tool, the test data and the outcome. The version verified here is 18-Q-001-2.1 dated 7 March 2024.
Does not cover: It sets a minimum, not a full validation methodology, and it supplies no test datasets or reference images — you have to source those yourself. It does not certify or approve any tool, and it does not replace an accreditation body's assessment of your methods.
Working examinerAdvanced
United States Courts (rule text as printed by the Committee on the Judiciary, U.S. House of Representatives) · Amended April 24, 2023, effective December 1, 2023; credit line in the official print reads "As amended Apr. 17, 2000, eff. Dec. 1, 2000; Apr. 26, 2011, eff. Dec. 1, 2011; Apr. 24, 2023, eff. Dec. 1, 2023." · 2023
The federal admissibility rule for expert testimony. The 2023 amendment moved the burden into the rule text — the proponent must demonstrate to the court that it is more likely than not that each of the four requirements is met — and rewrote subsection (d) so that the opinion must reflect a reliable application of the principles and methods to the facts of the case.
Does not cover: The rule names no methods and endorses no discipline, so it does not tell you whether any particular forensic technique is reliable. It is federal; states that follow older Daubert or Frye formulations were not changed by it.
Lawyers and courtsWorking examinerAdvanced
Eran Salfati, Michael Pease · National Institute of Standards and Technology · NISTIR 8428, 22 June 2022 · 2022 · NISTIR 8428
An incident-handling framework for operational technology environments, extending conventional DFIR with event-escalation-based response, OT-specific forensic techniques, and the preparation needed to stand up an OT incident response team. Published as a NIST Interagency Report with DOI 10.6028/NIST.IR.8428.
Does not cover: It is a framework rather than a protocol-level manual: no PLC memory acquisition procedures, no vendor-specific controller instructions, and no treatment of Modbus/DNP3/S7 artefact parsing. It also does not cover safety-instrumented-system engineering or regulatory reporting duties.
Advanced
James R. Lyle, Barbara Guttman, John Butler, Kelly Sauerwein, Christina Reed, Corrine Lloyd · National Institute of Standards and Technology · NISTIR 8354, 21 November 2022 · 2022 · NISTIR 8354
NIST's scientific foundation review of digital forensics, examining the peer-reviewed literature, academic material and practitioner guidance behind digital investigation techniques. It concludes the techniques rest on established computer science methods and are reliable when properly applied, while naming specific limits.
Does not cover: It is a literature and foundations review, not a procedure or validation manual: it prescribes no test method, sets no error rates for named tools, and does not tell you how to validate your own lab's workflow. Note the number carefully — this is NISTIR 8354, and it is frequently miscited.
AdvancedLawyers and courts
The Sedona Conference · August 2021; published in The Sedona Conference Journal, Volume 22 (2021) · 2021
A consensus commentary on auto-deleting and disappearing-message applications: whether adopting them is defensible, what happens to the preservation duty when a trigger occurs, and how Rule 37(e) applies when messages are gone by design.
Does not cover: It is not binding, and courts have since gone various ways on the same facts, so it cannot be treated as settled law. It offers no technical method for recovering or proving deletion in any specific application. The PDF requires a free Sedona Conference account.
Lawyers and courtsWorking examiner
International Organization for Standardization / International Electrotechnical Commission · Edition 2, published 2020-01; a systematic review closed 2025-06-05 · 2020 · ISO/IEC 27050-3:2020
A 27-page code of practice setting out requirements and guidance for each ediscovery activity, from initiating a matter and issuing preservation instructions through to producing ESI. It is the operational part of the ISO/IEC 27050 series.
Does not cover: It is not legal advice and takes no position on privilege, disclosure obligations or sanctions, all of which are jurisdictional. It also predates current generative-AI review workflows. Confirm on iso.org whether the 2025 systematic review has produced a revision before citing it.
Lawyers and courtsWorking examiner
Martin Herman, Michaela Iorga, Ahsen Michael Salim, Robert Jackson, Mark Hurst, Ross Leo, Richard Lee, Nancy Landreville, Anand Kumar Mishra, Yien Wang, Rodrigo Sardinas · National Institute of Standards and Technology · NISTIR 8006, final, August 2020 · 2020 · NISTIR 8006
A catalogue produced by the NIST Cloud Computing Forensic Science Working Group that aggregates and categorises the forensic challenges of investigating incidents in cloud ecosystems — multi-tenancy, data location, provider dependency, chain of custody across parties, and the rest. The draft circulated from 2014; the final was issued in August 2020.
Does not cover: It only states challenges; it deliberately offers no solutions, no acquisition procedures and no provider-specific guidance, and it names no APIs or tools. For the architectural response, read NIST SP 800-201 instead.
Working examinerLawyers and courts
The Sedona Conference · Second edition, October 2020; published in The Sedona Conference Journal, Volume 22 (2021). The first edition dates from March 2008 · 2020
A consensus commentary on getting electronically stored information into evidence — authentication, hearsay, best evidence, and the certification routes — rewritten for the second edition to take account of Rules 902(13) and 902(14).
Does not cover: It is not binding and no court has adopted it; it is US-focused and does not address criminal admissibility in any depth. It explains the legal framework, not how to acquire or examine the evidence. The PDF requires a free Sedona Conference account.
Lawyers and courtsWorking examiner
United States Courts (rule text as printed by the Committee on the Judiciary, U.S. House of Representatives) · Both subsections added by the amendment of April 27, 2017, effective December 1, 2017; text verified against the official print current to December 1, 2024 · 2017
Two subsections of Rule 902 that let a party authenticate electronic evidence by written certification instead of live testimony: 902(13) covers a record generated by an electronic process or system that produces an accurate result, and 902(14) covers data copied from an electronic device, storage medium, or file when authenticated by a process of digital identification. Both borrow the certification and pretrial notice machinery of Rule 902(11).
Does not cover: Self-authentication settles authenticity only; it does not make the evidence relevant, non-hearsay, or admissible, and an opponent can still attack the underlying process. The rules are federal, and state adoption varies.
Lawyers and courtsWorking examiner
International Organization for Standardization / International Electrotechnical Commission · Edition 3, published 2017-11; reviewed and confirmed 2023 · 2017 · ISO/IEC 17025:2017
The 30-page accreditation standard against which forensic laboratories, including digital forensics units, are assessed for technical competence, impartiality and consistent operation. The third edition (2017) replaced the 2005 edition and was confirmed on systematic review in 2023.
Does not cover: It is discipline-neutral — there is not a word in it about digital evidence, imaging, hashing or mobile extraction. Accreditation to it says the management system and the declared methods were assessed competent; it makes no claim about any individual case, and scope statements are often narrower than lawyers assume.
Working examinerLawyers and courts
The Sedona Conference · Third edition, October 2017 · 2017
Fourteen consensus principles on producing electronically stored information in civil litigation, with commentary, revised to reflect the 2015 amendments to the Federal Rules of Civil Procedure. Courts cite it more often than any other non-binding ediscovery text.
Does not cover: It is consensus guidance, not law, and binds nobody; it addresses civil document production, not criminal discovery or forensic examination technique. The free PDF requires a free Sedona Conference account.
Lawyers and courtsWorking examiner
European Network of Forensic Science Institutes · Version 01, November 2015 · 2015 · ENFSI-BPM-FIT-01
A 65-page manual from ENFSI's Forensic Information Technology working group covering personnel, equipment, accommodation, peer review, examination protocols, validation and uncertainty of measurement, proficiency testing, handling items, case assessment and prioritisation. It is one of ten ENFSI best practice manuals issued in November 2015 under the EU-funded TEFSBPM project.
Does not cover: It is version 01 from November 2015 and ENFSI has not published a later version of this manual, so it predates current mobile, cloud and full-disk-encryption realities; ENFSI's own cover material directs readers to check its website for updates. It is a laboratory practice manual, not a technique-by-technique procedure set.
Working examiner
European Network of Forensic Science Institutes · Approved version 3.0; foreword dated 8 March 2015 · 2015
The output of ENFSI's STEOFRAE project (Strengthening the Evaluation of Forensic Results across Europe): a guideline on evaluating findings against competing propositions and reporting the strength of that evaluation, with an audit template, an implementation roadmap and nine worked case examples.
Does not cover: The worked examples are drawn mainly from DNA, glass, footwear, speaker recognition and gunshot residue; there is no computer or mobile forensics example, so the transfer to digital evidence is left to the reader. It is a guideline for reporting scientists, not a court rule, and it is dated 2015.
Working examinerLawyers and courtsAdvanced
United States Courts · Replaced in full by the amendment effective December 1, 2015 · 2015
The federal sanctions rule for lost ESI. It applies only where information that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it and it cannot be restored or replaced through additional discovery, and it reserves the severe measures — adverse inference, dismissal, default — for a finding that the party acted with intent to deprive another party of the information's use.
Does not cover: It governs civil cases in federal court only, says nothing about criminal matters or state-court practice, and does not define what "reasonable steps" are in any concrete system. Nothing in it addresses the duty to preserve itself, which comes from case law.
Lawyers and courtsWorking examiner
International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2015-06; reviewed and confirmed 2021; a further systematic review closed 2026-09-03 · 2015 · ISO/IEC 27041:2015
An 18-page standard on showing that an investigative method is fit for purpose: capturing functional and non-functional requirements, describing the method, and producing evidence that the implementation satisfies those requirements. It explicitly addresses how vendor and third-party testing can be folded into your own assurance argument.
Does not cover: It is guidance on the shape of a validation argument, not a validation protocol — there are no test datasets, no pass/fail criteria and no worked examples. At 18 pages it will not substitute for a discipline-specific validation methodology.
Working examinerAdvanced
International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2015-06; reviewed and confirmed 2021; a further systematic review closed 2026-09-03 · 2015 · ISO/IEC 27042:2015
A 14-page standard that picks up where ISO/IEC 27037 stops, covering the analysis and interpretation of potential digital evidence and the competence and proportionality considerations that go with them.
Does not cover: It is very short and stays at the level of principles: no file system, mobile or cloud specifics, no statistical framework for evaluating findings, and no report template. For evaluative interpretation with likelihood ratios, ISO 21043-4 and the ENFSI evaluative reporting guideline are the substantive documents.
Working examinerLawyers and courts
International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2015-03; reviewed and confirmed 2020; a further systematic review closed 2025-12-03 · 2015 · ISO/IEC 27043:2015
A 30-page standard setting out an idealised, process-class model for investigating incidents involving digital evidence, from readiness through initialisation, acquisition and investigation to reporting. It is the umbrella document that 27037, 27041 and 27042 sit under.
Does not cover: It is deliberately abstract: no technical procedures, no tooling, and no legal or jurisdictional content. It also does not cover incident management itself — that is the ISO/IEC 27035 series (parts 1:2023 and 2:2023, part 3:2020 and part 4:2024, all published as at September 2026).
Working examiner
Richard Ayers, Sam Brothers, Wayne Jansen · National Institute of Standards and Technology · Revision 1, May 2014 · 2014 · NIST SP 800-101 Rev. 1
NIST's guidance on seizing, preserving, acquiring and examining mobile phones and their associated media, including the acquisition-level model (manual, logical, physical, chip-off, JTAG) that practitioners still use as shared vocabulary. It supersedes the 2007 first edition of SP 800-101.
Does not cover: It is still the current NIST revision but is now over a decade old: it does not address Android file-based encryption, iOS Secure Enclave and Data Protection classes, modern checkm8/bootloader exploits, cloud-side account acquisition or the current commercial extraction tools. Do not cite its device coverage or tool capability claims as present-day fact.
Working examiner
International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2012-10; reviewed and confirmed 2018; a further systematic review closed 2023-12-03 · 2012 · ISO/IEC 27037:2012
A 38-page international standard covering the first four handling activities for potential digital evidence: identification, collection, acquisition and preservation. It names the device classes in scope, including computer storage media, mobile phones, memory cards, navigation systems, still and video cameras including CCTV, and TCP/IP networks.
Does not cover: It stops at preservation — analysis, interpretation and reporting are out of scope and are handled by ISO/IEC 27042. It also sets no competence or accreditation requirements and does not tell you which tool to use. ISO's page shows it under systematic review, so check iso.org for a newer edition before citing it as current.
Working examinerLawyers and courts
National Institute of Justice, U.S. Department of Justice · November 2009 · 2009 · NCJ 227050
A pocket flipbook companion to NIJ's first responder guide, condensing device types, scene securing, documentation, collection and packaging into an on-scene quick reference, with digital evidence considerations by crime category.
Does not cover: By design it is abbreviated, with no reasoning, no examination guidance and no legal analysis; it cannot substitute for the full second-edition guide. It dates from 2009 and reflects the device landscape of that time.
New to the field
Computer Crime and Intellectual Property Section, Criminal Division, U.S. Department of Justice · 2009 manual, still the version published on the CCIPS documents page · 2009
The Justice Department's own manual on the Fourth Amendment and statutory rules governing searches of computers and the acquisition of electronic evidence, including warrant drafting, plain view, consent, and the Stored Communications Act and Pen/Trap provisions.
Does not cover: It is seventeen years old and predates Riley v. California, Carpenter v. United States, and the CLOUD Act, so substantial parts of its Fourth Amendment and stored-data analysis are superseded — nothing in it should be cited without checking current law. It is federal criminal procedure only, and it is not a forensic examination manual.
Lawyers and courtsWorking examiner
National Institute of Justice, U.S. Department of Justice · Second edition, April 2008 · 2008 · NCJ 219941
NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.
Does not cover: It stops at the lab door: no examination, analysis or interpretation, and no legal authority analysis for the search or seizure itself. Being a 2008 second edition, it predates smartphone-dominant scenes, cloud accounts, IoT devices and live-encryption decisions, so its device inventory is dated.
New to the field
The Sedona Conference · July 2008; reprinted in The Sedona Conference Journal, Volume 10 Supplement · 2008
A short statement, endorsed by a large number of federal and state judges, that discovery is a non-adversarial exchange and that counsel have an obligation to cooperate on process even while contesting the merits. It remains a stable, frequently cited citation in discovery opinions.
Does not cover: It is aspirational: it creates no duty, provides no remedy, and does not tell you what cooperation requires in any concrete dispute. It is a US document with no application outside that system.
Lawyers and courts
National Institute of Justice, U.S. Department of Justice · January 2007 · 2007 · NCJ 211314
An 81-page NIJ guide on the legal handling of digital evidence: search and seizure issues including the Fourth Amendment, the Electronic Communications Privacy Act and the Privacy Protection Act; maintaining evidence integrity; pretrial preparation including authentication and hearsay; courtroom presentation and expert testimony; and a chapter on child pornography cases. Appendices include consent forms and evidence return stipulations.
Does not cover: It is US criminal practice and is written from the prosecution side; it gives no civil, eDiscovery or non-US guidance and no defence perspective. Written in 2007, it predates two decades of case law on cell-site data, device searches at the border, warrant particularity for digital devices and provider-held cloud data — treat every legal proposition in it as needing a current check.
Lawyers and courts
Karen Kent, Suzanne Chevalier, Tim Grance, Hung Dang · National Institute of Standards and Technology · August 2006 (final, published 1 September 2006) · 2006 · NIST SP 800-86
A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.
Does not cover: It has not been revised since 2006, so it predates full-disk encryption as a default, cloud-hosted workloads, smartphones, SSD trim behaviour and modern Windows artefacts; the tool and OS specifics are obsolete even though the process model is not. It gives no legal analysis of admissibility and no US or foreign procedural law.
New to the fieldWorking examiner
National Institute of Justice, U.S. Department of Justice · April 2004 · 2004 · NCJ 199408
An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.
Does not cover: NIJ states the recommendations are not legal mandates, are not the only correct courses of action, and may not be feasible in all circumstances. Technically it is a 2004 document: no mobile devices, no cloud, no encryption-at-rest defaults, and none of the current tooling.
New to the fieldWorking examiner
Supreme Court of the United States · Decided March 23, 1999 · 1999 · 526 U.S. 137
The decision extending the Daubert gatekeeping obligation to all expert testimony under Rule 702, including technical and other specialized knowledge, and holding that the Daubert considerations are flexible rather than mandatory, with the trial court's choices reviewed for abuse of discretion.
Does not cover: It says nothing about what makes any specific technical method reliable and gives no guidance on computer or mobile evidence. Abuse-of-discretion review means it produces few reversals, so it offers little predictive help on close calls.
Lawyers and courtsWorking examiner
Supreme Court of the United States · Decided June 28, 1993 · 1993 · 509 U.S. 579
The decision holding that the Federal Rules of Evidence, not Frye's general-acceptance test, govern expert scientific testimony, and that the trial judge acts as a gatekeeper for reliability and fit. It offers a non-exclusive list of considerations: testability, peer review and publication, known or potential error rate, standards controlling the technique's operation, and general acceptance.
Does not cover: It predates every modern digital forensic method and mentions none of them, and its factors are not a test to be applied mechanically. It binds federal courts; a number of states still apply Frye or their own variants.
Lawyers and courtsWorking examiner
United States Courts (rule text as printed by the Committee on the Judiciary, U.S. House of Representatives) · Enacted January 2, 1975; restyled by the amendment effective December 1, 2011; text verified against the official print current to December 1, 2024 · 1975
An illustration of sufficient authentication: "Evidence describing a process or system and showing that it produces an accurate result." It is the route by which the output of software, an acquisition tool, or an automated system is authenticated through testimony about the tool rather than about the document.
Does not cover: It sets no threshold for how much validation is enough and names no test, tool, or error-rate standard; those come from case law and Rule 702. It is federal, and it says nothing about weight once the evidence is admitted.
Lawyers and courtsWorking examiner
American Bar Association · Current text of Comment [8] as published by the ABA and verified on 2026-09-12
The comment on maintaining competence, which provides that to maintain the requisite knowledge and skill a lawyer should keep abreast of changes in the law and its practice, "including the benefits and risks associated with relevant technology," engage in continuing study and education, and comply with applicable CLE requirements.
Does not cover: It is a comment to a model rule: it is not law anywhere until a jurisdiction adopts it, adoption and wording vary by state, and it sets no standard of what technological competence actually requires. It creates no cause of action and says nothing about a non-lawyer expert's obligations.
Lawyers and courtsWorking examiner
Forensic Science Regulator (England and Wales) · Issue 4; gov.uk page last updated 22 July 2024 · FSR-G-200
Guidance on the content of reports issued by expert witnesses in the criminal justice system of England and Wales, setting out the legal requirements for expert reports, requirements imposed by certain prosecuting authorities, and advice on applying them.
Does not cover: It is jurisdiction-specific: it does not address US federal reporting under FRCP 26 or FRE 702, nor civil practice in England and Wales. It is also discipline-neutral, so it gives no digital-specific direction on how to present hashes, extraction scope or tool limitations.
Working examinerLawyers and courts
INTERPOL
INTERPOL's guidance on establishing and managing a digital forensics laboratory, together with technical guidelines for managing and processing electronic evidence. INTERPOL lists it on its digital forensics page alongside two related publications, Framework for Responding to a Drone Incident and Guidelines for Digital Forensics First Responders.
Does not cover: INTERPOL's own topic page names the publication but states no version, edition or publication date and provides no direct download link, so the year could not be verified from an official source and is omitted here. It is guidance for law enforcement laboratories, not an accreditation standard, and carries no legal force in any jurisdiction.
Working examiner
Forensic Science Regulator (England and Wales) · Issue 2; gov.uk page last updated 22 July 2024 · FSR-G-218
The Regulator's guidance on applying the validation requirements of the code of practice to digital forensic methods: demonstrating that a method is fit for its specific intended purpose and that its limitations are understood and stated.
Does not cover: It is guidance rather than a requirement in itself; the binding requirements sit in the statutory code of practice. It does not validate any tool for you, supplies no reference datasets, and its general validation companion FSR-G-201 is non-digital. Note that FSR-G-201 is 'Forensic science providers: validation', not mobile phone guidance.
Working examinerAdvanced
Organization of Scientific Area Committees for Forensic Science, National Institute of Standards and Technology
A NIST-administered repository of forensic science standards that have passed technical and quality review by practitioners, researchers, statisticians and legal experts, and been approved by a two-thirds vote of the relevant OSAC subcommittee and the Forensic Science Standards Board. It lists both standards published by external standards development organisations and OSAC Proposed Standards awaiting SDO publication, spanning 24 disciplines.
Does not cover: Registry listing is not accreditation, certification or a legal requirement, and a method's absence is not evidence it is unsound. Access is mixed rather than uniformly free: OSAC's own proposed standards are free, ASTM documents need a free account, and other SDO-published standards follow that publisher's terms.
Working examinerLawyers and courts
Scientific Working Group on Digital Evidence
SWGDE's own listing of its published best practices, guidelines, technical notes, positions and considerations for digital and multimedia forensics, together with archived prior versions. As at September 2026 the library holds well over a hundred numbered documents across forensics (F), video (V), audio (A), imaging (I), photography (P), quality (Q) and multi-discipline (M) series.
Does not cover: SWGDE states that its documents carry no warranty, that they may be revised, deprecated or sunsetted at any time, and that any quotation must include the version number. They are consensus best practices, not accreditation requirements or legal standards, and coverage is uneven — some topics have detailed documents, others none.
Working examinerLawyers and courts
FreeSuperseded or dormant Association of Chief Police Officers · March 2012 · 2012
The UK guide that states the four ACPO principles for handling digital evidence — do not change the original data, record everything done, have a competent person do any live examination, and place responsibility for compliance on the officer in charge. Its own front matter records that ACPO agreed the revised guide for adoption by police forces in England, Wales and Northern Ireland.
Does not cover: ACPO was dissolved in 2015 and no longer maintains this guide; there is no official ACPO URL left, so the copy linked here is third-party hosted, and the current UK authority is the Forensic Science Regulator's statutory Code plus College of Policing guidance. It is England, Wales and Northern Ireland only, it predates cloud and modern mobile acquisition entirely, and the principles are a framework, not a method you can validate against.
Working examinerLawyers and courtsNew to the field