Legal Cyber Academy
ToolFreeCurrent

Computer Forensics Tool Testing Program (CFTT)

National Institute of Standards and Technology

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

NIST's long-running programme that builds tool specifications, test assertions, test procedures and test data for categories of forensic function — disk imaging, hardware and software write blocking, deleted file recovery, file carving, string searching, media preparation, mobile device and cloud data extraction, Windows registry and SQLite tools — and publishes the resulting test reports with DHS Science and Technology.

Who it is for, and when

Use the published reports as third-party evidence of how a specific version of a specific tool behaved against a defined specification, which is often the fastest answer to a cross-examination question about tool reliability. Lab managers use the specifications and assertions as the skeleton of their own validation plans.

What it does not cover

CFTT tests functions against its own written requirements; it does not certify, approve or rank products, does not test every tool or every version, and its reports can lag current releases by years. A CFTT report on an old version says nothing directly about the build you actually ran.

Go to the source

Open at nist.gov (opens in a new tab)

https://www.nist.gov/itl/ssd/software-quality-group/computer-forensics-tool-testing-program-cftt

Details

Type
Tool
Written for
Working examinerLawyers and courtsWorking examiner, Lawyers and courts
Publisher
National Institute of Standards and Technology
Topics
tool-testing, validation, quality-assurance, lab-accreditation, us-federal
Checked at source
  • A CFTT offshoot that packages NIST's test methodology so labs can run it themselves and optionally share results: distributed as bootable Linux ISOs and a portable Windows web-server build, with report templates. Current suites cover disk imaging, forensic media preparation, hardware write blocking, string searching, SQLite recovery, mobile device acquisition and cloud data extraction, with companion datasets in CFReDS.

  • SWGDE's statement of the minimum a laboratory must do to test a tool before using it in casework, including what to record about the tool, the test data and the outcome. The version verified here is 18-Q-001-2.1 dated 7 March 2024.

  • A NIST repository of documented simulated digital evidence — images and data sets with known ground truth — developed with National Institute of Justice support. Holdings include scenario images (hacking case, data leakage case), Windows registry and Unicode string-search sets, Mac and mobile images, memory images, file carving and deleted-file-recovery sets, and reference/control drives.

  • A 65-page manual from ENFSI's Forensic Information Technology working group covering personnel, equipment, accommodation, peer review, examination protocols, validation and uncertainty of measurement, proficiency testing, handling items, case assessment and prioritisation. It is one of ten ENFSI best practice manuals issued in November 2015 under the EU-funded TEFSBPM project.

  • The statutory code of practice the Forensic Science Regulator is required to publish under the Forensic Science Regulator Act 2021, setting quality standard requirements for forensic science activities relating to the investigation of crime in England and Wales. Version 2 replaced version 1 and came into force on 2 October 2025.