| Work item | Question | Equiv. Num. | Status | Timing | Approval process | Version | Liaison relationship | Subject / Title | Priority |
| X.1053rev | Q10/17 | | Under study | 2026-06 | AAP | Rev. | - | Information security controls based on ITU-T X.1051 for small and medium-sized telecommunication organizations | Medium |
| X.1254rev | Q10/17 | | Under study | 2027-01 | TAP | Rev. | FIDO Alliance, NIST, ISO/IEC JTC1 SC 27 WG 5 | Entity authentication assurance framework | - |
| X.1281Amd1 | Q10/17 | OSIA v6.1.0 | Under study | 2026-09 | TAP | - | SIA (Secure Identity Alliance), ETSI | APIs for interoperability of identity management systems | Medium |
| X.2311 (ex X.f2am) | Q10/17 | OpenID FAPI 2.0 attacker model | Determined 2026-06-10 | 2026-06 | TAP | New | OpenID Foundation | Financial-grade API (FAPI) 2.0 attacker model | Medium |
| X.2312 (ex X.f2sp) | Q10/17 | OpenID FAPI 2.0 security profile | Under study | 2026-09 | TAP | New | OpenID Foundation | Financial-grade API 2.0 (FAPI) security profile | Medium |
| X.aas-2 | Q10/17 | ISO/IEC 27566-2 | Under study | 2028-09 | TAP | New | ISO/IEC JTC 1/SC 27/WG 5, IETF | Age assurance systems - Part 2: Technical approaches and guidance for implementation | Medium |
| X.aas-3 | Q10/17 | ISO/IEC 27566-3 | Under study | - | TAP | New | ISO/IEC JTC 1/SC 27/WG 5, IETF | Age assurance systems - Part 3: Approaches to analysis or comparison | Medium |
| X.AIA-dii-req | Q10/17 | | Under study | 2028-12 | TAP | New | ITU-T SG13, SG20, SG21, IETF, IEEE, ISO/IEC JTC1/SC27 , ISO/TC 307 | Security requirements for DLT-based decentralized identity interoperability across artificial intelligence agents | Medium |
| X.aiidm | Q10/17 | | Under study | 2027-06 | TAP | New | W3C (DID/VC WG), IETF (OAuth, Security Area), OIDF, CNCF, Linux Foundation (A2A), ISO/IEC JTC 1/SC 27 & SC 42, NIST | Canonical agentic AI identity data model | Medium |
| X.AIssc-sm | Q10/17 | | Under study | 2028-06 | TAP | New | ITU-T SG 13, ITU-T SG 20, ISO/IEC JTC 1/SC 42 | Guidelines on AI system supply chain security management for telecommunications organizations | Medium |
| X.C2M2 | Q10/17 | | Under study | 2027-01 | AAP | New | - | Cybersecurity capability maturity model for telecommunication organisations | Medium |
| X.cdc-csirt | Q10/17 | | Under study | 2027-01 | AAP | New | FIRST | Relationship between Cyber Defence/Security Center and Computer Security Incident Response Team | Medium |
| X.dpidm-aAI | Q10/17 | | Under study | 2027-12 | TAP | New | OIDF, IETF, W3C | Terminology and design guidelines for Agentic AI identity management | Medium |
| X.gsm-cdc | Q10/17 | | Under study | 2027-01 | AAP | New | - | Guidelines on Security Metrics for CDC | Medium |
| X.qspm | Q10/17 | | Under study | 2028-06 | TAP | New | IETF, ISO/IEC JTC 1/SC 27/WG 5 | Framework for QR code-based serverless password manager using a mobile device | Medium |
| X.remote-qes | Q10/17 | | Under study | 2027-12 | TAP | New | ETSI ESI, ISO/IEC JTC 1/SC 27, Cloud Signature Consortium | Security and interoperability framework for remote and cloud qualified electronic signatures | Medium |
| X.sc-sd | Q10/17 | | Under study | 2027-09 | TAP | New | ISO/IEC JTC 1/SC 27/WG 5, ISO TC 307, W3C, OASIS, OpenID Foundation, DIF | Security capability for implementing selective disclosure system in the decentralized identity system | Medium |
| X.sfdiw | Q10/17 | | Under study | 2026-09 | TAP | Rev. | ISO/IEC JTC 1/SC 27/WG 5, ISO TC 307, W3C, OASIS, OpenID Foundation, DIF, SIA (Secure Identity Alliance) | Security framework of digital identity wallet for decentralized identity model | Medium |
| X.sg-dfivc | Q10/17 | | Under study | 2027-09 | TAP | New | ISO/IEC JTC 1/SC 27/WG 5, ISO TC 307, W3C, OASIS, OpenID Foundation, DIF | Security guidelines for data format interoperability of verifiable credential in decentralized identity system | Medium |
| X.srm-ssc | Q10/17 | | Under study | 2027-01 | TAP | New | ISO/IEC JTC 1/SC 27 WG4 & WG5 | Security risk management on software supply chain for telecommunication organizations | Medium |