Back to Compliance
IAM Framework
NIST 800-63
Digital Identity Guidelines
United States / Global
Effective: June 22, 2017
Updated: July 31, 2025
Overview
NIST Special Publication 800-63 sets technical requirements for federal agencies implementing digital identity services. Revision 4 (SP 800-63-4) was published as final in July 2025 and supersedes Revision 3. It covers identity proofing, authentication, and federation at three assurance levels each (IAL, AAL, FAL), and adds a digital identity risk management process, requirements for syncable authenticators, subscriber-controlled wallets, and fraud controls for identity proofing. Although written for federal systems, it is widely used as a reference for digital identity practice.
IAM Requirements
Digital Identity Risk Management (800-63-4)
- Define the online service, its functional scope, and the user groups it serves
- Conduct an initial impact assessment across impact categories and potential harms
- Select initial assurance levels (IAL, AAL, FAL) from the assessed impact levels
- Tailor and document the selected assurance levels
- Continuously evaluate and improve the identity management approach
Identity Proofing (800-63A-4)
- IAL1: Core attributes are validated against authoritative or credible sources to support the real-world existence of the claimed identity (Revision 3 required no proofing at IAL1)
- IAL2: Additional evidence and more rigorous validation and verification than IAL1
- IAL3: A trained CSP representative interacts directly with the applicant in an attended session, with biometric collection
- Proofing may be remote unattended, remote attended, on-site unattended, or on-site attended
- Credential service providers must establish and maintain a fraud management program
Authentication (800-63B-4)
- AAL1: Single-factor or multi-factor authentication; phishing resistance is not required
- AAL2: Two distinct authentication factors; verifiers must offer at least one phishing-resistant option
- AAL3: Phishing-resistant public-key cryptographic authenticator with a non-exportable private key; syncable authenticators are not permitted
- Session limits: overall timeout should be no more than 30 days at AAL1 and 24 hours at AAL2, and must be no more than 12 hours at AAL3
- Passwords: at least 15 characters when used as the only factor and 8 when part of multi-factor authentication; no composition rules, no periodic changes, and comparison against a blocklist
Federation (800-63C-4)
- FAL1: Assertion is audience-restricted to a specific RP or set of RPs; injection protection is recommended
- FAL2: Single RP per assertion, protection against assertion injection, and a trust agreement established before the transaction
- FAL3: The RP verifies that the subscriber controls an authenticator (holder-of-key or bound) in addition to the assertion
- Subscriber-controlled wallets are covered as a federation model in which the wallet presents attributes issued by the CSP
Authenticator Types
- Passwords
- Look-up secrets
- Out-of-band devices (PSTN delivery is restricted; email must not be used)
- Single-factor and multi-factor OTP
- Single-factor and multi-factor cryptographic authenticators, including syncable authenticators below AAL3
Compliance Checklist
1
Run the digital identity risk management process for each online service2
Determine required assurance levels (IAL, AAL, FAL) for each application3
Select appropriate identity proofing methods4
Implement compliant authenticators5
Offer a phishing-resistant authenticator option at AAL2 and require one at AAL36
Establish credential lifecycle management7
Implement session management controls8
Deploy federation services where needed9
Document identity and authentication policies10
Implement privacy protections11
Conduct regular assessments12
Train staff on digital identity requirementsPenalties for Non-Compliance
Required for federal agencies; no direct penalties for private sector but increasingly referenced in regulations
Quick Facts
- Region
- United States / Global
- Effective Date
- June 22, 2017
- Enforcing Body
- National Institute of Standards and Technology (NIST)
Related Certifications
- CIDPRO