Skip to main content
IAMRoadmapIAMRoadmap
Back to Compliance
IAM Framework

NIST 800-63

Digital Identity Guidelines

United States / Global
Effective: June 22, 2017
Updated: July 31, 2025

Overview

NIST Special Publication 800-63 sets technical requirements for federal agencies implementing digital identity services. Revision 4 (SP 800-63-4) was published as final in July 2025 and supersedes Revision 3. It covers identity proofing, authentication, and federation at three assurance levels each (IAL, AAL, FAL), and adds a digital identity risk management process, requirements for syncable authenticators, subscriber-controlled wallets, and fraud controls for identity proofing. Although written for federal systems, it is widely used as a reference for digital identity practice.

IAM Requirements

Digital Identity Risk Management (800-63-4)

  • Define the online service, its functional scope, and the user groups it serves
  • Conduct an initial impact assessment across impact categories and potential harms
  • Select initial assurance levels (IAL, AAL, FAL) from the assessed impact levels
  • Tailor and document the selected assurance levels
  • Continuously evaluate and improve the identity management approach

Identity Proofing (800-63A-4)

  • IAL1: Core attributes are validated against authoritative or credible sources to support the real-world existence of the claimed identity (Revision 3 required no proofing at IAL1)
  • IAL2: Additional evidence and more rigorous validation and verification than IAL1
  • IAL3: A trained CSP representative interacts directly with the applicant in an attended session, with biometric collection
  • Proofing may be remote unattended, remote attended, on-site unattended, or on-site attended
  • Credential service providers must establish and maintain a fraud management program

Authentication (800-63B-4)

  • AAL1: Single-factor or multi-factor authentication; phishing resistance is not required
  • AAL2: Two distinct authentication factors; verifiers must offer at least one phishing-resistant option
  • AAL3: Phishing-resistant public-key cryptographic authenticator with a non-exportable private key; syncable authenticators are not permitted
  • Session limits: overall timeout should be no more than 30 days at AAL1 and 24 hours at AAL2, and must be no more than 12 hours at AAL3
  • Passwords: at least 15 characters when used as the only factor and 8 when part of multi-factor authentication; no composition rules, no periodic changes, and comparison against a blocklist

Federation (800-63C-4)

  • FAL1: Assertion is audience-restricted to a specific RP or set of RPs; injection protection is recommended
  • FAL2: Single RP per assertion, protection against assertion injection, and a trust agreement established before the transaction
  • FAL3: The RP verifies that the subscriber controls an authenticator (holder-of-key or bound) in addition to the assertion
  • Subscriber-controlled wallets are covered as a federation model in which the wallet presents attributes issued by the CSP

Authenticator Types

  • Passwords
  • Look-up secrets
  • Out-of-band devices (PSTN delivery is restricted; email must not be used)
  • Single-factor and multi-factor OTP
  • Single-factor and multi-factor cryptographic authenticators, including syncable authenticators below AAL3

Compliance Checklist

1
Run the digital identity risk management process for each online service
2
Determine required assurance levels (IAL, AAL, FAL) for each application
3
Select appropriate identity proofing methods
4
Implement compliant authenticators
5
Offer a phishing-resistant authenticator option at AAL2 and require one at AAL3
6
Establish credential lifecycle management
7
Implement session management controls
8
Deploy federation services where needed
9
Document identity and authentication policies
10
Implement privacy protections
11
Conduct regular assessments
12
Train staff on digital identity requirements

Penalties for Non-Compliance

Required for federal agencies; no direct penalties for private sector but increasingly referenced in regulations

Quick Facts

Region
United States / Global
Effective Date
June 22, 2017
Enforcing Body
National Institute of Standards and Technology (NIST)

Related Certifications

  • CIDPRO

Related Regulations & Frameworks