NIST SP 800-63-4
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Authentication and Authenticator Types
Implement authentication per NIST SP 800-63-4 Volume B (Authentication and Authenticator Lifecycle). Approve authenticator types per Section 4 covering (a) memorised secrets (Section 4.1), (b) look-up secrets (Section 4.2), (c) out-of-band devices (Section 4.3 with restrictions on SMS), (d) single-factor and multi-factor OTP devices (Section 4.4 + 4.5), (e) cryptographic software and hardware (Section 4.6 + 4.7 + 4.8 + 4.9), (f) syncable authenticators (NEW in Rev 4 per Section 4.10 covering FIDO2 passkeys that synchronise across user devices via cloud + provider attestation + cryptographic guarantees). Multi-Factor Authentication required at AAL2 per Section 5.2 + AAL3 per Section 5.3. Phishing-resistance per Section 4.13 specifies phishing-resistant authenticators (multi-factor cryptographic hardware + FIDO2 + smart card + PIV) and is REQUIRED at AAL3 + RECOMMENDED at AAL2 for high-ris
- authenticator inventory by AAL level + authenticator type
- syncable passkey policy (provider selection + attestation + recovery)
- phishing-resistance enforcement evidence at AAL3 + high-risk AAL2 services
- MFA enrolment metrics + coverage reporting
- SMS OTP still primary second factor despite Rev 4 restrictions
- syncable passkeys deployed without policy + attestation evaluation
- phishing-resistance not enforced at AAL3 despite mandate
Authenticator Lifecycle Management
Manage authenticator lifecycle per NIST SP 800-63-4 Volume B Chapter 6. Binding per Section 6.1: bind authenticator to verified subscriber identity. Authenticator recovery per Section 6.2: post-loss recovery via re-proofing OR strong alternative evidence + alternative authenticator + risk-based controls. Authenticator replacement per Section 6.3. Authenticator expiration per Section 6.4 covering cryptographic key lifetime + biometric template freshness + memorised secret rotation policy (note: Rev 4 retains the no-arbitrary-rotation guidance but allows rotation on suspected compromise). Authenticator suspension per Section 6.5: temporary suspension on suspected compromise + clear unsuspend procedure. Authenticator revocation per Section 6.6: terminal revocation on confirmed compromise + clear binding-replacement workflow. Lifecycle event records per Section 6.7. Subscriber notification o
- authenticator binding event records
- recovery process documentation with assurance level matching authentication
- suspension and revocation logs + procedures
- subscriber notification of changes evidence
- recovery uses security questions or static PINs (weak fallback)
- recovery process has lower assurance than authentication
- subscriber notification of binding changes not implemented
Digital Identity Risk Management
Conduct Digital Identity Risk Management per NIST SP 800-63-4 Section 5 (April 2025) using the updated risk management process introduced in Rev 4. The process now explicitly considers (a) impacts to people accessing services (not only impacts to the agency), (b) equity impacts assessed alongside security and privacy impacts, (c) usability impacts on legitimate users. Select Identity Assurance Level (IAL1 + IAL2 + IAL3) per SP 800-63-4 Volume A based on consequences of identity proofing failure to the individual + the agency + third parties. Select Authenticator Assurance Level (AAL1 + AAL2 + AAL3) per SP 800-63-4 Volume B based on consequences of authentication failure. Select Federation Assurance Level (FAL1 + FAL2 + FAL3) per SP 800-63-4 Volume C based on consequences of federation failure. Document the Digital Identity Acceptance Statement with rationale + alternatives considered + e
- Digital Identity Risk Management documentation per Rev 4 Section 5 covering subscriber + agency + third-party impacts
- IAL/AAL/FAL selection rationale per service with equity + privacy + usability assessment
- Digital Identity Acceptance Statement approved by authorising official
- ongoing monitoring plan for risk model + assumptions
- risk model considers agency only not subscribers
- no equity or usability assessment alongside security and privacy
- Digital Identity Acceptance Statement not updated since Rev 3
Equity, Accessibility, Inclusion
Address equity and accessibility per NIST SP 800-63-4 (substantial expansion versus Rev 3). Equity considerations per Section 8 of SP 800-63-4 Base require (a) assessing differential impact of identity service design on protected classes + vulnerable populations + people without standard documentary evidence, (b) providing alternative proofing pathways including trusted referee + applicant references + supervised remote for those without standard evidence, (c) accessibility per Section 504 + ADA + Section 508 covering reasonable adjustments + multiple language support + alternative formats for instructions and notices, (d) usability testing with diverse populations during design + after changes, (e) feedback channels for subscribers to report barriers + measurable improvement plans. Service-level evidence must be collected to demonstrate equitable outcomes by demographic where lawful and
- equity assessment per identity service with differential impact analysis
- alternative proofing pathways evidence (trusted referee + applicant references + supervised remote)
- accessibility compliance evidence (Section 508 + ADA + reasonable adjustments + multiple language support)
- usability testing with diverse populations + feedback channel + improvement plan
- no equity assessment despite Rev 4 mandate
- no alternative proofing pathway for those without standard evidence
- accessibility limited to single language or single format
Federation and Assertions
Implement federation per NIST SP 800-63-4 Volume C (Federation and Assertions). Trust agreements per Section 4.3 between Credential Service Provider (CSP) + Identity Provider (IdP) + Relying Party (RP) defining responsibilities + assurance levels + assertion format + cryptographic parameters + audit obligations. Assertion protection per Section 5: bearer (FAL1) + encrypted (FAL2) + holder-of-key (FAL3) per Section 5.5 with required cryptographic algorithms + key management + nonce + expiry + audience binding. RP validation per Section 6.2: validate signature + audience + issuer + replay nonce + expiry + revocation status. Pseudonymous identifiers per Section 7.3 supporting privacy by letting RP-specific identifiers prevent cross-RP correlation by IdP. Attribute minimisation per Section 7.4. Runtime subscriber decision per Section 7.5: subscriber choice on attribute release at runtime. Fe
- trust agreements between CSP/IdP/RP with assurance level + cryptographic parameters + audit obligations
- FAL2/FAL3 encryption + holder-of-key evidence where applicable
- RP validation library evidence
- pseudonymous identifier design where required for privacy
- assertions not validated for audience + replay nonce
- FAL declared higher than implemented
- no pseudonymous identifier support despite privacy requirements
Identity Proofing - Evidence and Validation
Conduct identity proofing per NIST SP 800-63-4 Volume A (Identity Proofing and Enrollment). Collect identity evidence per Section 4.3 (evidence quality tiers FAIR + STRONG + SUPERIOR) appropriate to IAL level. Conduct remote identity proofing per Section 5 with explicit support for (a) fully remote unattended proofing with document authentication + selfie capture + liveness detection, (b) supervised remote with trained operator, (c) Identity Validation Services (IDVS) per Section 4 as a new category in Rev 4 covering commercial identity verification providers operating under NIST conformance. Identity resolution per Section 4.4 (correlate evidence to single identity). Identity validation per Section 4.5 (confirm authenticity of evidence via authoritative source where available). Identity verification per Section 4.6 (bind validated evidence to the live applicant). Apply phishing-resistan
- evidence collection records with quality tier per piece per applicant
- remote proofing vendor evaluation against Rev 4 conformance
- IDVS provider selection record with conformance evidence
- identity resolution + validation + verification step-by-step audit trail per enrolment
- vendor selected on cost not on Rev 4 conformance
- IDVS provider chain of trust unclear
- remote proofing without liveness or document authentication
Operational Audit, Sessions, Cross-cutting
Operate cross-cutting controls per NIST SP 800-63-4. Identity service operational audit per Volume B Chapter 10: continuous audit of authentication events + identity proofing decisions + federation assertions + administrative actions with retention aligned to legal + investigative + regulatory requirements. Session management per Volume B Chapter 7: session binding via cryptographic protection of session tokens + reauthentication every 12 hours OR 30 minutes idle at AAL2 + every 12 hours OR 15 minutes idle at AAL3 + secure session termination + concurrent session limits where appropriate. Authenticator recovery per Volume B Chapter 6 with no weak fallback. Biometric governance per Volume A Section 4.3.6 + Volume B Section 4.10 + Volume B Chapter 9: subject consent + presentation attack detection + accuracy thresholds per AAL + bias testing + retention restrictions. Memorised secret requi
- continuous audit of authentication + proofing + federation + administrative events with retention
- session binding + reauthentication configuration aligned to AAL
- memorised secret policy aligned to Rev 4 (minimum length + breach check + context-common-word check + no forced rotation + no security questions)
- NIST SP 800-61 IR runbook integration for identity compromise + post-incident lessons learned
- audit retention shorter than statute requires
- session reauthentication intervals not enforced
- password policy still uses arbitrary complexity + forced rotation contrary to Rev 4
- no identity-specific IR runbook
Privacy, Records, User-Controlled Wallets
Apply privacy and records management per NIST SP 800-63-4. Privacy requirements per Section 7 of each Volume require (a) purpose limitation + minimisation + storage limitation + lawful basis per applicable jurisdiction, (b) Privacy Impact Assessment per agency obligations, (c) Privacy Act + GDPR + state law + sectoral compliance, (d) subscriber notice + consent + redress, (e) limits on biometric retention and reuse beyond original purpose. Records retention per Volume A Section 4.8 + Volume B Section 6.7 + Volume C Section 10 covering chain of custody for evidence + biometrics + transcripts + lifecycle events as required by agency policy + statute. User-controlled wallets (NEW in Rev 4) per emerging guidance: when issuing or accepting credentials held in user-controlled wallets (mDL + verifiable credentials + decentralised identifiers) (a) define the trust framework + revocation mechanis
- Privacy Impact Assessment per identity service
- biometric retention and use limitations evidence
- records retention policy + chain of custody for evidence + biometrics + lifecycle events
- user-controlled wallet trust framework + revocation + binding + privacy properties where deployed
- biometric retention beyond original purpose
- records retention policy not aligned to statutory requirements
- user-controlled wallets deployed without trust framework documentation
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-63-4 framework page.