NIST SP 800-63 Digital Identity Guidelines
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Authentication - AAL1 + AAL2
Implement AAL1 and AAL2 authentication per NIST SP 800-63B Chapter 4 + Chapter 5 + Section 7. AAL1 requires (a) Single-factor authentication using any of memorised secret + look-up secret + out-of-band device + single-factor OTP + single-factor cryptographic software + single-factor cryptographic device + multi-factor authenticator (Section 5.1), (b) Phishing resistance not required at AAL1, (c) Verifier requirements per Section 5.1.1 (rate limiting + breached-password check + memorised secret composition rules per Section 5.1.1.2). AAL2 requires (a) Multi-Factor Authentication using approved authenticator combinations from Section 4.2.1 (memorised secret with second factor + multi-factor authenticator + or hardware OTP combined with memorised secret), (b) Cryptographic protection of authenticators + session binding per Section 7, (c) Reauthentication every 12 hours OR after 30 minutes o
- authenticator inventory per AAL level showing approved authenticator types
- memorised secret breach check evidence per Section 5.1.1.2
- rate limiting and lockout configuration
- session binding evidence per Section 7 + reauthentication timeline configuration
- weak password rules contrary to Section 5.1.1.2
- session token not bound per Section 7.1.1
- reauthentication interval not enforced
Authentication - AAL3
Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a separate hardware cryptographic authenticator, (b) Verifier Impersonation Resistance (phishing resistance) per Section 4.3.4 - the authentication protocol must prevent attackers from impersonating the verifier (FIDO2/WebAuthn + PIV + client-certificate authentication satisfy this), (c) Verifier Compromise Resistance per Section 5.2.7, (d) Replay Resistance per Section 4.3.5, (e) Hardware Authenticator Requirements (FIPS 140-2 Level 1 overall + Level 2 physical security minimum), (f) Reauthentication every 12 hours OR 15 minutes of inactivity per Section 7.2 (stricter than AAL2), (g) Strong session binding per Section 7.1, (h) Recor
- hardware authenticator inventory (FIDO2 + PIV + smart card) per AAL3 service
- phishing-resistance verification per Section 4.3.4
- FIPS 140-2 validation evidence for hardware authenticators
- stricter reauthentication timeline configuration (12hr / 15min)
- software MFA claimed as AAL3 (does not meet hardware requirement)
- phishing-resistant authenticators not phishing-resistant in actual protocol implementation
- hardware token FIPS validation not verified
Cross-cutting: Threat Model, Lifecycle, Privacy, Equity
Operate cross-cutting requirements per NIST SP 800-63-3 / 63A / 63B / 63C. Threat Model per AAL: (a) per Section 8 of SP 800-63B + Section 4.4 of SP 800-63-3 (cover impersonation + verifier compromise + session hijacking + replay + phishing + denial of service threats appropriate to assurance level). Authenticator Lifecycle Management per SP 800-63B Chapter 6: (a) Authenticator Binding per Section 6.1, (b) Authenticator Loss and Replacement per Section 6.2 (post-loss recovery requires re-proofing or strong evidence of identity), (c) Authenticator Expiration per Section 6.3, (d) Authenticator Suspension and Revocation per Section 6.4 + Section 6.5, (e) Authenticator Strength Maintenance per Section 6.6. Subscriber Notification of Changes per Section 6.1.2 + 6.5. Authentication Event Records per SP 800-63B Section 10.2. Privacy per SP 800-63A Section 5.5 + SP 800-63B Section 9 + SP 800-63C
- threat model per AAL covering Section 8 threats
- authenticator lifecycle records (binding + loss + replacement + suspension + revocation)
- privacy notices + consent records + retention policy + redress process
- equity assessment (accessibility + alternatives + trusted referee + non-standard evidence options)
- authentication event records per Section 10.2
- threat model generic and not AAL-tailored
- loss/replacement process bypasses re-proofing requirement
- equity considerations not documented
- authentication event records insufficient for forensics
Digital Identity Risk and Assurance Level Selection
Conduct a Digital Identity Risk Assessment per NIST SP 800-63-3 Section 5 and select appropriate assurance levels for each digital transaction or service. The assessment determines (a) Identity Assurance Level (IAL1 self-asserted + IAL2 evidence-based remote or in-person + IAL3 in-person or supervised remote with strong evidence and biometric collection), (b) Authenticator Assurance Level (AAL1 single-factor + AAL2 multi-factor + AAL3 hardware cryptographic with verifier impersonation resistance), (c) Federation Assurance Level (FAL1 bearer assertion + FAL2 encrypted assertion + FAL3 holder-of-key assertion). Selection must consider (a) potential harms from authentication errors + identity proofing errors + federation errors across categories (inconvenience + distress + damage to standing or reputation + financial loss + harm to agency programs or public interests + unauthorised release
- Digital Identity Risk Assessment per SP 800-63-3 Section 5 with harm categories + likelihood + mitigations
- Assurance Level Selection rationale per dimension (IAL + AAL + FAL)
- Digital Identity Acceptance Statement approved by authorising official
- Privacy Impact Assessment per Section 5.5
- assurance level chosen without documented risk basis
- all three dimensions over-specified causing equity barriers
- no Digital Identity Acceptance Statement on file
Federation - FAL1/2/3
Implement federation per NIST SP 800-63C across FAL1 + FAL2 + FAL3 levels. FAL1 per Section 4 requires (a) Bearer Assertion (signed by IdP + not encrypted to RP), (b) Trust Agreement between IdP and RP per Section 4.3.1, (c) Assertion Content Requirements per Section 4.4 (issuer + subject + audience + assertion identifier + expiry + nonce + signature), (d) Relying Party Validation Obligations per Section 4.5 (signature verification + audience + replay protection + expiry). FAL2 adds (a) Encrypted Assertion to the RP per Section 5, (b) Cryptographic key management per Section 5.2. FAL3 adds (a) Holder-of-Key assertion binding the assertion to a key held by the subscriber per Section 6 (preventing assertion replay by an intermediary), (b) Strong cryptographic binding of the holder-of-key authenticator to the assertion. Across all FAL: (c) Federation Audit Logging per Section 8.2, (d) Feder
- federation trust agreements between IdP and RPs
- assertion content compliance evidence (issuer + subject + audience + identifier + expiry + nonce + signature)
- RP validation library evidence (signature + audience + replay + expiry check)
- FAL2 encryption evidence + FAL3 holder-of-key binding evidence where applicable
- attribute minimisation policy + runtime subscriber decision evidence
- bearer assertion at FAL1 not validated for audience or replay
- attribute over-release (no minimisation)
- FAL2/FAL3 declared but not implemented
Identity Proofing - IAL1
Implement IAL1 self-asserted identity proofing per NIST SP 800-63A Section 4.2. At IAL1 attributes are self-asserted by the applicant + no validation or verification of those attributes is required + identifier may be pseudonymous + attributes may be collected only with applicant consent. IAL1 requires (a) clear notice to applicants per Section 5.5 of what attributes are collected and how they will be used, (b) consent mechanism per Section 5.5, (c) basic fraud mitigation appropriate to risk per Section 5.4 (rate limiting + anomaly detection + abuse reporting channels), (d) record retention per agency policy and legal requirements per Section 5.3, (e) accessibility considerations per Section 9. IAL1 is appropriate for low-risk transactions where impersonation harm is minimal and no need for binding identity to a real-world person.
- IAL1 service inventory with documented risk basis
- applicant notice and consent mechanism evidence
- fraud mitigation controls (rate limiting + anomaly detection)
- record retention policy and evidence
- IAL1 chosen for convenience without risk justification
- no fraud mitigation despite IAL1 permitting basic mitigation
- applicant notice incomplete
Identity Proofing - IAL2
Implement IAL2 identity proofing per NIST SP 800-63A Chapter 5 covering remote (Section 5.3.2) and in-person (Section 5.3.3) options. IAL2 requires (a) Identity Evidence Collection per Section 5.2.1 with strength categories (UNACCEPTABLE + WEAK + FAIR + STRONG + SUPERIOR) where IAL2 requires one piece of SUPERIOR or STRONG plus one piece of STRONG or FAIR evidence per Table 5-1, (b) Identity Resolution per Section 5.2.2 (correlating evidence to a single unique identity), (c) Evidence Validation per Section 5.2.3 (authenticity of presented evidence including authoritative source confirmation where available), (d) Identity Verification per Section 5.2.4 (binding evidence to the live applicant via in-person inspection + biometric comparison or live remote engagement with biometric comparison), (e) Knowledge-Based Verification restrictions per Section 5.3.2 (KBV may only be used as a seconda
- evidence strength tracking per applicant matching Table 5-1 requirements
- remote proofing vendor evidence (live biometric + document authentication + secure transmission)
- in-person proofing process evidence with trained operator + documentation
- KBV restriction adherence evidence (secondary process only + no publicly-available data alone)
- vendor only performs subset of required IAL2 steps
- KBV used as primary mechanism violating Section 5.3.2
- evidence strength not tracked against Table 5-1
Identity Proofing - IAL3
Implement IAL3 identity proofing per NIST SP 800-63A Section 5.3.3 and Section 5.3.4. IAL3 requires (a) Two pieces of SUPERIOR evidence or one SUPERIOR plus two STRONG or three STRONG pieces, (b) Biometric collection at enrolment per Section 5.2.3 enabling subsequent binding to the live applicant, (c) In-Person Proofing per Section 5.3.3 (physical presence) OR Supervised Remote Proofing per Section 5.3.4 (live remote interaction with a trained operator + video + biometric capture + secure transmission + tamper-evident technology + audit trail), (d) Trusted Referee and Applicant References per Section 5.3.5 where supported by the agency to address equity gaps, (e) Identity Proofing Record Retention per Section 5.3.6 including evidence + biometric + transcripts as required by Section 5.5. IAL3 is appropriate for high-risk transactions where impersonation harm is severe (financial fraud + s
- IAL3 service inventory with risk justification
- in-person proofing process evidence OR supervised remote proofing evidence (operator + video + biometric + tamper-evident + secure transmission + audit trail)
- biometric collection at enrolment evidence with chain of custody
- trusted referee process where used
- IAL3 over-selected causing equity barriers
- supervised remote proofing without all required technological controls
- biometric chain of custody incomplete
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.