Skip to content

Evidence request lists

NIST SP 800-63 Digital Identity Guidelines

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Authentication - AAL1 + AAL2

NISTSP63-5
AAL1 and AAL2 Authentication: MFA, Approved Authenticators, Session Binding

Implement AAL1 and AAL2 authentication per NIST SP 800-63B Chapter 4 + Chapter 5 + Section 7. AAL1 requires (a) Single-factor authentication using any of memorised secret + look-up secret + out-of-band device + single-factor OTP + single-factor cryptographic software + single-factor cryptographic device + multi-factor authenticator (Section 5.1), (b) Phishing resistance not required at AAL1, (c) Verifier requirements per Section 5.1.1 (rate limiting + breached-password check + memorised secret composition rules per Section 5.1.1.2). AAL2 requires (a) Multi-Factor Authentication using approved authenticator combinations from Section 4.2.1 (memorised secret with second factor + multi-factor authenticator + or hardware OTP combined with memorised secret), (b) Cryptographic protection of authenticators + session binding per Section 7, (c) Reauthentication every 12 hours OR after 30 minutes o

Artefacts an auditor will ask for
  • authenticator inventory per AAL level showing approved authenticator types
  • memorised secret breach check evidence per Section 5.1.1.2
  • rate limiting and lockout configuration
  • session binding evidence per Section 7 + reauthentication timeline configuration
Where this commonly fails
  • weak password rules contrary to Section 5.1.1.2
  • session token not bound per Section 7.1.1
  • reauthentication interval not enforced

Authentication - AAL3

NISTSP63-6
AAL3 Authentication: Hardware Cryptographic, Verifier Impersonation Resistance, Phishing Resistance

Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a separate hardware cryptographic authenticator, (b) Verifier Impersonation Resistance (phishing resistance) per Section 4.3.4 - the authentication protocol must prevent attackers from impersonating the verifier (FIDO2/WebAuthn + PIV + client-certificate authentication satisfy this), (c) Verifier Compromise Resistance per Section 5.2.7, (d) Replay Resistance per Section 4.3.5, (e) Hardware Authenticator Requirements (FIPS 140-2 Level 1 overall + Level 2 physical security minimum), (f) Reauthentication every 12 hours OR 15 minutes of inactivity per Section 7.2 (stricter than AAL2), (g) Strong session binding per Section 7.1, (h) Recor

Artefacts an auditor will ask for
  • hardware authenticator inventory (FIDO2 + PIV + smart card) per AAL3 service
  • phishing-resistance verification per Section 4.3.4
  • FIPS 140-2 validation evidence for hardware authenticators
  • stricter reauthentication timeline configuration (12hr / 15min)
Where this commonly fails
  • software MFA claimed as AAL3 (does not meet hardware requirement)
  • phishing-resistant authenticators not phishing-resistant in actual protocol implementation
  • hardware token FIPS validation not verified

Cross-cutting: Threat Model, Lifecycle, Privacy, Equity

NISTSP63-8
Threat Model, Lifecycle Management, Privacy, Equity, Records, and Subscriber Communication

Operate cross-cutting requirements per NIST SP 800-63-3 / 63A / 63B / 63C. Threat Model per AAL: (a) per Section 8 of SP 800-63B + Section 4.4 of SP 800-63-3 (cover impersonation + verifier compromise + session hijacking + replay + phishing + denial of service threats appropriate to assurance level). Authenticator Lifecycle Management per SP 800-63B Chapter 6: (a) Authenticator Binding per Section 6.1, (b) Authenticator Loss and Replacement per Section 6.2 (post-loss recovery requires re-proofing or strong evidence of identity), (c) Authenticator Expiration per Section 6.3, (d) Authenticator Suspension and Revocation per Section 6.4 + Section 6.5, (e) Authenticator Strength Maintenance per Section 6.6. Subscriber Notification of Changes per Section 6.1.2 + 6.5. Authentication Event Records per SP 800-63B Section 10.2. Privacy per SP 800-63A Section 5.5 + SP 800-63B Section 9 + SP 800-63C

Artefacts an auditor will ask for
  • threat model per AAL covering Section 8 threats
  • authenticator lifecycle records (binding + loss + replacement + suspension + revocation)
  • privacy notices + consent records + retention policy + redress process
  • equity assessment (accessibility + alternatives + trusted referee + non-standard evidence options)
  • authentication event records per Section 10.2
Where this commonly fails
  • threat model generic and not AAL-tailored
  • loss/replacement process bypasses re-proofing requirement
  • equity considerations not documented
  • authentication event records insufficient for forensics

Digital Identity Risk and Assurance Level Selection

NISTSP63-1
Digital Identity Risk Assessment and Assurance Level Selection (IAL, AAL, FAL)

Conduct a Digital Identity Risk Assessment per NIST SP 800-63-3 Section 5 and select appropriate assurance levels for each digital transaction or service. The assessment determines (a) Identity Assurance Level (IAL1 self-asserted + IAL2 evidence-based remote or in-person + IAL3 in-person or supervised remote with strong evidence and biometric collection), (b) Authenticator Assurance Level (AAL1 single-factor + AAL2 multi-factor + AAL3 hardware cryptographic with verifier impersonation resistance), (c) Federation Assurance Level (FAL1 bearer assertion + FAL2 encrypted assertion + FAL3 holder-of-key assertion). Selection must consider (a) potential harms from authentication errors + identity proofing errors + federation errors across categories (inconvenience + distress + damage to standing or reputation + financial loss + harm to agency programs or public interests + unauthorised release

Artefacts an auditor will ask for
  • Digital Identity Risk Assessment per SP 800-63-3 Section 5 with harm categories + likelihood + mitigations
  • Assurance Level Selection rationale per dimension (IAL + AAL + FAL)
  • Digital Identity Acceptance Statement approved by authorising official
  • Privacy Impact Assessment per Section 5.5
Where this commonly fails
  • assurance level chosen without documented risk basis
  • all three dimensions over-specified causing equity barriers
  • no Digital Identity Acceptance Statement on file

Federation - FAL1/2/3

NISTSP63-7
Federation - FAL1, FAL2, FAL3 Assertions, RP Validation, Trust Agreements

Implement federation per NIST SP 800-63C across FAL1 + FAL2 + FAL3 levels. FAL1 per Section 4 requires (a) Bearer Assertion (signed by IdP + not encrypted to RP), (b) Trust Agreement between IdP and RP per Section 4.3.1, (c) Assertion Content Requirements per Section 4.4 (issuer + subject + audience + assertion identifier + expiry + nonce + signature), (d) Relying Party Validation Obligations per Section 4.5 (signature verification + audience + replay protection + expiry). FAL2 adds (a) Encrypted Assertion to the RP per Section 5, (b) Cryptographic key management per Section 5.2. FAL3 adds (a) Holder-of-Key assertion binding the assertion to a key held by the subscriber per Section 6 (preventing assertion replay by an intermediary), (b) Strong cryptographic binding of the holder-of-key authenticator to the assertion. Across all FAL: (c) Federation Audit Logging per Section 8.2, (d) Feder

Artefacts an auditor will ask for
  • federation trust agreements between IdP and RPs
  • assertion content compliance evidence (issuer + subject + audience + identifier + expiry + nonce + signature)
  • RP validation library evidence (signature + audience + replay + expiry check)
  • FAL2 encryption evidence + FAL3 holder-of-key binding evidence where applicable
  • attribute minimisation policy + runtime subscriber decision evidence
Where this commonly fails
  • bearer assertion at FAL1 not validated for audience or replay
  • attribute over-release (no minimisation)
  • FAL2/FAL3 declared but not implemented

Identity Proofing - IAL1

NISTSP63-2
IAL1 Self-Asserted Identity Proofing

Implement IAL1 self-asserted identity proofing per NIST SP 800-63A Section 4.2. At IAL1 attributes are self-asserted by the applicant + no validation or verification of those attributes is required + identifier may be pseudonymous + attributes may be collected only with applicant consent. IAL1 requires (a) clear notice to applicants per Section 5.5 of what attributes are collected and how they will be used, (b) consent mechanism per Section 5.5, (c) basic fraud mitigation appropriate to risk per Section 5.4 (rate limiting + anomaly detection + abuse reporting channels), (d) record retention per agency policy and legal requirements per Section 5.3, (e) accessibility considerations per Section 9. IAL1 is appropriate for low-risk transactions where impersonation harm is minimal and no need for binding identity to a real-world person.

Artefacts an auditor will ask for
  • IAL1 service inventory with documented risk basis
  • applicant notice and consent mechanism evidence
  • fraud mitigation controls (rate limiting + anomaly detection)
  • record retention policy and evidence
Where this commonly fails
  • IAL1 chosen for convenience without risk justification
  • no fraud mitigation despite IAL1 permitting basic mitigation
  • applicant notice incomplete

Identity Proofing - IAL2

NISTSP63-3
IAL2 Remote and In-Person Identity Proofing

Implement IAL2 identity proofing per NIST SP 800-63A Chapter 5 covering remote (Section 5.3.2) and in-person (Section 5.3.3) options. IAL2 requires (a) Identity Evidence Collection per Section 5.2.1 with strength categories (UNACCEPTABLE + WEAK + FAIR + STRONG + SUPERIOR) where IAL2 requires one piece of SUPERIOR or STRONG plus one piece of STRONG or FAIR evidence per Table 5-1, (b) Identity Resolution per Section 5.2.2 (correlating evidence to a single unique identity), (c) Evidence Validation per Section 5.2.3 (authenticity of presented evidence including authoritative source confirmation where available), (d) Identity Verification per Section 5.2.4 (binding evidence to the live applicant via in-person inspection + biometric comparison or live remote engagement with biometric comparison), (e) Knowledge-Based Verification restrictions per Section 5.3.2 (KBV may only be used as a seconda

Artefacts an auditor will ask for
  • evidence strength tracking per applicant matching Table 5-1 requirements
  • remote proofing vendor evidence (live biometric + document authentication + secure transmission)
  • in-person proofing process evidence with trained operator + documentation
  • KBV restriction adherence evidence (secondary process only + no publicly-available data alone)
Where this commonly fails
  • vendor only performs subset of required IAL2 steps
  • KBV used as primary mechanism violating Section 5.3.2
  • evidence strength not tracked against Table 5-1

Identity Proofing - IAL3

NISTSP63-4
IAL3 In-Person and Supervised Remote Identity Proofing

Implement IAL3 identity proofing per NIST SP 800-63A Section 5.3.3 and Section 5.3.4. IAL3 requires (a) Two pieces of SUPERIOR evidence or one SUPERIOR plus two STRONG or three STRONG pieces, (b) Biometric collection at enrolment per Section 5.2.3 enabling subsequent binding to the live applicant, (c) In-Person Proofing per Section 5.3.3 (physical presence) OR Supervised Remote Proofing per Section 5.3.4 (live remote interaction with a trained operator + video + biometric capture + secure transmission + tamper-evident technology + audit trail), (d) Trusted Referee and Applicant References per Section 5.3.5 where supported by the agency to address equity gaps, (e) Identity Proofing Record Retention per Section 5.3.6 including evidence + biometric + transcripts as required by Section 5.5. IAL3 is appropriate for high-risk transactions where impersonation harm is severe (financial fraud + s

Artefacts an auditor will ask for
  • IAL3 service inventory with risk justification
  • in-person proofing process evidence OR supervised remote proofing evidence (operator + video + biometric + tamper-evident + secure transmission + audit trail)
  • biometric collection at enrolment evidence with chain of custody
  • trusted referee process where used
Where this commonly fails
  • IAL3 over-selected causing equity barriers
  • supervised remote proofing without all required technological controls
  • biometric chain of custody incomplete
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.