Digital Identity
What is Digital Identity?
The collection of electronically captured and stored personal attributes, credentials, and identifiers that uniquely represent an individual in digital systems.
Terms that appear alongside digital identity
Each of these is named in at least one of the same controls as digital identity. The number is how many controls name both.
- authentication 8 shared controls
- nist 5 shared controls
- transparency 4 shared controls
- identity verification 3 shared controls
- zero trust 3 shared controls
- oauth 3 shared controls
- multi factor authentication 3 shared controls
- saml 3 shared controls
Frameworks that govern digital identity
What the standards actually require on digital identity
Requirements naming digital identity across 6 standards, quoted from the control text.
Requires Member States to designate supervisory bodies to supervise European Digital Identity Wallet providers, with powers to monitor compliance, require information and order corrective action, and to report to the Commission and the Cooperation Group.
EIDAS-Art.46a · Supervision of the European Digital Identity Wallet framework →Conduct a Digital Identity Risk Assessment per NIST SP 800-63-3 Section 5 and select appropriate assurance levels for each digital transaction or service.
NISTSP63-1 · Digital Identity Risk Assessment and Assurance Level Selection (IAL, AAL, FAL) →Conduct Digital Identity Risk Management per NIST SP 800-63-4 Section 5 (April 2025) using the updated risk management process introduced in Rev 4.
NISTSP63R4-1 · Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection →Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication ensures the validity of the claimed identities of the entities participating in communication (e.g.
X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication · ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Factor + Cryptographic Authentication →Recognising that interoperable digital identity regimes promote connectivity and growth in the digital economy, the Parties shall pursue mechanisms to promote compatibility and interoperability between their respective digital identity regimes, including throu...
DEPA-7.1 · Digital Identities →The FATF 40 Recommendations + Methodology are the global AML/CFT/CPF standard. Last comprehensive revision February 2012; subsequent TARGETED UPDATES: R.5 (Terrorist Financing) 2024; R.8 (NPO) 2023 narrowed scope to focused proportionate measures;
FATF-Status · FATF 40 Recommendations - corpus status, 5th + 6th Mutual Evaluation Rounds + targeted updates →Questions people ask about digital identity
What is Digital Identity?
Why is Digital Identity important for compliance?
Which compliance frameworks address Digital Identity?
Where can I learn more about Digital Identity?
See how Digital Identity applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.