Start with Identity
← Blog
News

NIST Digital Identity Guidelines (SP 800-63-4): from draft to final

NIST's rewrite of the Digital Identity Guidelines reached final publication in July 2025 after roughly four years and about 6,000 public comments. It brings syncable passkeys into scope, admits subscriber-controlled wallets to the federation model, and adds controls for injection attacks and forged media.

By SWI Community TeamAug 21, 2024Updated Jul 27, 2026

NIST published a public draft of SP 800-63-4 in August 2024 and finalised the revision in July 2025. It took roughly four years and about 6,000 public comments, which is a fair measure of how contested the previous edition had become.

Four changes matter most. Syncable authenticators, meaning passkeys that sync across a vendor's cloud, are explicitly in scope rather than an awkward fit, which removes the main excuse for treating them as unsuitable in regulated environments. The federation model admits subscriber-controlled wallets, aligning it with verifiable credentials work. New controls address injection attacks and forged media, deepfakes included, the first time synthetic media appears as a proofing threat. Identity proofing itself is restructured around clearer roles and expanded fraud requirements.

Why it matters

If you have been told that synced passkeys cannot meet a compliance bar, this is the document that settles the argument. 800-63-4 is what US federal agencies work to and what auditors in regulated industries reach for, so its treatment of an authenticator type effectively decides whether that type is deployable. Revisit any passwordless strategy scoped against 800-63-3 assumptions, and ask your identity proofing vendor what it does about forged media, because the guidelines now expect an answer.

Source: NIST SP 800-63-4

Independent analysis. No vendor sponsorship.