# aal

Source: https://startwithidentity.com/glossary/aal/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

NIST 800-63B levels describing authentication strength. AAL1: single factor. AAL2: multi-factor. AAL3: multi-factor with phishing-resistant cryptographic authenticator (FIDO2, smartcards). Higher AAL is mandatory for higher-impact systems.

Assurance levels matter because they let a policy say "this action requires AAL2" instead of naming a specific product, which survives vendor changes. The practical jump is AAL2 to AAL3: push notifications and one-time codes satisfy AAL2 but are relayed by attacker-in-the-middle kits every day, while AAL3 requires a cryptographic authenticator bound to the origin. US federal systems and a growing set of regulated industries map controls directly to these levels.

See also: [NIST 800-63](https://startwithidentity.com/glossary/nist-800-63/), [phishing-resistant MFA](https://startwithidentity.com/glossary/phishing-resistant-mfa/), [WebAuthn and FIDO2](https://startwithidentity.com/standards/webauthn-fido2/), [IAL](https://startwithidentity.com/glossary/ial/)
