NIST SP 800-63
The US National Institute of Standards and Technology Digital Identity Guidelines. Defines Identity Assurance Levels (IAL), Authenticator Assurance Levels (AAL), and Federation Assurance Levels (FAL). The reference framework for federal and many enterprise identity programs.
The value of SP 800-63 is that it separates three questions people constantly conflate: how well we proved who you are (IAL), how strongly you authenticated (AAL), and how much we trust an assertion from another party (FAL). Writing requirements against those levels rather than against products is what makes a control survive a vendor migration, and it is why US federal and many regulated programs reference it directly.
See also: IAL, AAL, phishing-resistant MFA, identity verification
Related on Start with Identity
- GlossaryWebAuthn
A W3C standard browser API for public-key authentication. WebAuthn is the protocol used by passkeys and FIDO2 security keys. The relying party server stores the
- GlossaryPasskey
A passkey is a WebAuthn public-key credential that replaces a password. Possession of the authenticator plus a user verification step proves identity, with no s
- ExpertLead author, NIST SP 800-63-3
Paul Grassi led NIST SP 800-63-3 with Michael Garcia and James Fenton in NIST's Applied Cybersecurity Division. The 2017 revision restructured federal digital i
- BlogNIST Digital Identity Guidelines (SP 800-63-4): from draft to final
NIST's rewrite of the Digital Identity Guidelines reached final publication in July 2025 after roughly four years and about 6,000 public comments. It brings syn
- GlossaryAnonCreds
A verifiable credential format, originating in Hyperledger Indy and now a standalone specification, built around zero-knowledge proofs for strong selective disc
- ExpertCo-author of the NIST RBAC model
David Ferraiolo co-authored "Role-Based Access Controls" with Rick Kuhn, presented at the 15th National Computer Security Conference in October 1992. The NIST m