NIST SP 800-63 Digital Identity Guidelines
NIST SP 800-63 is the United States government’s core framework for managing digital identity risk. It defines assurance levels for identity proofing, authentication and federation, and is widely used as a benchmark beyond federal agencies.
NIST Special Publication 800-63, Digital Identity Guidelines, is the United States government framework for establishing trust in online identities. It sets technical and process expectations for services that need to know who is accessing an account, how confidently that person’s identity has been established, and whether credentials can be shared safely between systems.
The guidelines are in force for US federal digital identity programs through federal policy and agency implementation. They are not a statute or a general-purpose privacy law, and they do not automatically bind private companies. However, they are a central reference point for identity verification, authentication and single sign-on design in the United States.
What NIST 800-63 covers
The framework separates digital identity into three related assurance concepts. This separation matters because proving an applicant’s identity, protecting an account at login and accepting an assertion from another service are different risks with different controls.
- Identity Assurance Level, or IAL, addresses identity proofing. It concerns the confidence that an applicant is the person they claim to be, based on evidence, validation and verification processes. Higher IALs call for stronger evidence and checks, and may include in-person or supervised remote proofing options.
- Authenticator Assurance Level, or AAL, addresses authentication. It measures confidence that the person using an account controls the authenticator, such as a cryptographic security key, passkey, smart card or other approved method. Higher AALs require stronger authentication and more protection against account takeover.
- Federation Assurance Level, or FAL, addresses federated identity. Federation allows a relying party, such as a government service, to accept a signed assertion from an identity provider rather than authenticate the user directly. FAL requirements address the protection, integrity and handling of those assertions.
The 800-63 publication suite provides the overarching model, while companion volumes address identity proofing and enrollment, authentication and authenticator management, and federation and assertions. Agencies use the levels to specify requirements for particular transactions, not as a universal ranking of every user or service.
A risk-based model, not one rule for every account
NIST 800-63 calls for agencies to select assurance based on the potential harm from an error or compromise. Relevant consequences can include financial loss, unauthorized disclosure of personal data, denial of benefits, damage to reputation, physical safety risks and effects on civil liberties.
A low-risk informational service may need little or no identity proofing. A service involving tax data, health information, benefits, regulated records or high-value transactions may require stronger proofing and phishing-resistant authentication. Agencies must also consider usability, accessibility, equity, fraud threats and the practical availability of identity evidence. The objective is proportionate assurance, rather than collecting more personal data or imposing stronger login steps by default.
Use in federal government and beyond
US federal agencies use NIST 800-63 when designing public-facing and workforce digital services, subject to Office of Management and Budget policy and agency-specific risk decisions. It helps agencies document why a particular proofing method, multi-factor authentication requirement or federation arrangement is appropriate. Implementation can vary across programs because the guidelines are applied to each service’s risk profile.
State and local governments, contractors and organizations serving federal users also look to the guidelines, especially where systems exchange identity information with federal programs. NIST publications are influential internationally, but they are US guidance rather than EU law. Organizations operating in Europe may need to align separately with the EU Digital Identity Framework, the eIDAS framework and applicable data protection obligations.
The 800-63 revision cycle
NIST updates the guidelines through public drafts, comment periods, workshops and final publications. The fourth revision, known as the 800-63-4 suite, succeeds the widely used 800-63-3 version and reflects changes in authentication technology, remote identity proofing, fraud methods and user experience research.
Revision work is consequential because it can change how agencies evaluate evidence, handle biometric checks, support alternative proofing paths, deploy phishing-resistant authentication and manage federated credentials. NIST’s process is ongoing in the broader sense: the agency continues to gather implementation feedback, issue related guidance and revise technical recommendations as threats and technologies evolve. Organizations should therefore identify the specific edition and companion volume referenced in a contract, policy or procurement requirement.
Why private-sector organizations reference it
Private organizations often use NIST 800-63 as a defensible vocabulary for security and procurement. A bank, marketplace, healthcare provider or identity vendor can describe proofing, authentication and federation requirements using IAL, AAL and FAL rather than relying on vague claims such as “verified” or “secure.”
It also helps teams distinguish legitimate assurance needs from unnecessary friction. Referencing NIST does not itself establish legal compliance, guarantee fraud prevention or replace sector-specific rules. But its risk-based structure, public development process and detailed technical guidance make it a common baseline for evaluating identity controls, vendor capabilities and audit evidence.