Digital Identity

NIST SP 800-63 Digital Identity Guidelines

We help organizations align with NIST SP 800-63 (IAL, AAL, FAL) requirements and prepare for Kantara Initiative conformance where needed. Our work covers 800-63A (identity proofing), 800-63B (authentication), and 800-63C (federation) across both Revision 3 and the final Revision 4 suite released in July 2025 — as readiness support, not official certification.

Why teams engage us

Common reasons teams come to us

  • A government or regulated relying party requires a specific IAL, AAL, or FAL level.
  • A Kantara Initiative conformance assessment is on the horizon and scope is unclear.
  • Identity proofing (800-63A) workflows have never been formally reviewed against NIST guidance.
  • Authenticator, session, and MFA design (800-63B) needs to move beyond ad-hoc decisions.
  • Federation, assertions, and SSO (800-63C) span multiple partners and need a coherent security review.
  • The team wants to align FIDO2, OIDC, and SAML choices to 800-63 assurance targets.

Talk through your scope, timeline, and customer pressure on a 30-minute call.

Who it's for
  • Identity providers (IdPs) and credential service providers (CSPs)
  • Federation partners integrating with government or regulated relying parties
  • SaaS, fintech, payments, and health-tech IdPs aligning to 800-63 assurance levels
  • Regulated B2B teams asked for a specific IAL, AAL, or FAL by a customer
  • Teams preparing for a Kantara Initiative conformance assessment
What's included
  • Target IAL (Identity Assurance Level), AAL (Authenticator Assurance Level), and FAL (Federation Assurance Level) selection
  • Gap assessment against NIST SP 800-63-3 and the final SP 800-63-4 suite (July 2025)
  • Identity proofing workflow review (800-63A)
  • Authenticator, session, and MFA design review (800-63B)
  • Federation, assertion, and SSO design review (800-63C)
  • Kantara Initiative conformance readiness and evidence preparation
  • Alignment with adjacent identity standards (FIDO2, OIDC, SAML)
Coverage

What 800-63 readiness covers

Assurance-level targeting

Select realistic IAL, AAL, and FAL levels based on relying-party and regulatory needs.

Identity proofing (800-63A)

Review remote and in-person proofing workflows, evidence, and fraud controls.

Authentication (800-63B)

Authenticators, sessions, MFA, recovery, and re-authentication design review.

Federation (800-63C)

Assertion, SSO, and federation architecture review across OIDC and SAML partners.

Kantara conformance readiness

Scope, control mapping, and evidence preparation for a Kantara Initiative assessment.

Adjacent identity standards

Alignment with FIDO2, OIDC, and SAML choices so the identity stack tells one story.

Relying party asking for a specific IAL, AAL, or FAL?

We map your current identity stack to the target assurance levels, surface the real gaps, and give engineering a prioritized remediation plan.

Benefits
  • Target the right assurance levels for your relying parties and use cases
  • Enter a Kantara conformance assessment with scope, controls, and evidence organized
  • Reduce identity-related risk of account takeover and federation abuse
  • Give regulated buyers a clear, standards-based identity posture
Typical outputs
  • Digital identity scope and assurance-level target
  • Gap assessment across 800-63A, 800-63B, and 800-63C
  • Remediation roadmap for identity proofing, authentication, and federation
  • Kantara conformance evidence plan
Process

A clear path from scope to remediation

  1. 01

    Scope

    Identify identity flows, relying parties, users, and target IAL / AAL / FAL.

  2. 02

    Assess

    Gap assessment against NIST SP 800-63 A, B, and C.

  3. 03

    Design

    Recommend proofing, authenticator, session, and federation improvements.

  4. 04

    Remediate

    Advisory support while engineering closes identity gaps.

  5. 05

    Prepare

    Organize evidence and support a Kantara Initiative conformance assessment when needed — we provide readiness support, not official certification.

FAQ

Questions we hear most

What's the difference between IAL, AAL, and FAL?
IAL (Identity Assurance Level) covers identity proofing — how confidently you tied a credential to a real person. AAL (Authenticator Assurance Level) covers authentication — how strongly you verify the person at each session. FAL (Federation Assurance Level) covers assertions passed to relying parties. NIST SP 800-63 lets you choose each level independently based on relying-party and regulatory needs.
Do we need 800-63-4 now, or is Rev 3 still fine?
NIST released the final SP 800-63-4 suite in July 2025, which supersedes Revision 3. Federal agencies and relying parties will move to Rev 4 on their own timelines; private-sector organizations should assess Rev 4 against their current architecture now and plan a transition, especially where identity proofing, phishing-resistant authenticators, and federation posture are changing.
Can you help us prepare for a Kantara Initiative conformance assessment?
Yes. We support scoping, control mapping across 800-63A/B/C, evidence preparation, and remediation ahead of a Kantara Initiative conformance assessment. Kantara Initiative issues the conformance decision itself — we provide readiness support, not the official certification.
How does 800-63 relate to FIDO2, OIDC, and SAML?
FIDO2, OIDC, and SAML are technology standards that implement pieces of the identity stack. NIST SP 800-63 defines assurance-level requirements those technologies need to satisfy. A common readiness output is a mapping of your FIDO2, OIDC, and SAML choices to specific 800-63 A, B, and C requirements so the identity architecture tells one coherent story.
Who typically engages us for 800-63 readiness?
Identity providers, credential service providers, federation operators, fintech and payments teams, health-tech IdPs, and regulated B2B SaaS selling into government-adjacent or heavily regulated buyers. Anyone who has been asked for a specific IAL/AAL/FAL target by a relying party is a good fit.
Next step

Need a clear view of your security gaps?

Start with a focused readiness call. We'll discuss your customer pressure, compliance goals, application risk, and the best next step.