NIST SP 800-63 Digital Identity Guidelines
We help organizations align with NIST SP 800-63 (IAL, AAL, FAL) requirements and prepare for Kantara Initiative conformance where needed. Our work covers 800-63A (identity proofing), 800-63B (authentication), and 800-63C (federation) across both Revision 3 and the final Revision 4 suite released in July 2025 — as readiness support, not official certification.
Common reasons teams come to us
- A government or regulated relying party requires a specific IAL, AAL, or FAL level.
- A Kantara Initiative conformance assessment is on the horizon and scope is unclear.
- Identity proofing (800-63A) workflows have never been formally reviewed against NIST guidance.
- Authenticator, session, and MFA design (800-63B) needs to move beyond ad-hoc decisions.
- Federation, assertions, and SSO (800-63C) span multiple partners and need a coherent security review.
- The team wants to align FIDO2, OIDC, and SAML choices to 800-63 assurance targets.
Talk through your scope, timeline, and customer pressure on a 30-minute call.
- Identity providers (IdPs) and credential service providers (CSPs)
- Federation partners integrating with government or regulated relying parties
- SaaS, fintech, payments, and health-tech IdPs aligning to 800-63 assurance levels
- Regulated B2B teams asked for a specific IAL, AAL, or FAL by a customer
- Teams preparing for a Kantara Initiative conformance assessment
- Target IAL (Identity Assurance Level), AAL (Authenticator Assurance Level), and FAL (Federation Assurance Level) selection
- Gap assessment against NIST SP 800-63-3 and the final SP 800-63-4 suite (July 2025)
- Identity proofing workflow review (800-63A)
- Authenticator, session, and MFA design review (800-63B)
- Federation, assertion, and SSO design review (800-63C)
- Kantara Initiative conformance readiness and evidence preparation
- Alignment with adjacent identity standards (FIDO2, OIDC, SAML)
What 800-63 readiness covers
Assurance-level targeting
Select realistic IAL, AAL, and FAL levels based on relying-party and regulatory needs.
Identity proofing (800-63A)
Review remote and in-person proofing workflows, evidence, and fraud controls.
Authentication (800-63B)
Authenticators, sessions, MFA, recovery, and re-authentication design review.
Federation (800-63C)
Assertion, SSO, and federation architecture review across OIDC and SAML partners.
Kantara conformance readiness
Scope, control mapping, and evidence preparation for a Kantara Initiative assessment.
Adjacent identity standards
Alignment with FIDO2, OIDC, and SAML choices so the identity stack tells one story.
Relying party asking for a specific IAL, AAL, or FAL?
We map your current identity stack to the target assurance levels, surface the real gaps, and give engineering a prioritized remediation plan.
- Target the right assurance levels for your relying parties and use cases
- Enter a Kantara conformance assessment with scope, controls, and evidence organized
- Reduce identity-related risk of account takeover and federation abuse
- Give regulated buyers a clear, standards-based identity posture
- Digital identity scope and assurance-level target
- Gap assessment across 800-63A, 800-63B, and 800-63C
- Remediation roadmap for identity proofing, authentication, and federation
- Kantara conformance evidence plan
A clear path from scope to remediation
- 01
Scope
Identify identity flows, relying parties, users, and target IAL / AAL / FAL.
- 02
Assess
Gap assessment against NIST SP 800-63 A, B, and C.
- 03
Design
Recommend proofing, authenticator, session, and federation improvements.
- 04
Remediate
Advisory support while engineering closes identity gaps.
- 05
Prepare
Organize evidence and support a Kantara Initiative conformance assessment when needed — we provide readiness support, not official certification.
Explore other ControlSolid services
SOC 2 Readiness
SOC 2 readiness for SaaS teams — Trust Services Criteria gap assessment, policy and control build-out, evidence library, and audit-ready handoff.
Learn more →ISO 27001
ISO 27001 consulting and ISMS build-out — Annex A control mapping, risk assessment, statement of applicability, and certification-ready evidence.
Learn more →- ControlSolid home →Overview of readiness, advisory, and assessment services.
- Application & cloud security reviews →Architecture and threat modeling for identity providers and federation partners.
- Security assessments & gap analysis →Broader control review that complements 800-63 identity-specific work.
- SOC 2 Type 1 & Type 2 readiness →Common companion for CSPs and IdPs selling into enterprise buyers.
- vCISO & customer security reviews →Ongoing advisory and customer questionnaire support for regulated identity buyers.
- Guide: What NIST SP 800-63-4 changes →The practical differences from Rev 3 and how to prepare identity systems for Rev 4.
Questions we hear most
- What's the difference between IAL, AAL, and FAL?
- IAL (Identity Assurance Level) covers identity proofing — how confidently you tied a credential to a real person. AAL (Authenticator Assurance Level) covers authentication — how strongly you verify the person at each session. FAL (Federation Assurance Level) covers assertions passed to relying parties. NIST SP 800-63 lets you choose each level independently based on relying-party and regulatory needs.
- Do we need 800-63-4 now, or is Rev 3 still fine?
- NIST released the final SP 800-63-4 suite in July 2025, which supersedes Revision 3. Federal agencies and relying parties will move to Rev 4 on their own timelines; private-sector organizations should assess Rev 4 against their current architecture now and plan a transition, especially where identity proofing, phishing-resistant authenticators, and federation posture are changing.
- Can you help us prepare for a Kantara Initiative conformance assessment?
- Yes. We support scoping, control mapping across 800-63A/B/C, evidence preparation, and remediation ahead of a Kantara Initiative conformance assessment. Kantara Initiative issues the conformance decision itself — we provide readiness support, not the official certification.
- How does 800-63 relate to FIDO2, OIDC, and SAML?
- FIDO2, OIDC, and SAML are technology standards that implement pieces of the identity stack. NIST SP 800-63 defines assurance-level requirements those technologies need to satisfy. A common readiness output is a mapping of your FIDO2, OIDC, and SAML choices to specific 800-63 A, B, and C requirements so the identity architecture tells one coherent story.
- Who typically engages us for 800-63 readiness?
- Identity providers, credential service providers, federation operators, fintech and payments teams, health-tech IdPs, and regulated B2B SaaS selling into government-adjacent or heavily regulated buyers. Anyone who has been asked for a specific IAL/AAL/FAL target by a relying party is a good fit.
Need a clear view of your security gaps?
Start with a focused readiness call. We'll discuss your customer pressure, compliance goals, application risk, and the best next step.