Skip to main content
Category: Compliance Frameworks & Standards

NIST SP 800-63

Also known as: SP 800-63, NIST SP 800-63 Digital Identity Guidelines, Digital Identity Guidelines, SP 800-63-3, SP 800-63-4
Simply put

NIST SP 800-63 is a set of U.S. government guidelines that explains how to confirm a person's digital identity and how they should securely log in to online systems. It covers how organizations verify who someone is, how they prove their identity when signing in, and how identity information is shared between systems. It exists as a multi-volume suite that is periodically revised, with SP 800-63-3 being an earlier edition and SP 800-63-4 a more recent version.

Formal definition

NIST Special Publication 800-63, the Digital Identity Guidelines, is a multi-volume publication suite that specifies process and technical requirements for meeting digital identity assurance levels across three domains: identity proofing (Identity Assurance Levels), authentication (Authenticator Assurance Levels), and federation/assertions (Federation Assurance Levels). Volume 800-63B defines technical requirements for the three authenticator assurance levels, addressing authentication of subjects interacting with information systems over networks. The suite has been issued in successive revisions, SP 800-63-3 and the later SP 800-63-4, with newer versions superseding corresponding prior publications; practitioners should reference the specific revision and volume (e.g., 800-63A, 800-63B, 800-63C) applicable to their environment, as requirements differ between editions.

Why it matters

Digital identity is one of the most common points of failure in security programs, because weak identity proofing and authentication practices are frequently exploited to gain unauthorized access. NIST SP 800-63 matters because it provides a structured, government-backed way to reason about identity assurance rather than treating authentication as a single yes-or-no decision. By separating identity proofing, authentication, and federation into distinct assurance levels, the guidelines give organizations a vocabulary for matching identity controls to the actual risk of a given system or transaction.

For security leaders, the practical value is that SP 800-63 turns abstract goals like "stronger login security" into specific, defensible requirements tied to defined assurance levels. This is useful when justifying controls to executives, aligning with auditors, or designing systems that must interoperate across organizational boundaries through federation. Because the suite is periodically revised, with SP 800-63-3 being an earlier edition and SP 800-63-4 a more recent one, understanding which revision and volume applies prevents an organization from designing to outdated or mismatched requirements.

It is important to be clear about scope. SP 800-63 is a set of guidelines for digital identity assurance; it does not by itself certify an organization or guarantee that authentication will never be defeated. Its value depends on correct interpretation, appropriate assurance-level selection for the risk involved, and consistent implementation. A virtual CISO advising on these guidelines helps an organization choose and document the right assurance levels, but accountability for the resulting identity decisions remains with the client organization.

Who it's relevant to

Security and identity program leaders
For CISOs and virtual CISOs, SP 800-63 provides a framework for selecting and documenting identity proofing, authentication, and federation assurance levels appropriate to organizational risk. A vCISO in this context typically advises on which volumes and revision apply and how to align identity controls with them, while accountability for the resulting decisions remains with the client organization.
Organizations building or federating access to online systems
Teams designing how users prove their identity, sign in, and share identity assertions between systems can use SP 800-63's separation of identity proofing, authentication, and federation to match controls to risk. The federation volume is particularly relevant where identity information must be shared across organizational or system boundaries.
Organizations interacting with U.S. government information systems
Because the guidelines address the authentication of subjects who interact with government information systems over networks, entities that connect to or support such systems have a direct interest in meeting the relevant authenticator assurance level requirements defined in the applicable volume and revision.
Compliance, audit, and governance stakeholders
Auditors and governance teams benefit from the defined assurance levels as a basis for evaluating identity controls. It is important to note that following SP 800-63 supports readiness and provides defensible criteria, but it does not by itself constitute a certification, and its effectiveness depends on correct selection of the applicable revision and volume.

Inside SP 800-63

Identity Assurance Level (IAL)
A classification, described in the enrollment and proofing volume (commonly 800-63A), that indicates the rigor of the identity-proofing process used to establish that a person is who they claim to be. Higher levels typically require stronger evidence and verification.
Authenticator Assurance Level (AAL)
A classification, addressed in the authentication volume (commonly 800-63B), that indicates the strength of the authentication process, including factors and mechanisms used at login. Higher levels typically call for stronger and multi-factor authentication.
Federation Assurance Level (FAL)
A classification, addressed in the federation volume (commonly 800-63C), that describes the strength and protection of assertions used when identity is shared across federated systems.
Multi-volume structure
The guidance is organized into a base volume plus companion volumes covering enrollment and proofing, authentication and lifecycle management, and federation and assertions, allowing organizations to reference the relevant portion for their needs.
Revision lineage
The publication has multiple revisions, such as the version that introduced the separated IAL, AAL, and FAL model and a later revision that updated the guidance; the applicable revision may vary by organization and obligation.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-63.

Does NIST SP 800-63 still require organizations to enforce periodic password expiration and complex character rules?
This is a common misconception. NIST SP 800-63, particularly the digital identity guidelines addressing authentication (historically SP 800-63B), moved away from mandating routine periodic password changes and prescriptive composition rules such as forced special characters. The guidance instead emphasizes screening passwords against known compromised or common values, supporting longer passphrases, and avoiding practices that push users toward predictable patterns. A virtual CISO typically clarifies that adopting the guidelines often means revising legacy password policies rather than layering on additional complexity requirements. Note that guidance evolves across revisions, so organizations should confirm the specific language in the version they are aligning to.
Is NIST SP 800-63 a law or regulation that my organization is legally required to follow?
Not directly for most private organizations. NIST SP 800-63 is a set of guidelines published by the National Institute of Standards and Technology, and its purpose is to provide technical requirements and recommendations for digital identity services, including identity proofing, authentication, and federation. It becomes mandatory primarily for U.S. federal agencies and, by extension, some contractors, and it may be referenced within other frameworks or contractual obligations. For many private-sector organizations, it functions as an authoritative reference rather than a binding regulation. A virtual CISO can advise on where it applies to your specific obligations, but accountability for determining regulatory applicability generally remains with the client organization and its officers.
Which version of NIST SP 800-63 should we align to, given that both 800-63-3 and 800-63-4 are referenced?
The publication has been issued in multiple revisions, with SP 800-63-3 being a widely referenced revision and SP 800-63-4 representing a subsequent update to the digital identity guidelines. The appropriate version often depends on contractual requirements, the version cited by any regulator or partner you must satisfy, and where NIST stands in its revision lifecycle at the time of your work. In many engagements, a virtual CISO helps confirm which revision applies to your obligations and identifies where the two differ so that policy and control decisions reference the correct baseline. Because revisions can change specific requirements, this should be verified against current NIST publications rather than assumed.
How does a virtual CISO typically support alignment with NIST SP 800-63 without performing hands-on implementation?
A virtual CISO generally provides strategy, governance, and program direction rather than executing operational tasks. In the context of SP 800-63, this often includes assessing current identity proofing and authentication practices against the guidelines, advising on target assurance levels, helping define policy, and prioritizing a roadmap. Hands-on activities such as configuring identity providers, deploying multi-factor authentication tooling, or administering directory services are typically out of scope unless explicitly contracted, and are usually performed by internal staff, integrators, or managed service providers under the vCISO's guidance.
What organizational factors affect how successfully we can adopt the SP 800-63 assurance levels?
Adoption value often depends on organizational maturity, stakeholder cooperation, and clearly defined scope. The guidelines organize requirements around assurance levels for identity proofing, authentication, and federation, and selecting appropriate levels requires understanding your risk tolerance, user populations, and the systems in scope. In many engagements, progress depends on access to identity and access management stakeholders, existing tooling capabilities, and willingness to revise legacy policies. A virtual CISO can direct this work, but decisions on assurance levels and resulting risk acceptance typically remain the responsibility of the client organization.
Does aligning with NIST SP 800-63 guarantee compliance with regulations like HIPAA or PCI DSS?
No. Aligning with SP 800-63 addresses digital identity practices, but it does not by itself establish compliance with broader regulations or standards such as HIPAA or PCI DSS, which have their own distinct requirements. In some cases, strong identity and authentication practices support readiness for control objectives within those frameworks, but readiness is not the same as certification or attestation. A virtual CISO can help map where SP 800-63 practices contribute to other obligations while being clear that meeting one guideline does not assert compliance with another.

Common misconceptions

SP 800-63 is a law that all organizations must follow.
It is a guideline published by NIST, aimed primarily at U.S. federal agencies. Private-sector organizations often adopt it voluntarily or by contractual reference, but it is not itself a universally binding legal mandate. Applicability may vary by organization and context.
Following SP 800-63 guarantees certification or compliance with other frameworks.
Aligning with SP 800-63 supports strong identity and authentication practices, but it does not by itself constitute certification. A virtual CISO can help support readiness against relevant assurance levels, but achieving or asserting compliance with other frameworks or certifications requires separate, distinct efforts.
IAL, AAL, and FAL are the same thing or must all be set to the same level.
These are distinct assurance categories covering identity proofing, authentication strength, and federation respectively. They can be selected independently based on risk, and setting one high level does not require the others to match.

Best practices

Confirm which revision of SP 800-63 applies to your organization or obligations, since terminology and requirements can differ between versions such as the 800-63-3 and 800-63-4 lineages.
Select IAL, AAL, and FAL independently based on the specific risk of each identity, authentication, and federation scenario rather than applying a single blanket level.
Treat SP 800-63 as guidance that supports readiness rather than as a guarantee of certification or legal compliance, and confirm separately how it maps to other frameworks relevant to you.
Engage a virtual CISO or security leader to interpret the assurance levels and advise on program direction, while keeping accountability for identity decisions with the client organization and its officers.
Document how chosen assurance levels are implemented and reviewed, recognizing that value depends on organizational maturity, stakeholder cooperation, and clearly defined scope.
Distinguish advisory guidance from operational execution; a vCISO typically directs identity strategy and governance but generally does not perform hands-on authentication administration unless explicitly contracted.