NIST SP 800-63
NIST SP 800-63 is a set of U.S. government guidelines that explains how to confirm a person's digital identity and how they should securely log in to online systems. It covers how organizations verify who someone is, how they prove their identity when signing in, and how identity information is shared between systems. It exists as a multi-volume suite that is periodically revised, with SP 800-63-3 being an earlier edition and SP 800-63-4 a more recent version.
NIST Special Publication 800-63, the Digital Identity Guidelines, is a multi-volume publication suite that specifies process and technical requirements for meeting digital identity assurance levels across three domains: identity proofing (Identity Assurance Levels), authentication (Authenticator Assurance Levels), and federation/assertions (Federation Assurance Levels). Volume 800-63B defines technical requirements for the three authenticator assurance levels, addressing authentication of subjects interacting with information systems over networks. The suite has been issued in successive revisions, SP 800-63-3 and the later SP 800-63-4, with newer versions superseding corresponding prior publications; practitioners should reference the specific revision and volume (e.g., 800-63A, 800-63B, 800-63C) applicable to their environment, as requirements differ between editions.
Why it matters
Digital identity is one of the most common points of failure in security programs, because weak identity proofing and authentication practices are frequently exploited to gain unauthorized access. NIST SP 800-63 matters because it provides a structured, government-backed way to reason about identity assurance rather than treating authentication as a single yes-or-no decision. By separating identity proofing, authentication, and federation into distinct assurance levels, the guidelines give organizations a vocabulary for matching identity controls to the actual risk of a given system or transaction.
For security leaders, the practical value is that SP 800-63 turns abstract goals like "stronger login security" into specific, defensible requirements tied to defined assurance levels. This is useful when justifying controls to executives, aligning with auditors, or designing systems that must interoperate across organizational boundaries through federation. Because the suite is periodically revised, with SP 800-63-3 being an earlier edition and SP 800-63-4 a more recent one, understanding which revision and volume applies prevents an organization from designing to outdated or mismatched requirements.
It is important to be clear about scope. SP 800-63 is a set of guidelines for digital identity assurance; it does not by itself certify an organization or guarantee that authentication will never be defeated. Its value depends on correct interpretation, appropriate assurance-level selection for the risk involved, and consistent implementation. A virtual CISO advising on these guidelines helps an organization choose and document the right assurance levels, but accountability for the resulting identity decisions remains with the client organization.
Who it's relevant to
Inside SP 800-63
Common questions
Answers to the questions practitioners most commonly ask about SP 800-63.