NIST SP 800-63 Digital Identity Guidelines
NIST SP 800-63 is a set of U.S. government guidelines that explain how organizations should verify who someone is online and confirm they are who they claim to be when logging in. It covers proving identity, managing login credentials, and authenticating users at different levels of confidence. The most current version is SP 800-63-4, which became effective August 1, 2025 and replaced the earlier SP 800-63-3 revision.
NIST SP 800-63 is a multi-volume Special Publication defining the process and technical requirements for meeting digital identity assurance levels across identity proofing, enrollment, authenticators, credential management, authentication, and federation. It specifies distinct assurance levels, including authenticator assurance levels detailed in SP 800-63B, each with associated technical requirements. SP 800-63-4 (finalized 2025) is the current revision and supersedes SP 800-63-3 as of August 1, 2025. As a set of guidelines, it establishes requirements and criteria that organizations can implement, but it is not itself a certification; the earlier revision noted here is retained only for historical reference to the current version.
Why it matters
Digital identity is a foundational control for nearly every security program. Before an organization can protect data, enforce access policies, or meet regulatory obligations, it must be able to answer two questions with confidence: is this person who they claim to be, and are they the same person who was originally enrolled? NIST SP 800-63 provides a structured, tiered way to answer those questions, defining assurance levels for identity proofing, authentication, and federation so that organizations can match the rigor of their identity controls to the risk of the systems being accessed.
The move from SP 800-63-3 to SP 800-63-4, which became effective August 1, 2025, matters because it establishes the current baseline that U.S. federal agencies and many organizations in regulated or federal-adjacent sectors reference when designing identity and access management programs. Organizations that built controls against the prior revision may need to reassess whether their identity proofing, credential management, and authentication practices still align with the current guidance. Treating the guidelines as a living reference rather than a one-time checklist helps avoid drift between documented policy and actual practice.
It is important to be precise about what SP 800-63 is and is not. It is a set of guidelines defining requirements and criteria that organizations can implement; it is not itself a certification, and adopting it does not guarantee any particular compliance or security outcome. The value of applying it depends heavily on organizational maturity, accurate scoping of which systems require which assurance levels, and disciplined implementation. Security leaders should resist the temptation to claim a system 'meets 800-63' without specifying which volume, which assurance level, and which requirements are actually satisfied.
Who it's relevant to
Inside SP 800-63
Common questions
Answers to the questions practitioners most commonly ask about SP 800-63.