Authenticator Assurance Level
Authenticator Assurance Level (AAL) is a classification that describes how much confidence a system can have that the person logging in actually controls the credential tied to their account. Higher levels generally require stronger authentication methods, such as combining multiple factors. It is defined in NIST Special Publication 800-63B, and the specific requirements at each level should be verified against the current revision.
AAL is a NIST-defined measure, established in the SP 800-63B Digital Identity Guidelines, that categorizes the strength and reliability of an authentication process by which a claimant demonstrates control of one or more authenticators bound to a subscriber account. As described in the evidence, AAL1 provides basic confidence that the claimant controls a bound authenticator and generally permits single-factor authentication using a range of authenticator types enumerated in SP 800-63B. Higher levels (commonly referenced as AAL2 and AAL3) impose progressively stronger requirements, which in practice may include multi-factor and phishing-resistant authentication; practitioners should confirm the precise requirements, authenticator options, and level definitions against the applicable revision of SP 800-63B, as this terminology and the associated criteria have evolved across versions. Note that AAL addresses authentication strength specifically and is distinct from identity proofing assurance and federation assurance concepts within the broader NIST digital identity framework; agency tailoring and compliance context may affect which AAL applies.
Why it matters
Authenticator Assurance Level matters because it gives agencies and their contractors a common, standardized way to reason about how much trust to place in an authentication event, rather than relying on ad hoc judgments about password strength or login methods. In defense and public sector contexts, the AAL selected for a given system helps determine whether single-factor authentication is acceptable or whether multi-factor and phishing-resistant methods are needed. Because higher levels generally impose progressively stronger requirements, choosing the appropriate AAL is a risk decision tied to the sensitivity of the system and the information it handles.
A common expert correction is that AAL addresses authentication strength specifically and should not be conflated with identity proofing assurance (how confidently a person's real-world identity was verified) or federation assurance within the broader NIST digital identity framework. Meeting a given AAL does not by itself establish that the subscriber's identity was rigorously proofed, nor does it substitute for the other assurance dimensions an authorizing official may need to consider. Practitioners should also remember that AAL requirements and authenticator options have evolved across revisions of SP 800-63B, so a control considered compliant under one version may not map cleanly to another.
Because guidance such as recommendations to meet at least AAL2 with phishing resistance, and AAL3 where business, industry, or compliance drivers require it, depends on the applicable revision and on agency tailoring, teams should verify the precise requirements against the current authoritative text of SP 800-63B rather than assuming a fixed definition. Selecting an AAL is best treated as a documented, defensible decision within a system's overall risk and compliance posture.
Who it's relevant to
Inside AAL
Common questions
Answers to the questions practitioners most commonly ask about AAL.