Skip to main content
Category: NIST Standards & Publications

FIPS 201

Also known as: FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors, FIPS 201-3
Simply put

FIPS 201 is a U.S. federal government standard, maintained by NIST, that defines how federal employees and contractors are issued secure identity credentials. These credentials, known as Personal Identity Verification (PIV) cards, are used to prove who a person is when accessing federal facilities and information systems. The standard is periodically revised, with FIPS 201-3 being the version issued in January 2022.

Formal definition

FIPS 201 is a Federal Information Processing Standard issued and maintained by NIST that establishes requirements for a Personal Identity Verification (PIV) system for federal employees and contractors. It specifies the credentials, controls, and security objectives associated with issuing and using PIV credentials for identity assurance in physical and logical access. As of the applicable revision, FIPS 201-3 (issued January 24, 2022) is the current version and introduced federation requirements, among other updates; practitioners should verify the current authoritative text and associated NIST Special Publication guidance (such as the SP 800-73, 800-76, and 800-78 series) for detailed implementation specifics, which are out of scope for this definition.

Why it matters

FIPS 201 underpins one of the most widely deployed identity assurance mechanisms across the U.S. federal government: the Personal Identity Verification (PIV) card. Because the standard establishes a common set of requirements for issuing and using credentials that prove the identity of federal employees and contractors, it enables consistent, government-wide approaches to both physical access (entering federal facilities) and logical access (authenticating to federal information systems). For compliance officers and security managers, a credential grounded in FIPS 201 provides a high-assurance, interoperable basis for identity that is difficult to achieve with agency-specific or ad hoc credentialing schemes.

The standard also matters because identity is foundational to nearly every other security control. Access decisions, audit trails, and accountability all depend on reliably establishing who a person is, and FIPS 201 is the reference point that federal identity, credential, and access management programs generally align to. As of the applicable revision, FIPS 201-3 (issued January 24, 2022) introduced federation requirements, reflecting an evolution toward supporting identity assertions across systems and organizational boundaries rather than relying solely on the physical card. Organizations tracking the standard's revisions should treat compliance as tied to a specific version and verify which revision applies to their obligations.

A common expert caution is to avoid conflating possession of a PIV credential with comprehensive security. FIPS 201 addresses identity credentialing; it is not a complete access control, monitoring, or authorization program. The detailed implementation requirements live in associated NIST Special Publication guidance (such as the SP 800-73, 800-76, and 800-78 series), and readers should confirm the current authoritative text rather than assume that holding a compliant credential satisfies all applicable requirements.

Who it's relevant to

Federal identity, credential, and access management (ICAM) program managers
Those responsible for issuing and managing identity credentials for federal employees and contractors rely on FIPS 201 as the governing standard for PIV credentialing. They should track which revision applies, including the federation requirements introduced in FIPS 201-3, and confirm details against the current authoritative text and associated NIST Special Publication guidance.
Information system security managers and physical security staff
Personnel who administer logical access to federal information systems and physical access to federal facilities use PIV credentials as an identity assurance mechanism. They should treat the credential as one element of an overall access control program rather than as complete security, and verify implementation specifics in the relevant SP 800-series guidance.
Government contractors and their compliance staff
Contractors whose personnel require PIV credentials to access federal facilities or systems are directly affected by FIPS 201 requirements. They should confirm the applicable revision and any agency-specific interpretations, and verify current contractual and credentialing obligations against official sources.
Compliance officers and auditors
Those assessing federal identity credentialing practices use FIPS 201 as the reference standard for PIV. Because the standard is periodically revised, assessors should anchor findings to the specific applicable version and not assume that a compliant credential alone satisfies broader access control, monitoring, or authorization requirements.

Inside FIPS 201

Personal Identity Verification (PIV) Standard
FIPS 201 is the Federal Information Processing Standard, issued by NIST, that establishes requirements for a common identity credential (the PIV card) for federal employees and contractors. It was issued in response to Homeland Security Presidential Directive 12 (HSPD-12), which directed a governmentwide standard for secure and reliable forms of identification.
Identity Proofing and Registration
The standard generally addresses the processes by which an applicant's identity is verified before a credential is issued, including background vetting requirements. Readers should confirm current proofing and vetting specifics against the applicable revision of the standard and associated NIST special publications.
PIV Card and Credential Elements
FIPS 201 describes the physical and logical characteristics of the PIV card, which in most implementations includes cryptographic keys, certificates, and biometric data used for authentication. The precise data elements and card topology are defined in the standard and its supporting technical publications, which the reader should verify against the current text.
Supporting NIST Special Publications
FIPS 201 is supported by a family of NIST Special Publications (such as the SP 800-73, SP 800-76, and SP 800-78 series) that provide technical detail on interfaces, biometric data, and cryptographic algorithms. The standard itself sets requirements while these companion documents cover implementation detail; consult the current versions for specifics.
Scope: Federal Personnel Identity
The standard is directed at credentialing federal employees and contractors for physical and logical access. It is an identity credentialing standard and does not by itself constitute a system security control baseline; it operates alongside frameworks such as FISMA and NIST SP 800-53 rather than replacing them.

Common questions

Answers to the questions practitioners most commonly ask about FIPS 201.

Does FIPS 201 issue or authorize the PIV credentials themselves?
No. FIPS 201 is a standard, published and maintained by NIST, that specifies the requirements for Personal Identity Verification (PIV) of federal employees and contractors. It defines the criteria for identity proofing, registration, and the credential, but it does not itself issue credentials or grant any authorization. Issuance is carried out by agency PIV issuing organizations operating in accordance with the standard, and readers should confirm current issuance policy against the applicable agency and OMB direction.
Is FIPS 201 the same thing as HSPD-12?
They are related but distinct. Homeland Security Presidential Directive 12 (HSPD-12) is the policy directive that called for a common, secure, and reliable identification standard for federal employees and contractors. FIPS 201 is the NIST technical standard developed in response to that directive. HSPD-12 establishes the policy mandate; FIPS 201 provides the standard implementing it. Confirm the current text of each against official sources, as supporting guidance evolves across revisions.
Does FIPS 201 apply to classified national security systems?
FIPS 201 addresses identity verification for federal employees and contractors in the context described by HSPD-12. Requirements for classified systems and national security systems may be governed by separate authorities and can differ in scope and applicability. Organizations should verify how FIPS 201 requirements are tailored or superseded for their specific system categorization against current authoritative guidance rather than assuming uniform applicability.
How does FIPS 201 relate to the NIST SP 800-73 and related special publications?
FIPS 201 is generally supported by a family of NIST Special Publications that provide the detailed technical specifications for implementing the standard, such as data model, interface, and cryptographic details. The FIPS itself sets the high-level requirements, while the associated SPs elaborate implementation specifics. Because these publications are revised over time, verify the current revision and the applicable companion documents before implementation.
What should an implementer check to confirm which revision of FIPS 201 applies?
Because FIPS 201 has been revised, and control and requirement details can change across revisions, implementers should confirm the current effective revision against the official NIST publication and any applicable OMB or agency direction. Do not assume that older implementation guidance or a prior revision remains authoritative; verify the applicable version for your program.
Does complying with FIPS 201 by itself satisfy an organization's broader security or authorization obligations?
No. FIPS 201 addresses identity verification and credentialing requirements; it does not by itself constitute overall system security or an authorization to operate. Compliance with an identity standard is one element within a broader control set and authorization process. Organizations should confirm how FIPS 201 requirements integrate with their applicable control baseline and authorization requirements against current authoritative sources.

Common misconceptions

FIPS 201 is a cybersecurity control baseline comparable to NIST SP 800-53 or SP 800-171.
FIPS 201 is an identity credentialing standard for the PIV card, issued by NIST under HSPD-12. It defines identity proofing and credential requirements, not a system-level control catalog. SP 800-53 (the control catalog) and SP 800-171 (protection of CUI in nonfederal systems) serve different purposes, and holding a PIV credential does not satisfy those separate requirements.
FIPS 201 and its PIV credential apply uniformly to all systems, including classified and non-federal environments.
The standard is generally directed at credentialing federal employees and contractors. National security systems, classified environments under the NISPOM, and state, local, tribal, and territorial obligations may have different or additional requirements. Readers should confirm applicability to their specific environment against current authoritative guidance.
Issuing a PIV card is a one-time event that permanently establishes trust.
Credentials are subject to lifecycle management, including revocation, renewal, and re-vetting, and possessing a valid credential is an authentication mechanism rather than a substitute for ongoing security or authorization processes. Compliance with FIPS 201 should not be equated with overall system security.

Best practices

Treat FIPS 201 as an identity credentialing standard and confirm the current revision and its supporting NIST Special Publications (such as the SP 800-73, SP 800-76, and SP 800-78 series) before implementation, since technical details evolve across revisions.
Verify applicability to your specific environment, distinguishing federal employee and contractor credentialing from national security systems, classified environments under the NISPOM, and any differing state, local, tribal, or territorial obligations.
Integrate PIV credentials into a broader security program rather than treating credential issuance alone as evidence of compliance or security; map PIV-based authentication to the relevant controls in your governing framework.
Implement lifecycle management for credentials, including timely revocation, renewal, and re-vetting, and do not assume an issued credential permanently establishes trust.
Coordinate identity proofing and vetting requirements with your organization's personnel security and authorizing processes, confirming vetting specifics against the applicable revision of the standard.
Consult the official NIST-issued text and supporting publications for precise data elements, algorithms, and interfaces rather than relying on summaries, and verify any citation before applying it in an authorization or contractual context.