FIPS 201
FIPS 201 is a U.S. federal government standard, maintained by NIST, that defines how federal employees and contractors are issued secure identity credentials. These credentials, known as Personal Identity Verification (PIV) cards, are used to prove who a person is when accessing federal facilities and information systems. The standard is periodically revised, with FIPS 201-3 being the version issued in January 2022.
FIPS 201 is a Federal Information Processing Standard issued and maintained by NIST that establishes requirements for a Personal Identity Verification (PIV) system for federal employees and contractors. It specifies the credentials, controls, and security objectives associated with issuing and using PIV credentials for identity assurance in physical and logical access. As of the applicable revision, FIPS 201-3 (issued January 24, 2022) is the current version and introduced federation requirements, among other updates; practitioners should verify the current authoritative text and associated NIST Special Publication guidance (such as the SP 800-73, 800-76, and 800-78 series) for detailed implementation specifics, which are out of scope for this definition.
Why it matters
FIPS 201 underpins one of the most widely deployed identity assurance mechanisms across the U.S. federal government: the Personal Identity Verification (PIV) card. Because the standard establishes a common set of requirements for issuing and using credentials that prove the identity of federal employees and contractors, it enables consistent, government-wide approaches to both physical access (entering federal facilities) and logical access (authenticating to federal information systems). For compliance officers and security managers, a credential grounded in FIPS 201 provides a high-assurance, interoperable basis for identity that is difficult to achieve with agency-specific or ad hoc credentialing schemes.
The standard also matters because identity is foundational to nearly every other security control. Access decisions, audit trails, and accountability all depend on reliably establishing who a person is, and FIPS 201 is the reference point that federal identity, credential, and access management programs generally align to. As of the applicable revision, FIPS 201-3 (issued January 24, 2022) introduced federation requirements, reflecting an evolution toward supporting identity assertions across systems and organizational boundaries rather than relying solely on the physical card. Organizations tracking the standard's revisions should treat compliance as tied to a specific version and verify which revision applies to their obligations.
A common expert caution is to avoid conflating possession of a PIV credential with comprehensive security. FIPS 201 addresses identity credentialing; it is not a complete access control, monitoring, or authorization program. The detailed implementation requirements live in associated NIST Special Publication guidance (such as the SP 800-73, 800-76, and 800-78 series), and readers should confirm the current authoritative text rather than assume that holding a compliant credential satisfies all applicable requirements.
Who it's relevant to
Inside FIPS 201
Common questions
Answers to the questions practitioners most commonly ask about FIPS 201.