Identity Assurance Level
An Identity Assurance Level (IAL) is a rating that describes how confident an organization can be that a person is who they claim to be, based on how thoroughly their identity was checked when they first enrolled or registered. Higher levels reflect stronger identity proofing and greater confidence that a claimed identity matches a real person. IALs are defined by the National Institute of Standards and Technology (NIST) and are commonly used by federal agencies as part of assessing digital identity risk.
The Identity Assurance Level (IAL) is a category defined by NIST that conveys the degree of confidence that an applicant's claimed identity corresponds to their real identity, based on the rigor of the identity proofing process performed at enrollment. Under NIST SP 800-63, IAL is one of several distinct assurance components an agency selects when evaluating digital identity risk; for non-federated systems, SP 800-63-3 directs agencies to select an IAL together with an Authenticator Assurance Level (AAL), with the Federation Assurance Level (FAL) applying to federated scenarios. IAL is scoped specifically to identity proofing and enrollment confidence and should not be conflated with authentication strength (AAL) or federation assurance (FAL). NIST SP 800-63-3 establishes three defined levels, IAL1 (some confidence), IAL2 (high confidence), and IAL3 (very high, in-person or supervised remote proofing), and practitioners should confirm the exact level definitions and requirements against the applicable revision of the standard. Note that NIST issued SP 800-63-4 as a later revision that supersedes SP 800-63-3; readers should verify which revision governs their systems and consult the current authoritative NIST text, as level definitions, terminology, and requirements may differ across revisions and agency tailoring.
Why it matters
Identity Assurance Level matters because it isolates a specific and often underappreciated dimension of digital identity risk: how confident an organization can be that a claimed identity actually belongs to a real person, based on the rigor of identity proofing performed at enrollment. Many access-related failures originate not at the point of authentication but at the point of registration, when a weakly proofed identity is admitted into a system. By defining discrete levels, IAL1 (some confidence), IAL2 (high confidence), and IAL3 (very high confidence, involving in-person or supervised remote proofing), NIST gives agencies a structured way to match the strength of identity proofing to the sensitivity and risk of the transaction or resource being protected.
A common and consequential mistake is treating identity proofing (IAL) as interchangeable with authentication strength (AAL) or federation assurance (FAL). Under NIST SP 800-63-3, these are deliberately separated so that agencies can select each component according to its own risk analysis rather than assuming a single blanket 'assurance level.' Strong authenticators do not compensate for a weak or unverified enrollment, and a rigorously proofed identity can still be undermined by weak authentication. Compliance and security teams that conflate these components risk both over-engineering low-risk services and under-protecting high-risk ones.
Because IAL definitions, terminology, and requirements are anchored to a specific revision of NIST SP 800-63, practitioners must confirm which revision governs their systems. NIST issued SP 800-63-4 as a later revision that supersedes SP 800-63-3, and level definitions or requirements may differ across revisions and agency tailoring. Selecting an IAL is therefore not a one-time labeling exercise but a decision that must be revalidated against the current authoritative NIST text and any agency-specific implementation guidance.
Who it's relevant to
Inside IAL
Common questions
Answers to the questions practitioners most commonly ask about IAL.