Skip to main content
Category: NIST Standards & Publications

NIST SP 800-63

Also known as: SP 800-63, NIST SP 800-63 Digital Identity Guidelines, Digital Identity Guidelines
Simply put

NIST SP 800-63 is a set of federal guidelines that explain how to verify who someone is and confirm their identity when they access government information systems online. It is published by the National Institute of Standards and Technology (NIST) and is organized as a multi-volume suite covering identity proofing, authentication, and related processes. The reader should consult the current official text, because the guidelines have been issued in successive revisions.

Formal definition

NIST Special Publication 800-63, Digital Identity Guidelines, is a NIST-issued document suite that presents the process and technical requirements for meeting digital identity assurance levels for identity proofing and authentication. In the 800-63-3 series it is structured as a four-volume suite, with volume SP 800-63B focusing on the authentication of subjects who interact with government information systems over networks and defining technical requirements across authenticator assurance levels. As of the applicable revision, the guidelines have been updated (for example, the 800-63-4 series and superseded prior editions such as SP 800-63B updates), so practitioners should verify which revision and volume apply to their environment. This entry does not address agency-specific tailoring, contractual, or implementation specifics, which must be confirmed against the current authoritative NIST text.

Why it matters

Digital identity is the front door to nearly every government information system, and getting it wrong undermines every downstream control. NIST SP 800-63 matters because it establishes the federal reference point for how agencies and their service providers verify who a person claims to be (identity proofing) and confirm that the person accessing a system is that same individual (authentication). When these processes are weak, an attacker who impersonates a legitimate user can bypass otherwise robust security architectures, which is why identity assurance is treated as a foundational element rather than an add-on.

The guidelines are organized around graduated assurance levels, allowing agencies to match the rigor of proofing and authentication to the sensitivity of the transaction or system. This risk-based framing helps organizations avoid two common failures: applying weak identity controls to high-consequence systems, and imposing burdensome verification on low-risk interactions. Because the suite is issued in successive revisions and structured across multiple volumes, practitioners should be careful to confirm which edition and which volume govern their environment rather than relying on a general familiarity with "800-63."

It is also worth noting a common misconception: adopting SP 800-63 is not the same as being secure, and identity assurance is only one component of a broader security and authorization posture. The guidelines address the process and technical requirements for digital identity, but they do not, by themselves, resolve agency-specific tailoring, contractual obligations, or implementation details, all of which must be confirmed against the current authoritative NIST text.

Who it's relevant to

Information System Security Managers and System Owners
Those responsible for government information systems accessed over networks rely on SP 800-63 to determine appropriate identity proofing and authenticator assurance levels for their users. They should confirm which revision and volume apply to their environment and treat the guidelines as one input into a broader security and authorization posture rather than a complete security solution.
Identity, Credential, and Access Management (ICAM) Practitioners
Engineers and architects implementing authentication and identity proofing use the technical requirements defined across the authenticator assurance levels, particularly in the authentication-focused volume. Because newer editions supersede prior guidance, they should verify the technical requirements against the current authoritative NIST text before designing or updating controls.
Compliance Officers and Auditors
Personnel assessing whether an organization's digital identity practices align with federal expectations reference SP 800-63 as the governing guidance for identity assurance. They should confirm the applicable revision and note that the guidelines do not, on their own, address agency-specific tailoring, contractual, or implementation specifics that may govern a given system.
Government Contractors and Service Providers
Organizations delivering services that involve verifying and authenticating users of government systems may be expected to align with SP 800-63 assurance levels. They should verify which revision and volume apply through the relevant agency or contract and confirm requirements against current NIST publications rather than assuming a single edition applies universally.

Inside SP 800-63

Digital Identity Guidelines (overall publication)
NIST SP 800-63 is the NIST-maintained suite of Digital Identity Guidelines that establishes technical requirements and recommendations for digital identity services, including identity proofing, authentication, and federation. It is structured as a family of related volumes rather than a single document.
Identity Assurance Level (IAL)
Addresses the identity proofing process and the degree of confidence that an applicant's claimed identity is their real identity. The specific volume addressing this is generally referred to as the enrollment and identity proofing guidance within the suite.
Authenticator Assurance Level (AAL)
Addresses the authentication process and the strength of the mechanisms used to confirm that a claimant controls one or more authenticators bound to a subscriber account, covering topics such as multi-factor authentication.
Federation Assurance Level (FAL)
Addresses federated identity architectures and assertions, describing requirements for conveying authentication and attribute information between a credential service provider, a relying party, and other participants in a federation.
Risk-based selection of assurance levels
The guidelines generally support selecting IAL, AAL, and FAL independently based on risk to the agency, the individual, and the transaction, rather than applying a single combined level of assurance across all identity components.
Applicability and governance
The publication is issued and maintained by NIST and is commonly applied to U.S. federal agency systems. Readers should verify the current revision, as terminology and requirements have evolved across editions.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-63.

Does NIST SP 800-63 apply the same way to Department of Defense systems as it does to federal civilian agencies?
Not necessarily in the same manner. NIST SP 800-63 is maintained by NIST as digital identity guidance that federal civilian agencies generally reference under FISMA-related direction. DoD systems are authorized under the DoD RMF and may incorporate identity requirements through DoD-specific policy and tailoring, so you should not assume the guidance flows to defense systems identically. National security systems and classified environments under the NISPOM may follow separate identity requirements. Confirm applicability against the governing policy for your specific system type and agency, since interpretations and mandates vary.
If a service or credential meets a particular Authenticator Assurance Level, does that mean the overall system is compliant and secure?
No. Meeting an assurance level for one component addresses a specific dimension of digital identity, not overall compliance or security. NIST SP 800-63 generally separates identity assurance, authenticator assurance, and federation assurance as distinct constructs that are evaluated independently. Satisfying one does not establish that a system meets its full control baseline or that it is secure in practice. Compliance with identity guidance is one input to a broader risk determination, and it should be confirmed against the applicable control set and the current authoritative revision.
How do the assurance levels in NIST SP 800-63 relate to one another when selecting requirements?
The guidance generally organizes digital identity into separate components, identity proofing, authentication, and federation, each with its own assurance levels that can be selected independently based on risk. In most implementations, an organization assesses the risk associated with each component rather than assuming a single overall level applies across all of them. Because the specific levels, terminology, and criteria are defined in the applicable revision, verify the exact definitions and selection process against the current official publication before making determinations.
Which document should I treat as authoritative when implementing NIST SP 800-63?
The authoritative source is the NIST SP 800-63 publication itself, as maintained by NIST, in the revision applicable to your environment. Because the guidance has been issued in multiple revisions and its structure and terminology can change between them, confirm which revision your agency or governing policy requires. Where agency-specific direction supplements or tailors the guidance, that direction should be consulted alongside the NIST text. This entry does not substitute for the current official publication.
Is NIST SP 800-63 mandatory, or is it advisory guidance?
Whether it is binding depends on the policy that invokes it. NIST publications are frequently referenced by federal requirements, and their binding force generally derives from the statute, regulation, or agency policy that adopts them rather than from the publication alone. For that reason, treatment as mandatory versus advisory can differ across federal civilian, defense, and other environments. Verify how your specific governing authority incorporates the guidance before treating it as either required or optional.
How does NIST SP 800-63 fit alongside a control baseline such as NIST SP 800-53?
The two serve different but related roles. NIST SP 800-63 provides digital identity guidance, while NIST SP 800-53 provides a catalog of security and privacy controls; both are maintained by NIST. In many implementations, identity-related controls in a baseline are informed by the digital identity guidance, but the documents are not interchangeable and each applies according to its own scope. Confirm how your applicable baseline references identity requirements, and consult the current revisions of both publications rather than assuming a fixed mapping between them.

Common misconceptions

NIST SP 800-63 uses a single overall Level of Assurance (LOA) that applies to the whole identity process.
Current guidance generally decomposes assurance into separate components (identity proofing, authentication, and federation) so that IAL, AAL, and FAL can be selected independently based on risk, rather than assigning one combined LOA. Readers should confirm the terminology in the applicable revision.
NIST SP 800-63 is a security control catalog like NIST SP 800-53.
SP 800-63 is the NIST Digital Identity Guidelines focused specifically on identity proofing, authentication, and federation. It is a distinct publication from the SP 800-53 control catalog and does not replace it; the two are maintained separately and address different scopes.
Meeting SP 800-63 automatically satisfies broader compliance or authorization requirements such as an ATO.
Compliance with digital identity guidance addresses only the identity-related aspects of a system and does not by itself constitute a security authorization or demonstrate overall security. Authorization, continuous monitoring, and other applicable requirements must be met separately and verified against current authoritative sources.

Best practices

Select IAL, AAL, and FAL independently based on a documented risk assessment of the transaction, rather than defaulting to a single blanket assurance level.
Confirm which revision of NIST SP 800-63 applies to your program, since terminology and requirements have evolved across editions, and verify details against the current official NIST text.
Treat SP 800-63 as identity-specific guidance that complements, rather than replaces, broader NIST publications such as the SP 800-53 control catalog.
Do not assume that meeting digital identity requirements satisfies security authorization obligations; address ATO, continuous monitoring, and other requirements separately.
Distinguish clearly between identity proofing (IAL), authentication (AAL), and federation (FAL) when documenting and communicating requirements to stakeholders and assessors.
Validate agency-specific interpretations and any tailoring, since applicability and implementation details may differ across federal, defense, and non-federal contexts.