NIST SP 800-63
NIST SP 800-63 is a set of federal guidelines that explain how to verify who someone is and confirm their identity when they access government information systems online. It is published by the National Institute of Standards and Technology (NIST) and is organized as a multi-volume suite covering identity proofing, authentication, and related processes. The reader should consult the current official text, because the guidelines have been issued in successive revisions.
NIST Special Publication 800-63, Digital Identity Guidelines, is a NIST-issued document suite that presents the process and technical requirements for meeting digital identity assurance levels for identity proofing and authentication. In the 800-63-3 series it is structured as a four-volume suite, with volume SP 800-63B focusing on the authentication of subjects who interact with government information systems over networks and defining technical requirements across authenticator assurance levels. As of the applicable revision, the guidelines have been updated (for example, the 800-63-4 series and superseded prior editions such as SP 800-63B updates), so practitioners should verify which revision and volume apply to their environment. This entry does not address agency-specific tailoring, contractual, or implementation specifics, which must be confirmed against the current authoritative NIST text.
Why it matters
Digital identity is the front door to nearly every government information system, and getting it wrong undermines every downstream control. NIST SP 800-63 matters because it establishes the federal reference point for how agencies and their service providers verify who a person claims to be (identity proofing) and confirm that the person accessing a system is that same individual (authentication). When these processes are weak, an attacker who impersonates a legitimate user can bypass otherwise robust security architectures, which is why identity assurance is treated as a foundational element rather than an add-on.
The guidelines are organized around graduated assurance levels, allowing agencies to match the rigor of proofing and authentication to the sensitivity of the transaction or system. This risk-based framing helps organizations avoid two common failures: applying weak identity controls to high-consequence systems, and imposing burdensome verification on low-risk interactions. Because the suite is issued in successive revisions and structured across multiple volumes, practitioners should be careful to confirm which edition and which volume govern their environment rather than relying on a general familiarity with "800-63."
It is also worth noting a common misconception: adopting SP 800-63 is not the same as being secure, and identity assurance is only one component of a broader security and authorization posture. The guidelines address the process and technical requirements for digital identity, but they do not, by themselves, resolve agency-specific tailoring, contractual obligations, or implementation details, all of which must be confirmed against the current authoritative NIST text.
Who it's relevant to
Inside SP 800-63
Common questions
Answers to the questions practitioners most commonly ask about SP 800-63.