What is NIST 800-63? | Transmit Security

Glossary

What is NIST 800-63?

NIST 800-63 is the US government’s Digital Identity Guidelines defining standards for identity proofing, authentication, and federation. Learn what it covers.
by Transmit Security

NIST Special Publication 800-63, the Digital Identity Guidelines, is the US National Institute of Standards and Technology’s framework defining requirements for identity proofing, authentication, and federation, organized around measurable assurance levels. Though written for US federal agencies, it’s become a globally referenced benchmark for how to do digital identity rigorously.

When practitioners argue about "how strong is strong enough" for verification or authentication, NIST 800-63 is usually the reference they reach for. It provides the shared vocabulary and the assurance-level scaffolding much of the industry uses.

The structure of 800-63

The guidance is split into components, each with its own assurance scale:

  • 800-63A, identity proofing, defining identity assurance levels (IAL1–IAL3): how rigorously the real-world identity is established.
  • 800-63B, authentication, defining authentication assurance levels (AAL1–AAL3): how strong the authentication is, including guidance favoring phishing-resistant methods.
  • 800-63C, federation, defining federation assurance levels (FAL): how trust is conveyed between an identity provider and a relying party.

What it says about modern authentication

NIST 800-63 has evolved with the threat landscape. Recent guidance discourages SMS-based OTP for higher assurance, emphasizes phishing-resistant authentication (aligned with FIDO2/passkeys) at the highest levels, and moved away from outdated advice like forced periodic password changes. It reflects the same direction the whole field is heading: away from shared secrets, toward possession- and biometric-based, phishing-resistant methods.

Why it matters beyond government

Because it’s rigorous, public, and regularly updated, 800-63 is widely adopted as a benchmark by private-sector organizations and referenced in other regulations and standards. Aligning identity proofing and authentication to its assurance levels gives businesses a defensible, recognized basis for their controls: useful for audits, procurement, and demonstrating due diligence. For vendors and buyers alike, "meets IAL2/AAL2" is a common shorthand grounded in this document.

How the guidance has evolved

NIST 800-63 is notable for moving with the threat landscape rather than ossifying. Earlier security folklore it helped retire includes forced periodic password changes and complex composition rules, practices later shown to push users toward weaker, predictable passwords. More recent revisions lean hard toward phishing-resistant authentication, aligning the highest assurance levels with FIDO2/passkey-style methods and steering away from SMS-based one-time passwords for higher assurance. On the proofing side, the guidance has grappled with remote identity proofing and the rising threat of fraud and deepfakes against it.

The practical value for businesses is that aligning to current 800-63 guidance gives a defensible, up-to-date basis for identity decisions, one that reflects where attacks actually are, not where they were a decade ago. Because the document is public and regularly updated, it functions as a shared reference that regulators, auditors, and vendors all recognize. "We meet IAL2 and AAL2" communicates a specific, verifiable bar far better than a vague claim of being "secure," which is much of why the framework is referenced so widely beyond its original government audience.

Frequently asked questions

What is NIST 800-63?

The US Digital Identity Guidelines defining standards for identity proofing, authentication, and federation.

What are its main parts?

800-63A (proofing/IAL), 800-63B (authentication/AAL), and 800-63C (federation/FAL).

Does NIST 800-63 apply outside the US government?

It’s written for federal agencies but widely used globally as a benchmark by private organizations.

What does it say about passwords and SMS?

It favors phishing-resistant authentication and discourages SMS OTP for higher assurance.

What’s the difference between IAL, AAL, and FAL?

IAL measures proofing strength, AAL measures authentication strength, and FAL measures how securely identity is federated between systems.

Related: Identity Assurance Levels (IAL) · Identity Proofing · Authentication · Passkeys · FIDO2

Request a Demo

By clicking the button, you agree to the Terms and Conditions