NIST SP 800-63-4
Authenticator Lifecycle Management

NIST SP 800-63-4 4: Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation

Manage authenticator lifecycle per NIST SP 800-63-4 Volume B Chapter 6. Binding per Section 6.1: bind authenticator to verified subscriber identity. Authenticator recovery per Section 6.2: post-loss recovery via re-proofing OR strong alternative evidence + alternative authenticator + risk-based controls. Authenticator replacement per Section 6.3. Authenticator expiration per Section 6.4 covering cryptographic key lifetime + biometric template freshness + memorised secret rotation policy (note: Rev 4 retains the no-arbitrary-rotation guidance but allows rotation on suspected compromise). Authenticator suspension per Section 6.5: temporary suspension on suspected compromise + clear unsuspend procedure. Authenticator revocation per Section 6.6: terminal revocation on confirmed compromise + clear binding-replacement workflow. Lifecycle event records per Section 6.7. Subscriber notification of binding changes per Section 6.8. Strong account recovery without weak fallback mechanisms (no security questions + no static PINs as sole factor).

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.