NIST SP 800-63 Digital Identity Guidelines
Authentication - AAL1 + AAL2

NIST SP 800-63 Digital Identity Guidelines 5: AAL1 and AAL2 Authentication: MFA, Approved Authenticators, Session Binding

Implement AAL1 and AAL2 authentication per NIST SP 800-63B Chapter 4 + Chapter 5 + Section 7. AAL1 requires (a) Single-factor authentication using any of memorised secret + look-up secret + out-of-band device + single-factor OTP + single-factor cryptographic software + single-factor cryptographic device + multi-factor authenticator (Section 5.1), (b) Phishing resistance not required at AAL1, (c) Verifier requirements per Section 5.1.1 (rate limiting + breached-password check + memorised secret composition rules per Section 5.1.1.2). AAL2 requires (a) Multi-Factor Authentication using approved authenticator combinations from Section 4.2.1 (memorised secret with second factor + multi-factor authenticator + or hardware OTP combined with memorised secret), (b) Cryptographic protection of authenticators + session binding per Section 7, (c) Reauthentication every 12 hours OR after 30 minutes of inactivity per Section 7.2, (d) FIPS 140 validation requirement, (e) Phishing resistance per Section 4.2.5 if AAL2-PR, (f) Replay resistance per Section 4.2.6, (g) Session binding per Section 7.1.1 (browser cookies + OAuth tokens + JWT + bearer tokens with appropriate protection).

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.