Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a separate hardware cryptographic authenticator, (b) Verifier Impersonation Resistance (phishing resistance) per Section 4.3.4 - the authentication protocol must prevent attackers from impersonating the verifier (FIDO2/WebAuthn + PIV + client-certificate authentication satisfy this), (c) Verifier Compromise Resistance per Section 5.2.7, (d) Replay Resistance per Section 4.3.5, (e) Hardware Authenticator Requirements (FIPS 140-2 Level 1 overall + Level 2 physical security minimum), (f) Reauthentication every 12 hours OR 15 minutes of inactivity per Section 7.2 (stricter than AAL2), (g) Strong session binding per Section 7.1, (h) Records of authentication events per Section 10.2.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.