NIST SP 800-63 Digital Identity Guidelines
Authentication - AAL3

NIST SP 800-63 Digital Identity Guidelines NISTSP63-6: AAL3 Authentication: Hardware Cryptographic, Verifier Impersonation Resistance, Phishing Resistance

Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a separate hardware cryptographic authenticator, (b) Verifier Impersonation Resistance (phishing resistance) per Section 4.3.4 - the authentication protocol must prevent attackers from impersonating the verifier (FIDO2/WebAuthn + PIV + client-certificate authentication satisfy this), (c) Verifier Compromise Resistance per Section 5.2.7, (d) Replay Resistance per Section 4.3.5, (e) Hardware Authenticator Requirements (FIPS 140-2 Level 1 overall + Level 2 physical security minimum), (f) Reauthentication every 12 hours OR 15 minutes of inactivity per Section 7.2 (stricter than AAL2), (g) Strong session binding per Section 7.1, (h) Records of authentication events per Section 10.2.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.