ISO/IEC 29115:2023 — Entity Authentication Assurance Framework
ISO/IEC 29115:2023 specifies a framework for entity authentication assurance in ICT systems. Defines four levels of authentication assurance (LoA 1-4) based on confidence in the identity claim during authentication. LoA 1 provides minimal confidence, LoA 4 provides very high confidence with hardware-based authenticators. The standard covers: authentication threats, assurance levels, credential types, authentication mechanisms, and lifecycle management. Widely referenced by eIDAS, national digital identity schemes, and financial regulators. Applicable to both human and machine (IoT) entity authentication. Complemented by ISO/IEC 29003 (identity proofing) and ISO/IEC 24760 (identity management framework).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (16)
Audit
| Code | Title |
|---|---|
| ISO29115-10.1 | Audit and Accountability |
| ISO29115-10.2 | Independent Assessment |
Authentication
| Code | Title |
|---|---|
| ISO29115-7.1 | Authentication Protocol Requirements |
| ISO29115-7.2 | Multi Factor Authentication |
| ISO29115-7.3 | Session Management |
Clause 1-4: Framework Introduction
| Code | Title |
|---|---|
| 29115-1 | Scope |
| 29115-3 | Terms and definitions |
| 29115-4 | Abbreviations |
Clause 10: Criteria and Controls for Levels of Assurance
| Code | Title |
|---|---|
| 29115-10.1 | Enrollment and identity proofing criteria |
| 29115-10.2 | Credential management criteria |
| 29115-10.3 | Entity authentication criteria |
| 29115-10.4 | Federation and assertion criteria |
Clause 11-12: Mapping and Guidance
| Code | Title |
|---|---|
| 29115-11 | Mapping other authentication schemes |
| 29115-12.1 | Exchanging authentication results |
| 29115-12.2 | Controls for mitigating threats |
Clause 5-6: Framework Overview and Context
| Code | Title |
|---|---|
| 29115-5.1 | Entity authentication assurance framework overview |
| 29115-5.2 | Authentication lifecycle phases |
| 29115-6.1 | Authentication context |
Clause 7-8: Levels of Assurance
| Code | Title |
|---|---|
| 29115-7.1 | Level of Assurance 1 (LoA1) |
| 29115-7.2 | Level of Assurance 2 (LoA2) |
| 29115-7.3 | Level of Assurance 3 (LoA3) |
| 29115-7.4 | Level of Assurance 4 (LoA4) |
Clause 9: Threats to Authentication
| Code | Title |
|---|---|
| 29115-9.1 | Threat analysis overview |
| 29115-9.2 | Enrollment and identity proofing threats |
| 29115-9.3 | Credential management threats |
| 29115-9.4 | Authentication mechanism threats |
Credential Management
| Code | Title |
|---|---|
| ISO29115-6.1 | Credential Lifecycle Management |
| ISO29115-6.2 | Authenticator Binding |
Enrolment
| Code | Title |
|---|---|
| ISO29115-5.2 | Enrolment Phase Controls |
Federation
| Code | Title |
|---|---|
| ISO29115-11.1 | Cross LoA Federation |
| ISO29115-11.2 | Privacy in Authentication |
Foundation
| Code | Title |
|---|---|
| ISO29115-5.1 | Authentication Assurance Level Selection |
Identity Proofing
| Code | Title |
|---|---|
| ISO29115-5.3 | Identity Proofing at LoA 1 |
| ISO29115-5.4 | Identity Proofing at LoA 2 |
| ISO29115-5.5 | Identity Proofing at LoA 3 |
| ISO29115-5.6 | Identity Proofing at LoA 4 |
Operations
| Code | Title |
|---|---|
| ISO29115-12.1 | Documented Operating Procedures |
Provider Assurance
| Code | Title |
|---|---|
| ISO29115-8.1 | Credential Service Provider Assurance |
| ISO29115-8.2 | Registration Authority Operations |
Threats
| Code | Title |
|---|---|
| ISO29115-9.1 | Threat Mitigation Mapping |
| ISO29115-9.2 | Fraud Detection and Response |
Your Compliance Coverage
If you comply with ISO/IEC 29115:2023 — Entity Authentication Assurance Framework, you already cover:
ISO/IEC 27400:2022
12%
5 controls mapped
Compare →ISO/IEC 23837 — Security Requirements for Quantum Key Distribution
12%
5 controls mapped
Compare →3GPP 5G Security Architecture (TS 33.501)
12%
5 controls mapped
Compare →+ 547 more: 3GPP Security Architecture (TS 33.501 — 5G Security) (12%), SWIFT CSCF (12%)
See all 550 mapped frameworks ↓Maps to 550 other frameworks
Frequently Asked Questions
What is ISO/IEC 29115:2023 — Entity Authentication Assurance Framework?
ISO/IEC 29115:2023 — Entity Authentication Assurance Framework is a compliance framework from International (ISO/IEC) with 16 domains and 41 controls. ISO/IEC 29115:2023 specifies a framework for entity authentication assurance in ICT systems. Defines four levels of authentication assurance (LoA 1-4) based on confidence in the identity claim during authentication. LoA 1 provides minimal confidence, LoA 4 provides very high confidence with hardware-based authenticators. The standard covers: authentication threats, assurance levels, credential types, authentication mechanisms, and lifecycle management. Widely referenced by eIDAS, national digital identity schemes, and financial regulators. Applicable to both human and machine (IoT) entity authentication. Complemented by ISO/IEC 29003 (identity proofing) and ISO/IEC 24760 (identity management framework). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 29115:2023 — Entity Authentication Assurance Framework have?
ISO/IEC 29115:2023 — Entity Authentication Assurance Framework has 41 controls organised across 16 domains. The largest domains are Clause 10: Criteria and Controls for Levels of Assurance (4 controls), Clause 7-8: Levels of Assurance (4 controls), Clause 9: Threats to Authentication (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 29115:2023 — Entity Authentication Assurance Framework map to?
ISO/IEC 29115:2023 — Entity Authentication Assurance Framework maps to 550 other compliance frameworks. The top mapping partners are ISO/IEC 27400:2022 (12% coverage), ISO/IEC 23837 — Security Requirements for Quantum Key Distribution (12% coverage), 3GPP 5G Security Architecture (TS 33.501) (12% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/IEC 29115:2023 — Entity Authentication Assurance Framework compliance?
Start your ISO/IEC 29115:2023 — Entity Authentication Assurance Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 29115:2023 — Entity Authentication Assurance Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 41 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required