ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
ISO/IEC 29115:2023 specifies a framework for entity authentication assurance in ICT systems. Defines four levels of authentication assurance (LoA 1-4) based on confidence in the identity claim during authentication. LoA 1 provides minimal confidence, LoA 4 provides very high confidence with hardware-based authenticators. The standard covers: authentication threats, assurance levels, credential types, authentication mechanisms, and lifecycle management. Widely referenced by eIDAS, national digital identity schemes, and financial regulators. Applicable to both human and machine (IoT) entity authentication. Complemented by ISO/IEC 29003 (identity proofing) and ISO/IEC 24760 (identity management framework).
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework is a compliance framework from International (ISO/IEC) with 16 domains and 41 controls that map to 169 other frameworks. The largest domains are Clause 10: Criteria and Controls for Levels of Assurance (4 controls), Clause 7-8: Levels of Assurance (4 controls), Clause 9: Threats to Authentication (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (16)
Audit
| Code | Title |
|---|---|
| ISO29115-10.1 | Audit and Accountability |
| ISO29115-10.2 | Independent Assessment |
Authentication
| Code | Title |
|---|---|
| ISO29115-7.1 | Authentication Protocol Requirements |
| ISO29115-7.2 | Multi Factor Authentication |
| ISO29115-7.3 | Session Management |
Clause 1-4: Framework Introduction
Clause 10: Criteria and Controls for Levels of Assurance
| Code | Title |
|---|---|
| 29115-10.1 | Enrollment and identity proofing criteria |
| 29115-10.2 | Credential management criteria |
| 29115-10.3 | Entity authentication criteria |
| 29115-10.4 | Federation and assertion criteria |
Clause 11-12: Mapping and Guidance
| Code | Title |
|---|---|
| 29115-11 | Mapping other authentication schemes |
| 29115-12.1 | Exchanging authentication results |
| 29115-12.2 | Controls for mitigating threats |
Clause 5-6: Framework Overview and Context
Clause 7-8: Levels of Assurance
Clause 9: Threats to Authentication
| Code | Title |
|---|---|
| 29115-9.1 | Threat analysis overview |
| 29115-9.2 | Enrollment and identity proofing threats |
| 29115-9.3 | Credential management threats |
| 29115-9.4 | Authentication mechanism threats |
Credential Management
| Code | Title |
|---|---|
| ISO29115-6.1 | Credential Lifecycle Management |
| ISO29115-6.2 | Authenticator Binding |
Enrolment
| Code | Title |
|---|---|
| ISO29115-5.2 | Enrolment Phase Controls |
Federation
| Code | Title |
|---|---|
| ISO29115-11.1 | Cross LoA Federation |
| ISO29115-11.2 | Privacy in Authentication |
Foundation
| Code | Title |
|---|---|
| ISO29115-5.1 | Authentication Assurance Level Selection |
Identity Proofing
| Code | Title |
|---|---|
| ISO29115-5.3 | Identity Proofing at LoA 1 |
| ISO29115-5.4 | Identity Proofing at LoA 2 |
| ISO29115-5.5 | Identity Proofing at LoA 3 |
| ISO29115-5.6 | Identity Proofing at LoA 4 |
Operations
| Code | Title |
|---|---|
| ISO29115-12.1 | Documented Operating Procedures |
Provider Assurance
| Code | Title |
|---|---|
| ISO29115-8.1 | Credential Service Provider Assurance |
| ISO29115-8.2 | Registration Authority Operations |
Threats
| Code | Title |
|---|---|
| ISO29115-9.1 | Threat Mitigation Mapping |
| ISO29115-9.2 | Fraud Detection and Response |
Your Compliance Coverage
If you comply with ISO/IEC 29115:2023 - Entity Authentication Assurance Framework, you already cover:
W3C Verifiable Credentials (VC) Data Model 2.0
11%
4 controls mapped
Compare →SLSA
11%
4 controls mapped
Compare →Sigstore - Software Artifact Signing and Verification
11%
4 controls mapped
Compare →+ 166 more: SIG (Shared Assessments) (11%), Secure by Design: A Guide for Manufacturers (CISA) (11%)
See all 169 mapped frameworks ↓Maps to 169 other frameworks
What is ISO/IEC 29115:2023 - Entity Authentication Assurance Framework and who does it apply to?
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework is a compliance framework from International (ISO/IEC) with 16 domains and 41 controls. ISO/IEC 29115:2023 specifies a framework for entity authentication assurance in ICT systems. Defines four levels of authentication assurance (LoA 1-4) based on confidence in the identity claim during authentication. LoA 1 provides minimal confidence, LoA 4 provides very high confidence with hardware-based authenticators. The standard covers: authentication threats, assurance levels, credential types, authentication mechanisms, and lifecycle management. Widely referenced by eIDAS, national digital identity schemes, and financial regulators. Applicable to both human and machine (IoT) entity authentication. Complemented by ISO/IEC 29003 (identity proofing) and ISO/IEC 24760 (identity management framework). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 29115:2023 - Entity Authentication Assurance Framework actually require?
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework has 41 controls organised across 16 domains. The largest domains are Clause 10: Criteria and Controls for Levels of Assurance (4 controls), Clause 7-8: Levels of Assurance (4 controls), Clause 9: Threats to Authentication (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework do I already cover?
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework maps to 169 other compliance frameworks. The top mapping partners are W3C Verifiable Credentials (VC) Data Model 2.0 (11% coverage), SLSA (11% coverage), Sigstore - Software Artifact Signing and Verification (11% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 29115:2023 - Entity Authentication Assurance Framework?
Start your ISO/IEC 29115:2023 - Entity Authentication Assurance Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 29115:2023 - Entity Authentication Assurance Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 41 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required