Back to Frameworks

ISO/IEC 29115:2023 - Entity Authentication Assurance Framework

International (ISO/IEC)
v2023
16 domains
41 controls

ISO/IEC 29115:2023 specifies a framework for entity authentication assurance in ICT systems. Defines four levels of authentication assurance (LoA 1-4) based on confidence in the identity claim during authentication. LoA 1 provides minimal confidence, LoA 4 provides very high confidence with hardware-based authenticators. The standard covers: authentication threats, assurance levels, credential types, authentication mechanisms, and lifecycle management. Widely referenced by eIDAS, national digital identity schemes, and financial regulators. Applicable to both human and machine (IoT) entity authentication. Complemented by ISO/IEC 29003 (identity proofing) and ISO/IEC 24760 (identity management framework).

Unverified

ISO/IEC 29115:2023 - Entity Authentication Assurance Framework is a compliance framework from International (ISO/IEC) with 16 domains and 41 controls that map to 169 other frameworks. The largest domains are Clause 10: Criteria and Controls for Levels of Assurance (4 controls), Clause 7-8: Levels of Assurance (4 controls), Clause 9: Threats to Authentication (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (16)

Audit

2 controls
Controls in the Audit domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework2 controls
CodeTitle
ISO29115-10.1Audit and Accountability
ISO29115-10.2Independent Assessment

Authentication

3 controls
Controls in the Authentication domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework3 controls
CodeTitle
ISO29115-7.1Authentication Protocol Requirements
ISO29115-7.2Multi Factor Authentication
ISO29115-7.3Session Management

Clause 1-4: Framework Introduction

3 controls

Clause 10: Criteria and Controls for Levels of Assurance

4 controls
Controls in the Clause 10: Criteria and Controls for Levels of Assurance domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework4 controls
CodeTitle
29115-10.1Enrollment and identity proofing criteria
29115-10.2Credential management criteria
29115-10.3Entity authentication criteria
29115-10.4Federation and assertion criteria

Clause 11-12: Mapping and Guidance

3 controls
Controls in the Clause 11-12: Mapping and Guidance domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework3 controls
CodeTitle
29115-11Mapping other authentication schemes
29115-12.1Exchanging authentication results
29115-12.2Controls for mitigating threats

Clause 5-6: Framework Overview and Context

3 controls
Controls in the Clause 5-6: Framework Overview and Context domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework3 controls
CodeTitle
29115-5.1Entity authentication assurance framework overview
29115-5.2Authentication lifecycle phases
29115-6.1Authentication context

Clause 7-8: Levels of Assurance

4 controls
Controls in the Clause 7-8: Levels of Assurance domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework4 controls
CodeTitle
29115-7.1Level of Assurance 1 (LoA1)
29115-7.2Level of Assurance 2 (LoA2)
29115-7.3Level of Assurance 3 (LoA3)
29115-7.4Level of Assurance 4 (LoA4)

Clause 9: Threats to Authentication

4 controls
Controls in the Clause 9: Threats to Authentication domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework4 controls
CodeTitle
29115-9.1Threat analysis overview
29115-9.2Enrollment and identity proofing threats
29115-9.3Credential management threats
29115-9.4Authentication mechanism threats

Credential Management

2 controls
Controls in the Credential Management domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework2 controls
CodeTitle
ISO29115-6.1Credential Lifecycle Management
ISO29115-6.2Authenticator Binding

Enrolment

1 controls
Controls in the Enrolment domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework1 controls
CodeTitle
ISO29115-5.2Enrolment Phase Controls

Federation

2 controls
Controls in the Federation domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework2 controls
CodeTitle
ISO29115-11.1Cross LoA Federation
ISO29115-11.2Privacy in Authentication

Foundation

1 controls
Controls in the Foundation domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework1 controls
CodeTitle
ISO29115-5.1Authentication Assurance Level Selection

Identity Proofing

4 controls
Controls in the Identity Proofing domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework4 controls
CodeTitle
ISO29115-5.3Identity Proofing at LoA 1
ISO29115-5.4Identity Proofing at LoA 2
ISO29115-5.5Identity Proofing at LoA 3
ISO29115-5.6Identity Proofing at LoA 4

Operations

1 controls
Controls in the Operations domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework1 controls
CodeTitle
ISO29115-12.1Documented Operating Procedures

Provider Assurance

2 controls
Controls in the Provider Assurance domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework2 controls
CodeTitle
ISO29115-8.1Credential Service Provider Assurance
ISO29115-8.2Registration Authority Operations

Threats

2 controls
Controls in the Threats domain of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework2 controls
CodeTitle
ISO29115-9.1Threat Mitigation Mapping
ISO29115-9.2Fraud Detection and Response

Your Compliance Coverage

If you comply with ISO/IEC 29115:2023 - Entity Authentication Assurance Framework, you already cover:

Maps to 169 other frameworks

38 total controls
W3C Verifiable Credentials (VC) Data Model 2.0
4 source controls mapped|2 target controls covered
11%
SLSA
4 source controls mapped|2 target controls covered
11%
Sigstore - Software Artifact Signing and Verification
4 source controls mapped|2 target controls covered
11%
SIG (Shared Assessments)
4 source controls mapped|2 target controls covered
11%
Secure by Design: A Guide for Manufacturers (CISA)
4 source controls mapped|2 target controls covered
11%
PTES
4 source controls mapped|2 target controls covered
11%
OWASP Top 10:2025
4 source controls mapped|3 target controls covered
11%
OWASP SAMM
4 source controls mapped|1 target controls covered
11%
OWASP MASVS
4 source controls mapped|3 target controls covered
11%
OWASP ASVS
4 source controls mapped|3 target controls covered
11%
OWASP API Security Top 10 - 2023
4 source controls mapped|2 target controls covered
11%
OpenSSF Scorecard
4 source controls mapped|2 target controls covered
11%
Oman National Cybersecurity Framework
4 source controls mapped|2 target controls covered
11%
O-RAN WG11 Security Specification
4 source controls mapped|2 target controls covered
11%
NIST SP 800-92
4 source controls mapped|1 target controls covered
11%
NIST SP 800-88
4 source controls mapped|2 target controls covered
11%
11%
NIST SP 800-66
4 source controls mapped|1 target controls covered
11%
NIST SP 800-63-4
4 source controls mapped|2 target controls covered
11%
NIST SP 800-61
4 source controls mapped|2 target controls covered
11%
NIST SP 800-146
4 source controls mapped|1 target controls covered
11%
NIST SP 800-145
4 source controls mapped|1 target controls covered
11%
NIST SP 800-144
4 source controls mapped|2 target controls covered
11%
NIST SP 800-137
4 source controls mapped|2 target controls covered
11%
NIST SP 800-123
4 source controls mapped|2 target controls covered
11%
NIST Privacy Framework
4 source controls mapped|2 target controls covered
11%
NIS2 Directive Implementing Acts
4 source controls mapped|2 target controls covered
11%
NAIC Insurance Data Security Model Law (MDL-668)
4 source controls mapped|2 target controls covered
11%
MTCS (Singapore)
4 source controls mapped|2 target controls covered
11%
MITRE D3FEND
4 source controls mapped|1 target controls covered
11%
MITRE ATT&CK
4 source controls mapped|2 target controls covered
11%
MDS2 (Medical Device)
4 source controls mapped|2 target controls covered
11%
MARS-E
4 source controls mapped|4 target controls covered
11%
ISMAP (Japan)
4 source controls mapped|2 target controls covered
11%
HL7 FHIR Security Framework
4 source controls mapped|2 target controls covered
11%
Ghana Cybersecurity Act
4 source controls mapped|2 target controls covered
11%
FTC GLBA Safeguards Rule (16 CFR Part 314)
4 source controls mapped|1 target controls covered
11%
FISMA
4 source controls mapped|2 target controls covered
11%
FIDO2 / WebAuthn
4 source controls mapped|2 target controls covered
11%
FedRAMP Rev 5
4 source controls mapped|2 target controls covered
11%
FDA 21 CFR Part 11
4 source controls mapped|2 target controls covered
11%
ISO/IEC 27400:2022
4 source controls mapped|2 target controls covered
11%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
4 source controls mapped|3 target controls covered
11%
ISO 19011
4 source controls mapped|3 target controls covered
11%
11%
ISO 13485
4 source controls mapped|4 target controls covered
11%
NIST SP 800-53 Rev 5
4 source controls mapped|5 target controls covered
11%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
4 source controls mapped|2 target controls covered
11%
ASD Strategies to Mitigate Cyber Security Incidents
4 source controls mapped|3 target controls covered
11%
Belgium CyberFundamentals
4 source controls mapped|2 target controls covered
11%
TISAX - Trusted Information Security Assessment Exchange
4 source controls mapped|3 target controls covered
11%
South Korea ISMS-P
4 source controls mapped|2 target controls covered
11%
ISO 27017
4 source controls mapped|2 target controls covered
11%
UK Open Banking Standard
4 source controls mapped|4 target controls covered
11%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
4 source controls mapped|5 target controls covered
11%
ISO 27799
4 source controls mapped|3 target controls covered
11%
NIST SP 800-190
4 source controls mapped|2 target controls covered
11%
BSI IT-Grundschutz
4 source controls mapped|2 target controls covered
11%
ISO 27043
4 source controls mapped|4 target controls covered
11%
3GPP 5G Security Architecture (TS 33.501)
4 source controls mapped|2 target controls covered
11%
ISO 27018
4 source controls mapped|2 target controls covered
11%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
4 source controls mapped|5 target controls covered
11%
ISO/SAE 21434
4 source controls mapped|4 target controls covered
11%
WCAG 2.2
3 source controls mapped|1 target controls covered
8%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
3 source controls mapped|1 target controls covered
8%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
3 source controls mapped|1 target controls covered
8%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
3 source controls mapped|1 target controls covered
8%
Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter
3 source controls mapped|1 target controls covered
8%
TSA Pipeline Cybersecurity Directives
3 source controls mapped|1 target controls covered
8%
TEFCA - Trusted Exchange Framework and Common Agreement
3 source controls mapped|1 target controls covered
8%
SWIFT CSCF
3 source controls mapped|1 target controls covered
8%
Regulation on the European Health Data Space (EHDS)
3 source controls mapped|1 target controls covered
8%
OWASP Top 10 for LLM Applications 2025
3 source controls mapped|2 target controls covered
8%
OWASP DevSecOps Maturity Model (DSOMM)
3 source controls mapped|1 target controls covered
8%
ITU-T X.805 - Security Architecture for End-to-End Communications
3 source controls mapped|1 target controls covered
8%
GLI-33 - Gaming Laboratories International Event Wagering Systems
3 source controls mapped|1 target controls covered
8%
Florida Digital Bill of Rights (FDBR)
3 source controls mapped|2 target controls covered
8%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
3 source controls mapped|1 target controls covered
8%
UK Telecommunications (Security) Act 2021
3 source controls mapped|1 target controls covered
8%
SSAE 18 - Attestation Standards (SOC Reporting)
3 source controls mapped|1 target controls covered
8%
Armenia Law on Protection of Personal Data (2015)
3 source controls mapped|1 target controls covered
8%
Illinois Biometric Information Privacy Act (BIPA)
3 source controls mapped|2 target controls covered
8%
AML/CTF Act 2006 (Australia)
3 source controls mapped|1 target controls covered
8%
NIST Cybersecurity Framework 2.0
3 source controls mapped|2 target controls covered
8%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
3 source controls mapped|1 target controls covered
8%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
3 source controls mapped|1 target controls covered
8%
ISO 27018:2019
1 source controls mapped|1 target controls covered
3%
ISO 27002:2022
1 source controls mapped|1 target controls covered
3%
Virginia CDPA
1 source controls mapped|1 target controls covered
3%
Vietnam PDPD
1 source controls mapped|1 target controls covered
3%
Uruguay DPL
1 source controls mapped|1 target controls covered
3%
Turkey KVKK
1 source controls mapped|1 target controls covered
3%
Texas Data Privacy Act
1 source controls mapped|1 target controls covered
3%
Taiwan PDPA
1 source controls mapped|1 target controls covered
3%
PSD2 SCA
1 source controls mapped|1 target controls covered
3%
Qatar DPL
1 source controls mapped|1 target controls covered
3%
Privacy Act 2020
1 source controls mapped|1 target controls covered
3%
Privacy Act 1988 (Australia)
1 source controls mapped|1 target controls covered
3%
POPIA
1 source controls mapped|1 target controls covered
3%
Peru DPL
1 source controls mapped|1 target controls covered
3%
Personal Data Act (personopplysningsloven)
1 source controls mapped|1 target controls covered
3%
PDPA Thailand
1 source controls mapped|1 target controls covered
3%
PDPA Singapore
1 source controls mapped|1 target controls covered
3%
OSFI B-13
1 source controls mapped|1 target controls covered
3%
Oregon Consumer Privacy Act
1 source controls mapped|1 target controls covered
3%
Open Banking Security
1 source controls mapped|1 target controls covered
3%
NIST SP 800-122
1 source controls mapped|1 target controls covered
3%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
1 source controls mapped|3 target controls covered
3%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
1 source controls mapped|1 target controls covered
3%
Nigeria Data Protection Regulation (NDPR)
1 source controls mapped|1 target controls covered
3%
Nigeria Data Protection Act 2023 (NDPA)
1 source controls mapped|2 target controls covered
3%
Nebraska Data Privacy Act
1 source controls mapped|2 target controls covered
3%
New Zealand Information Security Manual (NZISM)
1 source controls mapped|1 target controls covered
3%
New Jersey Data Privacy Act
1 source controls mapped|1 target controls covered
3%
New Hampshire Data Privacy Act
1 source controls mapped|1 target controls covered
3%
Montana Consumer Data Privacy Act
1 source controls mapped|1 target controls covered
3%
Monetary Authority of Singapore Technology Risk Management Guidelines
1 source controls mapped|1 target controls covered
3%
Minnesota Consumer Data Privacy Act
1 source controls mapped|1 target controls covered
3%
Mexico LFPDPPP
1 source controls mapped|1 target controls covered
3%
Mauritius DPA
1 source controls mapped|1 target controls covered
3%
Maryland Online Data Privacy Act of 2024
1 source controls mapped|1 target controls covered
3%
Malaysia PDPA 2010
1 source controls mapped|1 target controls covered
3%
Liechtenstein DPA
1 source controls mapped|1 target controls covered
3%
LGPD
1 source controls mapped|1 target controls covered
3%
Ley Orgánica de Protección de Datos Personales (LOPDP)
1 source controls mapped|1 target controls covered
3%
Law No. 172-13 on the Protection of Personal Data
1 source controls mapped|1 target controls covered
3%
Kentucky Consumer Data Protection Act
1 source controls mapped|1 target controls covered
3%
Jamaica Data Protection Act 2020
1 source controls mapped|1 target controls covered
3%
Iowa Consumer Data Protection Act
1 source controls mapped|1 target controls covered
3%
Indonesia PDP Law
1 source controls mapped|1 target controls covered
3%
Indiana Consumer Data Protection Act
1 source controls mapped|1 target controls covered
3%
India DPDP Act
1 source controls mapped|1 target controls covered
3%
3%
HKMA SPM
1 source controls mapped|1 target controls covered
3%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|1 target controls covered
3%
HITECH Act
1 source controls mapped|1 target controls covered
3%
GLBA
1 source controls mapped|1 target controls covered
3%
Family Educational Rights and Privacy Act (FERPA)
1 source controls mapped|1 target controls covered
3%
ISO/IEC 27011:2024
1 source controls mapped|1 target controls covered
3%
ISO/IEC 27010:2015
1 source controls mapped|1 target controls covered
3%
Bahrain PDPL
1 source controls mapped|1 target controls covered
3%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
1 source controls mapped|1 target controls covered
3%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|1 target controls covered
3%
PCI SSF
1 source controls mapped|1 target controls covered
3%
APPI
1 source controls mapped|1 target controls covered
3%
ISO 31000:2018
1 source controls mapped|1 target controls covered
3%
FFIEC IT Examination Handbook
1 source controls mapped|1 target controls covered
3%
NSA Guidance for Transition to Quantum-Resistant Cryptography
1 source controls mapped|3 target controls covered
3%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
1 source controls mapped|1 target controls covered
3%
PCI PIN Security
1 source controls mapped|1 target controls covered
3%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
3%
ISO 27005
1 source controls mapped|1 target controls covered
3%
ISO 20000-1
1 source controls mapped|1 target controls covered
3%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
1 source controls mapped|1 target controls covered
3%
SOC for Cybersecurity - Cybersecurity Risk Management Examination
1 source controls mapped|1 target controls covered
3%
FBI CJIS Security Policy
1 source controls mapped|2 target controls covered
3%
US ITAR and EAR - Export Control and Data Security
1 source controls mapped|2 target controls covered
3%
PCI P2PE
1 source controls mapped|1 target controls covered
3%
Saudi Arabia PDPL
1 source controls mapped|1 target controls covered
3%

What is ISO/IEC 29115:2023 - Entity Authentication Assurance Framework and who does it apply to?

ISO/IEC 29115:2023 - Entity Authentication Assurance Framework is a compliance framework from International (ISO/IEC) with 16 domains and 41 controls. ISO/IEC 29115:2023 specifies a framework for entity authentication assurance in ICT systems. Defines four levels of authentication assurance (LoA 1-4) based on confidence in the identity claim during authentication. LoA 1 provides minimal confidence, LoA 4 provides very high confidence with hardware-based authenticators. The standard covers: authentication threats, assurance levels, credential types, authentication mechanisms, and lifecycle management. Widely referenced by eIDAS, national digital identity schemes, and financial regulators. Applicable to both human and machine (IoT) entity authentication. Complemented by ISO/IEC 29003 (identity proofing) and ISO/IEC 24760 (identity management framework). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/IEC 29115:2023 - Entity Authentication Assurance Framework actually require?

ISO/IEC 29115:2023 - Entity Authentication Assurance Framework has 41 controls organised across 16 domains. The largest domains are Clause 10: Criteria and Controls for Levels of Assurance (4 controls), Clause 7-8: Levels of Assurance (4 controls), Clause 9: Threats to Authentication (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework do I already cover?

ISO/IEC 29115:2023 - Entity Authentication Assurance Framework maps to 169 other compliance frameworks. The top mapping partners are W3C Verifiable Credentials (VC) Data Model 2.0 (11% coverage), SLSA (11% coverage), Sigstore - Software Artifact Signing and Verification (11% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ISO/IEC 29115:2023 - Entity Authentication Assurance Framework?

Start your ISO/IEC 29115:2023 - Entity Authentication Assurance Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 29115:2023 - Entity Authentication Assurance Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 41 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required