Back to Frameworks

NIST SP 800-63 Digital Identity Guidelines

United States
4 domains
49 controls

NIST SP 800-63-3 + 800-63A/B/C Digital Identity Guidelines (IAL/AAL/FAL assurance levels).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

800-63-3

3 controls
Controls in the 800-63-3 domain of NIST SP 800-63 Digital Identity Guidelines3 controls
CodeTitle
DIG-RISK-1Digital Identity Risk Assessment
DIG-RISK-2Assurance Level Selection Per Transaction
DIG-RISK-3Privacy Risk Assessment

800-63A

14 controls
Controls in the 800-63A domain of NIST SP 800-63 Digital Identity Guidelines14 controls
CodeTitle
IAL1-PROOF-1IAL1 Self-Asserted Attributes
IAL2-PROOF-1IAL2 Identity Evidence Collection
IAL2-PROOF-2IAL2 Identity Resolution
IAL2-PROOF-3IAL2 Evidence Validation
IAL2-PROOF-4IAL2 Identity Verification
IAL2-PROOF-5IAL2 Remote Proofing Controls
IAL2-PROOF-6Knowledge-Based Verification Restrictions
IAL3-PROOF-1IAL3 In-Person or Supervised Remote
IAL3-PROOF-2IAL3 Evidence Strength
PROOF-BIOMETRIC-1Biometric Collection at Enrolment
PROOF-FRAUD-1Proofing Fraud Mitigation
PROOF-NOTICE-1Notice to Applicants
PROOF-RECORDS-1Identity Proofing Record Retention
PROOF-TRUSTED-1Trusted Referee and Applicant References

800-63B

20 controls
Controls in the 800-63B domain of NIST SP 800-63 Digital Identity Guidelines20 controls
CodeTitle
AAL1-AUTH-1AAL1 Single-Factor Authentication
AAL2-AUTH-1AAL2 Multi-Factor Required
AAL2-AUTH-2AAL2 Approved Authenticator Types
AAL2-AUTH-3AAL2 Reauthentication
AAL3-AUTH-1AAL3 Hardware Cryptographic Authenticator
AAL3-AUTH-2AAL3 Verifier Compromise Resistance
AAL3-AUTH-3AAL3 Reauthentication
AUTH-BIO-1Biometric Authentication Performance
AUTH-EVENT-1Authentication Event Records
AUTH-MIN-AGE-1Subscriber Notification of Changes
AUTH-OTP-1OTP Authenticator Controls
AUTH-PHISH-1Phishing Resistance
AUTH-RATELIMIT-1Rate Limiting and Account Lockout
AUTH-REPLACE-1Authenticator Loss and Replacement
AUTH-SECRET-1Memorized Secret Composition
AUTH-SECRET-2Memorized Secret Breach Check
AUTH-SECRET-3Memorized Secret Storage
AUTH-SESSION-1Session Binding
AUTH-SMS-1SMS OTP Restricted Use
AUTH-THREAT-1Threat Model Coverage Per AAL

800-63C

12 controls
Controls in the 800-63C domain of NIST SP 800-63 Digital Identity Guidelines12 controls
CodeTitle
FAL1-FED-1FAL1 Bearer Assertions
FAL2-FED-1FAL2 Encrypted Assertion
FAL3-FED-1FAL3 Holder-of-Key Assertion
FED-AGREE-1Trust Agreement Between IdP and RP
FED-ASSERT-1Assertion Content Requirements
FED-ATTR-1Attribute Minimisation in Assertions
FED-KEY-1Cryptographic Key Management for Federation
FED-LOG-1Federation Audit Logging
FED-PROXY-1Federation Proxies
FED-PSEUDO-1Pseudonymous Identifiers
FED-RP-1Relying Party Validation Obligations
FED-RUNTIME-1Runtime Subscriber Decision

Frequently Asked Questions

What is NIST SP 800-63 Digital Identity Guidelines?

NIST SP 800-63 Digital Identity Guidelines is a compliance framework from United States with 4 domains and 49 controls. NIST SP 800-63-3 + 800-63A/B/C Digital Identity Guidelines (IAL/AAL/FAL assurance levels). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-63 Digital Identity Guidelines have?

NIST SP 800-63 Digital Identity Guidelines has 49 controls organised across 4 domains. The largest domains are 800-63B (20 controls), 800-63A (14 controls), 800-63C (12 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-63 Digital Identity Guidelines map to?

NIST SP 800-63 Digital Identity Guidelines does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with NIST SP 800-63 Digital Identity Guidelines compliance?

Start your NIST SP 800-63 Digital Identity Guidelines compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-63 Digital Identity Guidelines requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 49 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required