Compliance matrix
NIST SP 800-63 Digital Identity Guidelines
United States (guideline, widely referenced globally) · Updated 2026-07-19
Applies to: US federal systems by mandate, and any team that wants a rigorous, standard way to set identity assurance.
Requirements mapped to CIAM
Authenticator Assurance Level (AAL)
The strength of authentication must match the risk: AAL1 (single factor), AAL2 (MFA), AAL3 (hardware-backed, phishing-resistant).
CIAM controls
- MFA for AAL2
- Phishing-resistant, hardware-backed authenticators (FIDO2 / passkeys) for AAL3
- Re-authentication at defined intervals
Evidence
- Authentication policy mapped to AAL
- Authenticator inventory
Ask the vendor
- Which AAL can you support, and do you offer AAL3-capable phishing-resistant authenticators?
Identity Assurance Level (IAL)
Higher-risk services need identity proofing: IAL1 (self-asserted), IAL2 (remote or in-person proofing), IAL3 (in-person or supervised).
CIAM controls
- Identity proofing / verification integration for IAL2+
- Evidence validation and verification
Evidence
- Proofing workflow documentation
- Verification records
Ask the vendor
- Do you offer or integrate identity proofing to reach IAL2?
Federation Assurance Level (FAL)
Federated assertions (SAML/OIDC) must be protected proportional to risk.
CIAM controls
- Signed, and where required encrypted, assertions
- Audience restriction and replay protection
Evidence
- Federation configuration
- Assertion samples
Ask the vendor
- How are federated assertions signed, encrypted, and protected against replay?
Take this into procurement
Turn these requirements into vendor questions.
The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.
Where it bites hardest
FAQ
- What AAL do passkeys reach?
- Device-bound FIDO2 authenticators can meet AAL3 because they are hardware-backed and phishing-resistant. Synced passkeys are phishing-resistant and strong for AAL2, but syncing across devices generally keeps them below the hardware-bound bar for AAL3. Confirm the exact authenticator type against your target AAL.
- Is NIST 800-63 mandatory?
- It is mandatory for US federal agencies and systems. For everyone else it is a voluntary but widely adopted framework, and referencing AAL/IAL is the clearest way to specify authentication and proofing requirements to a CIAM vendor.
Source
NIST SP 800-63 Digital Identity Guidelines
This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.