Skip to content

Build1 publisher2 min readPublished

NIST retires SP 800-63-3 in a four-volume rewrite of its digital identity requirements

The abstract states the supersession in one sentence. The requirement text sits in three companion volumes, and the base document spends its introduction asking organizations to tailor controls to their own risk.

The Engineer · Build desk

Illustration accompanying NIST retires SP 800-63-3 in a four-volume rewrite of its digital identity requirements

What happened

  • The abstract of NIST SP 800-63-4 states that the publication supersedes SP 800-63-3, the guideline set covering identity proofing, authentication and federation for people who use government information systems over networks.
  • The technical requirements are spread across the base document and three companion volumes, SP 800-63A, SP 800-63B and SP 800-63C.
  • The guidelines define assurance levels as baseline control sets, then say it is impractical for such levels to address the entire spectrum of risks, threats or considerations an organization will face.
  • They account for risks to individuals, communities and other organizations, and say privacy and customer experience for individuals should be considered along with security.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Scoping this work means budgeting review time for four documents, because the base volume's introduction is labelled informative and will not tell an engineer which control to build.
  • constraint A conformance statement that names an assurance level and stops does not describe the tailoring the guidelines ask organizations to do.
  • exposure Call center and in-person identity paths sit inside the approach the document asks organizations to weigh. Contact center scripts become part of the identity design review.
  • constraint Anyone planning a move off 800-63-3 has to source the deadline from a contract or an agency policy, since the publication supplies none.

The base volume's introduction labels itself. "This section is informative." [5] Same message in the abstract: the guidelines "also offer technical recommendations and other informative text as helpful suggestions" [14]. Requirements are the technical part, defined in identity proofing, enrollment, authenticators, management processes, authentication protocols, federation, and related assertions [3]. The abstract, preface and introduction do not say which companion volume carries which of those areas, so that mapping has to come out of the volumes themselves [3]. A team scoping the work is reading four documents [1].

The document is careful about what a named assurance level covers. It says the guidelines "promote a risk-based approach to digital identity solution implementation rather than a compliance-oriented approach, and organizations are encouraged to tailor their control implementations based on the processes defined in these guidelines" [8]. The document also says they "are not intended to constrain the development or use of standards outside of this purpose" [6]. For any of this to work as an audit checklist, somebody other than this document has to publish the assessment criteria, because the text describes the control set as a baseline to be tailored [8].

No compliance date, no transition window and no assessment procedure appears in the abstract, preface or introduction [2]. The page as published carries a timestamp of 26 August 2025 [12]. Migration timing therefore comes from a contract, an agency policy or an assessment guide [2].

The introduction also widens where an identity design gets reviewed. Organizations, it says, "should consider their digital identity approach alongside other mechanisms for identity management, such as those used in call centers and in-person interactions" [11]. If your account recovery path ends in a phone call to a human, that path is inside the approach the document describes. One scoping permission is stated outright: when confidence in a person's real-life identity is not required to provide access to an online service, organizations can use anonymous or pseudonymous accounts [16]. And the document says a customer-centric approach gives organizations the opportunity to "provide individuals with appropriate and effective redress options" [17].

What to watch

  • Whether an agency policy, contract clause or assessment guide supplies the transition deadline the publication itself does not carry.
  • Whether assessment procedures appear that convert the assurance levels into criteria an auditor can score.
  • Whether the requirement text in SP 800-63A, 800-63B and 800-63C picks up errata or revision after publication.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories