Configure an identity proofing flow's evidence requirements to meet NIST SP 800-63-4 IAL2 for a regulated onboarding product
domain: pages.nist.gov · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
Confirm your product's required assurance level (IAL2) against your regulatory or contractual requirement rather than defaulting to the strictest option
Select one of the IAL2-permitted proofing pathways defined in SP 800-63A-4: Non-Biometric, Digital Evidence, or Biometric verification
Configure your chosen IDV vendor's workflow to collect the evidence types required by that pathway (e.g. a biometric selfie match for the Biometric pathway)
Document your pathway choice and the evidence collected per applicant so you can demonstrate IAL2 conformance during an audit
Reassess your configuration whenever NIST publishes updates to SP 800-63A, since specific pathway requirements can change between revisions
Known gotchas
IAL2 is evidence-based proofing, distinct from IAL1 (self-asserted, no proofing) and IAL3 (on-site, attended, biometric-required) — configuring an IAL1-level flow while claiming IAL2 conformance is a common compliance gap
The three IAL2 pathways (Non-Biometric, Digital Evidence, Biometric) have different evidence-strength requirements — mixing partial requirements from different pathways does not constitute a valid configuration
SP 800-63-4 superseded prior 800-63-3-era assumptions, so integrations documented against the older revision may reference outdated pathway names or requirements
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?