Obtain the final SP 800-63-4 suite (published July 2025), which supersedes 800-63-3; note it is split into 800-63, 800-63A-4, 800-63B-4, and 800-63C-4 volumes.
For IAL2 remote proofing (800-63A-4): collect at minimum one piece of Superior evidence or two pieces of Strong evidence; verify document authenticity with automated forensic checks; perform biometric comparison of the selfie to the document photo.
Confirm liveness / presentation attack detection meets the evidence-binding requirement; ISO 30107-3 PAD Level 1 or higher is the common vendor certification reference.
For AAL2 (800-63B-4): require a phishing-resistant authenticator (e.g., FIDO2 passkey or hardware security key) or a combination of a memorized secret plus an OTP or push authenticator; syncable passkeys are now explicitly permitted at AAL2.
Adopt the Digital Identity Risk Management (DIRM) framework introduced in the final release: document the xAL selection rationale based on potential harms, mission impact, and population considerations rather than a checklist.
Audit Knowledge-Based Verification (KBV) usage: KBV is prohibited for authentication at any AAL; for identity proofing it may only be used for resolution or as a single Fair-level evidence supplement, not as the sole verification method.
Known gotchas
SP 800-63-4 was finalized in July 2025; older guidance documents referencing 800-63-3 are superseded — verify which revision your agency's policy references before building compliance artifacts.
Syncable passkeys are permitted at AAL2 in 800-63B-4 but federal agencies bound by OMB or FISMA policy may impose additional restrictions above the NIST baseline; check agency-specific supplemental requirements.
KBV and knowledge-based authentication (KBA) are treated differently in 800-63-4: KBV (identity proofing) has narrow permitted uses, while KBA (authentication) is entirely prohibited — conflating the two is a common compliance error.
Give your agent this knowledge — and 200+ more routes
One MCP install gives any agent live access to the full route map, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp