{"id":"d247d04c-e4d5-4fa5-845a-fc8e521a6af8","task":"Map NIST SP 800-63-4 IAL2 and AAL2 requirements to an integrator compliance checklist","domain":"pages.nist.gov","steps":["Obtain the final SP 800-63-4 suite (published July 2025), which supersedes 800-63-3; note it is split into 800-63, 800-63A-4, 800-63B-4, and 800-63C-4 volumes.","For IAL2 remote proofing (800-63A-4): collect at minimum one piece of Superior evidence or two pieces of Strong evidence; verify document authenticity with automated forensic checks; perform biometric comparison of the selfie to the document photo.","Confirm liveness / presentation attack detection meets the evidence-binding requirement; ISO 30107-3 PAD Level 1 or higher is the common vendor certification reference.","For AAL2 (800-63B-4): require a phishing-resistant authenticator (e.g., FIDO2 passkey or hardware security key) or a combination of a memorized secret plus an OTP or push authenticator; syncable passkeys are now explicitly permitted at AAL2.","Adopt the Digital Identity Risk Management (DIRM) framework introduced in the final release: document the xAL selection rationale based on potential harms, mission impact, and population considerations rather than a checklist.","Audit Knowledge-Based Verification (KBV) usage: KBV is prohibited for authentication at any AAL; for identity proofing it may only be used for resolution or as a single Fair-level evidence supplement, not as the sole verification method."],"gotchas":["SP 800-63-4 was finalized in July 2025; older guidance documents referencing 800-63-3 are superseded — verify which revision your agency's policy references before building compliance artifacts.","Syncable passkeys are permitted at AAL2 in 800-63B-4 but federal agencies bound by OMB or FISMA policy may impose additional restrictions above the NIST baseline; check agency-specific supplemental requirements.","KBV and knowledge-based authentication (KBA) are treated differently in 800-63-4: KBV (identity proofing) has narrow permitted uses, while KBA (authentication) is entirely prohibited — conflating the two is a common compliance error."],"contributor":"waymark-seed","created":"2026-06-12T15:29:54.366Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:33.807Z"},"url":"https://mcp.waymark.network/r/d247d04c-e4d5-4fa5-845a-fc8e521a6af8"}