FB pixel

ATARC publishes implementation guide for NIST SP 800-63-4

Document explains how agencies and vendors can apply NIST's new digital identity framework
ATARC publishes implementation guide for NIST SP 800-63-4
 

Organizations preparing to implement NIST SP 800-63-4 now have a practical roadmap to accompany the new digital identity standard. This month, the ATARC Identity Management Working Group published “Implementation Guide: Transitioning from NIST SP 800-63-3 to SP 800-63-4,” a companion document that translates NIST’s requirements into actionable implementation guidance. Rather than introducing new requirements, the guide explains how organizations can operationalize the significant changes introduced to SP 800-63-4 by NIST in 2025.

The guide was developed by members of the ATARC Identity Management Working Group, a collaboration of public- and private-sector identity experts. Contributors include representatives from the U.S. Department of Health and Human Services, the U.S. Army, the Department of Veterans Affairs, Ping Identity, Yubico, LC&J Security Solutions, Seventeen Sierra, and other organizations involved in federal identity management.

The implementation guide is intended for the teams responsible for designing, implementing, procuring, and governing digital identity services. That includes federal agencies preparing for SP 800-63-4 adoption, identity architects, cybersecurity and IT managers, compliance professionals, and technology providers supporting government identity programs. It is also relevant for organizations consuming third-party identity services, as the new framework extends beyond internally managed identity systems.

One important implication for relying parties is that the Digital Identity Risk Management (DIRM) process applies not only to identity services they operate, but also to external identity providers, credential service providers, and cloud-based digital services they rely upon. Organizations are expected to review the Digital Identity Acceptance Statements (DIAS) provided by those service providers and incorporate them into their own risk management decisions, making digital identity assurance a shared responsibility across the identity ecosystem.

At the center of the guide is the new Digital Identity Risk Management (DIRM) process, which represents one of the most significant changes in SP 800-63-4. Rather than selecting Identity Assurance Levels (IAL) and Authentication Assurance Levels (AAL) as static design decisions, organizations are expected to perform a structured risk assessment for every online service. The process begins by identifying all affected stakeholder groups — both internal and external — along with the data being processed and applicable legal and regulatory requirements. Organizations then assess the potential harm to each stakeholder group if the service is compromised, categorize those impacts as Low, Moderate, or High, and use the results to establish baseline IAL, AAL, and, where applicable, Federation Assurance Levels (FAL).

Those baseline assurance levels are then refined through the framework’s “Tailoring” process, which requires organizations to perform mandatory privacy, customer experience, and threat resistance assessments before determining whether additional or compensating controls are needed. The analyses are documented in the Digital Identity Risk Assessment (DIRA), with the final decisions formally captured in the Digital Identity Acceptance Statement (DIAS). The guide also covers new operational requirements, including formal user redress processes, governance of AI and machine learning systems, and continuous evaluation of digital identity controls over time.

Preparations for the transition to the new revision of the standard across the industry also include the Kantara Initiative’s recent publication of certification criteria for SP 800-63-4 Base Volume, SP 800-63A and SP 800-63B.

Related Posts

Article Topics

 |   |   |   | 

Latest Biometrics News

 

Biometrics consolidation reflects shift to continuous identity

AI-driven fraud is reshaping the biometrics industry. This week’s acquisitions, product launches and market developments all point toward the same…

 

Australia’s national face matching system expands with NSW participation

New South Wales (NSW) is joining Australia’s national face matching network, allowing driver licence and photo card images to be…

 

From behavior to payment: Visa builds trust across the customer lifecycle

Visa’s agreement to acquire BioCatch for $2.4 billion raises an important strategic question: Why would a global payments network invest…

 

Why deepfake detection is becoming trust infrastructure

For many, the word “deepfake” still has a twinge of novelty about it – a hint of science fiction. But…

 

Brazil age assurance challenge overlooks privacy-preserving options

Where there are online safety laws, there is litigation aiming to curb them. So it goes in Brazil, where the…

 

Post-quantum identity expands beyond cryptography

As governments and enterprises prepare for practical quantum computing, the focus has largely been on post-quantum cryptography. IBM is targeting…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events