eSign.AIeSign.AI

Glossary

IAL, AAL and FAL: NIST's Identity Assurance Levels, Explained

IAL, AAL and FAL are the three assurance scales in NIST SP 800-63-4 that rate how strongly an identity was proofed and how securely it authenticates. Here is what each level demands and how to choose.

eSign.AI Digital Trust Research Team6 min read

Three scales, one question: how much do you trust this identity?

When a US government agency, a bank, or an enterprise security team asks 'how strong is this login?', the answer is usually expressed in three-letter scales from NIST's Digital Identity Guidelines: IAL for how thoroughly the person's identity was proven, AAL for how securely they authenticate each time, and FAL for how trustworthy the assertion is when an identity provider hands it to another service. The current revision, SP 800-63-4, replaced 800-63-3 and shifted the whole framework from checklist compliance toward risk-based decisions. If you evaluate e-signature or identity-verification vendors that serve US customers, these acronyms appear in their security documentation — and increasingly in procurement questionnaires far beyond government.

At a glance

The three scales, one line each.

01

IAL (Identity Assurance Level) rates identity proofing: IAL1 attributes exist, IAL2 evidence verified, IAL3 in-person plus biometric.

02

AAL (Authentication Assurance Level) rates login strength: AAL1 basic, AAL2 two factors with approved crypto, AAL3 hardware-backed phishing-resistant.

03

FAL (Federation Assurance Level) rates how safely an identity is asserted across systems, from FAL1 anti-forgery to FAL3 IdP-compromise resistance.

04

SP 800-63-4 is current: published in 2025 as a four-volume suite, it supersedes 800-63-3 and adds the risk-based DIRM process.

05

The levels are independent: a workflow can need strong authentication (AAL2) without strong proofing (IAL1) — anonymous-but-authenticated is a valid combination.

What each level actually requires

The practical difference between levels, in the language a security reviewer uses.

Level 1Level 2Level 3
IAL — proofingAttributes exist and match a real identityRemote evidence checked, selfie or doc verification typicalOn-site with trained agent plus biometric comparison
AAL — authenticationSingle or multi-factor, basic confidenceTwo distinct factors, approved cryptographyHardware-backed, phishing-resistant, non-exportable keys
FAL — federationAssertions protected against forgeryPlus protection against assertion injectionPlus resistance to identity-provider compromise
Typical business caseConsumer accounts, low-value agreementsContracts, HR workflows, most B2B e-signingRegulated approvals, high-value cross-border execution
Verification burdenMinutes, automatedMinutes to days, document + livenessAppointment-based, manual review

What SP 800-63-4 changed (and why vendors cite it now)

The 2025 revision is not a cosmetic update; several changes shape what modern identity products advertise.

Risk management replaces checkbox compliance

The new Digital Identity Risk Management (DIRM) process makes agencies and enterprises choose levels by analyzing impact and fraud exposure rather than defaulting everything to the highest level. Expect vendors to pitch 'right-sized assurance' instead of maximum everything.

IAL1 was repurposed to fight synthetic identity

Level 1 now explicitly covers validation that a claimed identity really exists — a direct response to synthetic-identity fraud in remote enrollment.

Phishing-resistant authentication moved from nice-to-have to core

AAL3's hardware-backed authenticators and the revised AAL2 requirements reflect the post-phishing threat model; passkeys and FIDO2 align naturally with it.

Digital wallets and verifiable credentials are first-class

800-63-4 prepares for subscriber-controlled wallets acting as the identity provider — the same architectural direction as the EU's eIDAS 2.0 wallet, which makes these guidelines globally relevant reading.

Automated enrollment attacks are addressed

New requirements target bots and scripted attacks against enrollment, which is where most remote-onboarding fraud starts.

Choosing levels for e-signature workflows

A practical mapping most teams can defend in review.

Low-value, high-volume agreements

IAL1 with AAL1 or AAL2: click-to-accept NDAs, simple consents. The cost of stronger proofing outweighs the fraud exposure.

Standard B2B contracts

IAL2 with AAL2: verify the signer's document once, then require two-factor access. This is the level most enterprise e-signature deployments should be able to evidence.

High-value or regulated execution

IAL2-3 with AAL2-3: cross-border deals, regulated approvals. Pair with qualified signatures under eIDAS where applicable — the frameworks overlap but are not substitutes; 800-63 is risk guidance, eIDAS is law.

Anonymous but authenticated

Proofing and authentication are separable: a whistleblower portal or a public-service application may need AAL3 login with IAL1 (no identity collected at all). SP 800-63-4 makes this combination explicitly legitimate.

Common questions

No. SP 800-63 is guidance for US federal agencies, but it has become the de facto vocabulary for identity assurance across banking, healthcare, and enterprise procurement worldwide. Vendors cite conformance to signal rigor, and many non-US regulators use comparable frameworks.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.