IAL (Identity Assurance Level) rates identity proofing: IAL1 attributes exist, IAL2 evidence verified, IAL3 in-person plus biometric.
Three scales, one question: how much do you trust this identity?
When a US government agency, a bank, or an enterprise security team asks 'how strong is this login?', the answer is usually expressed in three-letter scales from NIST's Digital Identity Guidelines: IAL for how thoroughly the person's identity was proven, AAL for how securely they authenticate each time, and FAL for how trustworthy the assertion is when an identity provider hands it to another service. The current revision, SP 800-63-4, replaced 800-63-3 and shifted the whole framework from checklist compliance toward risk-based decisions. If you evaluate e-signature or identity-verification vendors that serve US customers, these acronyms appear in their security documentation — and increasingly in procurement questionnaires far beyond government.
At a glance
The three scales, one line each.
AAL (Authentication Assurance Level) rates login strength: AAL1 basic, AAL2 two factors with approved crypto, AAL3 hardware-backed phishing-resistant.
FAL (Federation Assurance Level) rates how safely an identity is asserted across systems, from FAL1 anti-forgery to FAL3 IdP-compromise resistance.
SP 800-63-4 is current: published in 2025 as a four-volume suite, it supersedes 800-63-3 and adds the risk-based DIRM process.
The levels are independent: a workflow can need strong authentication (AAL2) without strong proofing (IAL1) — anonymous-but-authenticated is a valid combination.
What each level actually requires
The practical difference between levels, in the language a security reviewer uses.
| Level 1 | Level 2 | Level 3 | |
|---|---|---|---|
| IAL — proofing | Attributes exist and match a real identity | Remote evidence checked, selfie or doc verification typical | On-site with trained agent plus biometric comparison |
| AAL — authentication | Single or multi-factor, basic confidence | Two distinct factors, approved cryptography | Hardware-backed, phishing-resistant, non-exportable keys |
| FAL — federation | Assertions protected against forgery | Plus protection against assertion injection | Plus resistance to identity-provider compromise |
| Typical business case | Consumer accounts, low-value agreements | Contracts, HR workflows, most B2B e-signing | Regulated approvals, high-value cross-border execution |
| Verification burden | Minutes, automated | Minutes to days, document + liveness | Appointment-based, manual review |
What SP 800-63-4 changed (and why vendors cite it now)
The 2025 revision is not a cosmetic update; several changes shape what modern identity products advertise.
Risk management replaces checkbox compliance
The new Digital Identity Risk Management (DIRM) process makes agencies and enterprises choose levels by analyzing impact and fraud exposure rather than defaulting everything to the highest level. Expect vendors to pitch 'right-sized assurance' instead of maximum everything.
IAL1 was repurposed to fight synthetic identity
Level 1 now explicitly covers validation that a claimed identity really exists — a direct response to synthetic-identity fraud in remote enrollment.
Phishing-resistant authentication moved from nice-to-have to core
AAL3's hardware-backed authenticators and the revised AAL2 requirements reflect the post-phishing threat model; passkeys and FIDO2 align naturally with it.
Digital wallets and verifiable credentials are first-class
800-63-4 prepares for subscriber-controlled wallets acting as the identity provider — the same architectural direction as the EU's eIDAS 2.0 wallet, which makes these guidelines globally relevant reading.
Automated enrollment attacks are addressed
New requirements target bots and scripted attacks against enrollment, which is where most remote-onboarding fraud starts.
Choosing levels for e-signature workflows
A practical mapping most teams can defend in review.
Low-value, high-volume agreements
IAL1 with AAL1 or AAL2: click-to-accept NDAs, simple consents. The cost of stronger proofing outweighs the fraud exposure.
Standard B2B contracts
IAL2 with AAL2: verify the signer's document once, then require two-factor access. This is the level most enterprise e-signature deployments should be able to evidence.
High-value or regulated execution
IAL2-3 with AAL2-3: cross-border deals, regulated approvals. Pair with qualified signatures under eIDAS where applicable — the frameworks overlap but are not substitutes; 800-63 is risk guidance, eIDAS is law.
Anonymous but authenticated
Proofing and authentication are separable: a whistleblower portal or a public-service application may need AAL3 login with IAL1 (no identity collected at all). SP 800-63-4 makes this combination explicitly legitimate.
Common questions
No. SP 800-63 is guidance for US federal agencies, but it has become the de facto vocabulary for identity assurance across banking, healthcare, and enterprise procurement worldwide. Vendors cite conformance to signal rigor, and many non-US regulators use comparable frameworks.







