Skip to main content
U.S. flag

An official website of the United States government

Digital Identity Guidelines [including updates as of 12-01-2017]

Published

Author(s)

Paul A. Grassi, James L. Fenton, Michael E. Garcia

Abstract

These guidelines provide technical requirements for federal agencies implementing digital identity services and are not intended to constrain the development or use of standards outside of this purpose. The guidelines cover identity proofing and authentication of users (such as employees, contractors, or private individuals) interacting with government IT systems over open networks. They define technical requirements in each of the areas of identity proofing, registration, authenticators, management processes, authentication protocols, federation, and related assertions. This publication supersedes NIST Special Publication 800-63-2. [Supersedes SP 800-63-3(June 2017): https://www.nist.gov/publications/digital-identity-guidelines]
Citation
Special Publication (NIST SP) - 800-63-3
Report Number
800-63-3

Keywords

authentication, authentication assurance, authenticator, assertions, credential service provider, digital authentication, digital credentials, identity proofing, federation, passwords, PKI

Citation

Grassi, P. , Fenton, J. and Garcia, M. (2017), Digital Identity Guidelines [including updates as of 12-01-2017], Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.SP.800-63-3 (Accessed April 2, 2025)

Issues

If you have any questions about this publication or are having problems accessing it, please contact reflib@nist.gov.

Created December 1, 2017, Updated January 27, 2020