Skip to main content

NIST's New IAL3 Conformance Criteria: A Checklist for FedRAMP High Teams

5 min read
NIST's New IAL3 Conformance Criteria: A Checklist for FedRAMP High Teams

On September 30, 2026, NIST published conformance criteria for its Digital Identity Guidelines, SP 800-63-4, as part of a new implementation resource hub. Every requirement is now a numbered control with NIST's own wording, its objective, and how to assess it. For teams pursuing FedRAMP High (Class D) that need IAL3 identity proofing, this is the checklist that matters.

NIST does not certify anyone against these criteria. They are public, in Excel, PDF, and OSCAL, so agencies and assessors can evaluate any provider directly. NIST also encourages assessors to test controls in operation instead of relying on paperwork alone.

The criteria add no new requirements. They make the existing ones testable, which raises the bar for every IAL3 claim. Whatever assessment or certification a provider presents, check its scope, the guideline revision it covers, when it was done, and the operational evidence behind it. Public criteria let you and your assessor check the controls yourselves, whenever you need to. That is the standard we hold ourselves to, and it is why we run a public IAL3 biometric spoof challenge.

NIST IAL3 conformance criteria, in brief:

  • The requirement: NIST SP 800-63A-4 defines 24 controls that apply only at IAL3, numbered IAL3-1 to IAL3-24, on top of the general requirements that apply at every assurance level.
  • The standard: IAL3 is on-site attended. A trained proofing agent attends every session, in the room or through a CSP-controlled kiosk or device, and the provider collects and retains a biometric sample.
  • The solution: Trust Swiftly runs every IAL3 session on a managed kit at an approved private location, with a live agent on high-resolution video, and shares a control-by-control mapping with agencies, assessors, and customers under NDA.

What IAL3 Requires Under Revision 4

Revision 4 sets IAL3 apart by how proofing happens. The evidence rules match IAL2: one SUPERIOR piece, two STRONG, or one STRONG plus one FAIR. NIST's own FAQ confirms that an issuer-signed, device-bound mobile driver's license counts as SUPERIOR evidence.

What sets IAL3 apart:

  • On-site attended, every time. A trained proofing agent attends every session, in the room or through a CSP-controlled kiosk or device (§4.3.1). Earlier revisions called this remote-agent model supervised remote identity proofing.
  • A biometric, collected and retained. The provider captures a biometric sample during proofing and keeps it (§4.3.3).
  • A controlled station. The station's own sensors read chips and digital IDs, and the station is protected from tampering and inspected (§4.3.8).
  • A notice after proofing. The applicant is notified at a validated address once proofing succeeds (§4.3.9).
  • An authenticator enrolled in person. The first authenticator is distributed or enrolled during an on-site attended interaction with a proofing agent. Enrolling it outside that session requires a biometric comparison against the proofing sample first (§4.3.10). Trust Swiftly enrolls the initial authenticator during the proofing session itself.

The 24 IAL3 Controls, and How We Meet Them

NIST lists 24 controls that apply only at IAL3, numbered IAL3-1 to IAL3-24. The table summarizes how we meet them in five groups. The full control-by-control mapping is available under NDA.

Group NIST controls What Trust Swiftly does
Where proofing happens IAL3-1, IAL3-7, IAL3-11 Every IAL3 session runs on a Trust Swiftly kit at an approved private location: a company office, a private office, or a private home workspace. Never a public space. Proofing agents work on managed systems behind multi-factor sign-in and role-based access.
The live agent IAL3-12 to IAL3-17 A trained proofing agent attends every session on live high-resolution video and guides each step. Applicants are told about recording and accept it before it starts, and recordings are kept only for the retention period stated to them. Agents can flag suspected fraud quietly, without stopping the session.
The kit IAL3-18 to IAL3-21 Only enrolled, attested kits on our allow-list can run a session. The kit's own reader handles passport chips and mobile IDs. Kits run under administrator-only management with platform malware protections and a software update process. Each kit is checked before it ships and inspected when it returns.
Evidence and biometrics IAL3-2 to IAL3-6, IAL3-8 to IAL3-10 Passport chips and mobile driver's licenses are verified against their issuer's digital signature. The agent compares the applicant with the ID photo, backed by an automated comparison.
After the session IAL3-22 to IAL3-24 The applicant gets a notice of proofing at a validated address. Their hardware security key is enrolled during the session, and any authenticator bound later, outside the session, needs a biometric comparison against the proofing sample first. The customer receives a signed evidence package.

How We Control the Proofing Location and the Kit

Revision 4 places on-site attended proofing where "the physical location and devices are controlled by the CSP." The guideline does not prescribe how. We control each session's location in layers, and we control the kit at every step.

  • Approved before the kit ships. Kits go only to private, non-public locations: a company office, a private office, or a private home workspace. Public and shared spaces are not allowed.
  • Confirmed during use. The kit confirms where it is with several independent signals, including its satellite position, the networks around it, and its own motion and environment sensors. It reports in over signed, hardware-attested connections.
  • Never outside our control. Each kit checks its own integrity before it connects, reaches our service only with credentials issued to that enrolled device, and stores no session data locally.
  • Watched for the whole session. A live agent sees the session on high-resolution video from evidence collection through verification.

Assessors can test these controls directly: review the location policy, sample a kit's custody and inspection history, and watch a live session.

Owning the premises is not what makes a location controlled. A kiosk in a public lobby sits in a building its operator does not own, open to anyone and unattended between sessions. A Trust Swiftly kit is never in a public space and never outside our management, and your people never travel to a public counter.

A Trust Swiftly kit goes back into service only after a recorded inspection Kit lifecycle. A kit gets a pre-ship check of its charge and condition, ships only to an approved private location, and hosts an attended IAL3 session with a live agent while its location is verified. It returns to Trust Swiftly tracked in transit and is inspected, and the inspection is recorded. A kit that passes goes back to the pre-ship check. A damaged kit is removed from service. Pre-ship check Charge and condition Ship to approved site Private, non-public only Attended IAL3 session Agent live, location verified Return to Trust Swiftly Tracked in transit Inspect on return Inspection recorded Removed from service Flagged by the agent Passes Damaged
Every kit is checked before it ships and inspected when it returns. Only a recorded inspection puts it back into service.

Kits ship to all 50 states and more than 32 countries.

Questions to Ask Any IAL3 Provider

Ask with NIST's control IDs, and ask for artifacts rather than assurances.

  1. Which revision of SP 800-63 is your IAL3 service built and assessed against, and when was it assessed?
  2. Is every IAL3 session on-site attended, and where do sessions take place? (IAL3-1, IAL3-7)
  3. Do your station's own sensors read chips and digital IDs, or can an applicant's personal phone submit evidence? (IAL3-18)
  4. Who controls the station between sessions? Show a redacted inspection record. (IAL3-19 to IAL3-21)
  5. How do you verify SUPERIOR evidence back to a trust anchor? (IAL3-5)
  6. How long do you retain the biometric sample, and where do applicants see that retention period? (§4.3.3)
  7. Provide the recording notice, the consent step, and the video retention schedule applicants see. (IAL3-13)
  8. Show the notice of proofing an applicant receives, and how you validate the address it goes to. (IAL3-22)
  9. Demonstrate authenticator enrollment, and explain how you handle enrollment outside the attended session. (IAL3-23, IAL3-24)
  10. Will you share a control-by-control mapping to NIST's criteria, and let our assessor test it?

For the records your assessor will ask for once you choose, see our FedRAMP High IAL3 audit evidence checklist. For broader selection criteria, see IAL3 best practices for enterprise identity proofing.

Frequently Asked Questions

What are the NIST SP 800-63-4 conformance criteria?

They restate every SHALL statement in SP 800-63-4 as a numbered control, with its objective, an assessment method, the section it comes from, and the assurance level it applies to. NIST published version 0.1 on September 30, 2026, in Excel, PDF, and OSCAL formats.

How many NIST controls apply only at IAL3?

Twenty-four, numbered IAL3-1 to IAL3-24. They cover the on-site attended proofing type, evidence collection and validation, verification, the secure setting, kiosk monitoring and tamper protection, notification of proofing, and authenticator binding. General requirements for fraud management, privacy, and biometrics apply at every assurance level on top of them.

Does NIST certify IAL3 providers?

No. NIST states that it does not conduct certification or conformity assessment against these criteria. Agencies and assessors use them to evaluate a provider directly.

Can IAL3 identity proofing happen without travel to an enrollment center?

Yes. Revision 4 lets the proofing agent attend through a CSP-controlled kiosk or device instead of sitting in the same room. Trust Swiftly ships kits to approved private locations, such as a company office or a private home workspace, and a live agent attends every session over high-resolution video.

Is a mobile driver's license accepted as IAL3 evidence?

Yes, when it meets NIST's bar. NIST's FAQ states that an ISO/IEC 18013-5 mobile driver's license that is signed by the issuer, cryptographically bound to the device, and carries the same attributes as the physical license qualifies as SUPERIOR evidence for IAL1, IAL2, and IAL3.

Get Our IAL3 Conformance Mapping

We share a control-by-control mapping of our IAL3 service to all 24 IAL3 controls with agencies, assessors, and customers under NDA. We also offer a walkthrough of a live session on a kit. Contact us to request either.

Share: X LinkedIn

About the Trust Swiftly Team

We publish practical guidance on identity assurance, fraud prevention, and FedRAMP-aligned controls for high-risk workflows.

Comments