
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

NIST has launched an online hub of implementation resources for the latest revision of its Digital Identity Guidelines, adding FAQs, conformance criteria and guidance on digital wallets more than a year after SP 800-63-4 was finalized.
Summary
The agency describes the site, which went live October 6, as a “one-stop hub” for putting SP 800-63 Revision 4 into practice. It does not create new requirements. The normative requirements remain in SP 800-63-4 and its companion volumes, and the hub’s materials explain and illustrate them.
The hub is aimed at teams that design, buy, run and govern digital identity services, including federal agencies preparing to adopt the revision, identity architects, compliance professionals and technology providers. It is also relevant to organizations that rely on third-party identity services. The initial FAQs cover questions NIST says it hears from agencies and credential service providers, including core attributes, authoritative and credible sources, trusted referees, password requirements and password managers.
NIST has also released version 0.1 of its conformance criteria, which organize the normative requirements across all four SP 800-63-4 volumes into structured controls for evaluating identity services. The criteria are available in Excel and PDF, as well as OSCAL formats including JSON, XML and YAML, allowing use in automated assessment tools. NIST says it does not conduct certification or conformity assessments against the criteria.
Kantara Initiative separately has published service assessment criteria for the SP 800-63-4 base volume, SP 800-63A-4 identity proofing and SP 800-63B-4 authentication as part of its assessment and certification framework. The launch also includes two additional resources. One explains the subscriber-controlled wallet model for verifiable digital credentials, including mobile driver’s licenses (mDLs), and points implementers to mDL work at the National Cybersecurity Center of Excellence (NCCoE).
The other is an authenticator reference that compares authentication methods on characteristics such as replay resistance and phishing resistance. From guidelines to working systems NIST finalized Revision 4 in July 2025, but the standards alone do not answer every question agencies and providers encounter when translating requirements into working identity systems. The new hub gives implementers a common reference point for interpreting requirements, assessing conformance and designing deployments.
NIST says shared implementation guidance and conformance criteria are intended to support more consistent implementation and reduce duplication across agencies and providers. The same gap has shown up in NIST’s work on mDLs. As Biometric Update reported in July 2026, NIST Identity Program Lead Ryan Galluzzo said many relying parties know about the technology but have not worked out how to fit it into their online workflows.
He said organizations need hands-on experience to decide what implementations, requirements and procurement should look like, and that compliance, governance and risk teams must understand the technology before adoption can move ahead. Galluzzo says “the only way to understand how it works, what your implementations are going to look like, what your requirements are going to be, what your procurements are going to be expected to look like, is to start putting those things into place, testing them out and understanding how you can get some data around usage.” NIST is not the only source of implementation support. In July 2026, the ATARC Identity Management Working Group published “Implementation Guide: Transitioning from NIST SP 800-63-3 to SP 800-63-4,” a roadmap for federal agencies moving to the revised framework.
More to come NIST calls the materials living resources and is taking questions and suggested updates at [email protected] and through GitHub issues. Reference architectures, webinars, blogs and interactive tools are planned. Among them is a Digital Identity Risk Management (DIRM) Tool, listed on the hub as “coming soon.” It is intended to walk organizations through the risk management process in SP 800-63-4, from defining an online service and assessing potential impacts to selecting and tailoring assurance levels.
KazaSec's take
Phishing and credential-based attacks succeed because they target people, not just infrastructure, technical controls like SPF, DKIM, and DMARC only ever close part of that gap. The rest comes down to whether a team can actually spot the fake, and whether a compromised credential can still be reused anywhere else.
Coverage details
We've archived 9 other articles touching the same topic (digital identity, civil / national id, biometrics news) , see the full security news archive.
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.