NIST Digital Identity Guidelines (SP 800-63-4): from draft to final
NIST's rewrite of the Digital Identity Guidelines reached final publication in July 2025 after roughly four years and about 6,000 public comments. It brings syncable passkeys into scope, admits subscriber-controlled wallets to the federation model, and adds controls for injection attacks and forged media.
NIST published a public draft of SP 800-63-4 in August 2024 and finalised the revision in July 2025. It took roughly four years and about 6,000 public comments, which is a fair measure of how contested the previous edition had become.
Four changes matter most. Syncable authenticators, meaning passkeys that sync across a vendor's cloud, are explicitly in scope rather than an awkward fit, which removes the main excuse for treating them as unsuitable in regulated environments. The federation model admits subscriber-controlled wallets, aligning it with verifiable credentials work. New controls address injection attacks and forged media, deepfakes included, the first time synthetic media appears as a proofing threat. Identity proofing itself is restructured around clearer roles and expanded fraud requirements.
Why it matters
If you have been told that synced passkeys cannot meet a compliance bar, this is the document that settles the argument. 800-63-4 is what US federal agencies work to and what auditors in regulated industries reach for, so its treatment of an authenticator type effectively decides whether that type is deployable. Revisit any passwordless strategy scoped against 800-63-3 assumptions, and ask your identity proofing vendor what it does about forged media, because the guidelines now expect an answer.
Source: NIST SP 800-63-4
Related on Start with Identity
- BlogA loose PHP comparison let attackers sign in as WordPress admin through SAML
Two unauthenticated bypasses in the miniOrange SAML 2.0 Single Sign On plugin, CVE-2026-61979 and CVE-2026-15981, treat OpenSSL's error return as a valid signat
- BlogEMVCo drafts one credential standard so merchants stop building per-wallet integrations
EMVCo published a draft framework for verifiable digital credentials in card-based payments, aimed at giving merchants one consistent data structure to authenti
- BlogGoogle and Mastercard's answer to "can I trust an AI agent to pay for this" is a cryptographic mandate
Google's Agent Payments Protocol and Mastercard's Verifiable Intent framework, both contributed to the FIDO Alliance for standardization, define how an AI agent
- GlossaryNIST SP 800-63
The US National Institute of Standards and Technology Digital Identity Guidelines. Defines Identity Assurance Levels (IAL), Authenticator Assurance Levels (AAL)
- CVECitrix Bleed, session-token leak from NetScaler ADC
A buffer over-read on NetScaler ADC/Gateway leaked session tokens in the clear. Attackers replayed them and skipped the login, including MFA. CISA KEV. October
- GlossaryDigital Identity Wallet
An app or service that stores a holder's decentralized identifiers and verifiable credentials and manages consent when presenting them. Government wallets such