Digital identity governance — NIST SP 800-63-4
Proofing 800-63A-4 · Authentication 800-63B-4 · Federation 800-63C-4 · IAL2/AAL2/FAL2 floor, step-up to IAL3/AAL3
Safe degradation active. Login.gov is unavailable — gates relying on it now default to Hold / Fail, never Pass. Adjudication requires an alternate approved CSP or PIV/CAC.
WALKTHROUGH · STEP {{ walkStep }}/8 {{ walkText }}
GATE {{ st.gateN }} ▸ click {{ st.n }} {{ st.role }} {{ st.name }} {{ st.detail }}
✓ Pass–Proceed ⏸ Hold–Step-up Required ✗ Fail–Return to PMO Outcome model
Approved Credential Service Providers
{{ c.name }}
PIV/CAC is the primary authenticator for Federal employees (HSPD-12, FIPS 201-3) and satisfies AAL3. Commercial CSPs serve principally external vendor / non-PIV users.
Recent gate executions
{{ r.po }} Gate {{ r.gate }} {{ r.assert }} {{ r.outcome }}
G{{ modalGate }}
Governance Gate {{ modalGate }} — {{ gateWhere }}
NIST SP 800-63-4 identity verification · executing against PO-48310
IAL — 800-63A-4
IAL2 floor
Step-up to IAL3 for high-value / sensitive actions
AAL — 800-63B-4
AAL3 via PIV/CAC
PIV/CAC satisfies AAL3 for internal Federal users (FIPS 201-3)
FAL — 800-63C-4
FAL2 floor
Federation assertions signed & encrypted
{{ c.mark }} {{ c.label }} {{ c.meta }}
{{ outcomeMark }}
{{ outcome }}
{{ outcomeDetail }}