Skip to main content
Home > Solutions > Solutions by Standard > Authentication assurance levels. AAL3, achieved.

Authentication assurance levels.
AAL3, achieved.

NIST SP 800-63B defines the federal technical requirements for authentication. MyID delivers AAL3, the highest level, using phishing-resistant FIDO2 and PKI credentials.

Authentication assurance levels. AAL3, achieved.
Standards · NIST SP 800-63B

Authentication assurance levels, achieved.

NIST Special Publication 800-63B defines the technical requirements for federal authentication. MyID achieves the highest assurance level, AAL3, with FIDO2 hardware keys and PKI smart cards.

AAL3

Multi-factor cryptographic authentication, with hardware-bound keys verifier-impersonation resistant. MyID achieves AAL3 out of the box.

Phishing-resistant

Credentials cryptographically tied to the legitimate verifier, fake login pages cannot harvest them.

FIPS 140-2/3

Cryptographic modules required at AAL3, MyID supports FIPS-validated HSMs and smart card chips.

Why this matters

AAL3 is the federal authentication target. Most products only deliver AAL2.

NIST SP 800-63B defines three authenticator assurance levels. AAL3 is the highest, it requires multi-factor cryptographic authentication, hardware-bound keys, verifier-impersonation resistance, and FIPS 140-validated cryptographic modules. Most authentication products in the market deliver AAL2 (push notifications, OTP) and stop there. MyID issues credentials that cleanly meet AAL3: PKI smart cards and FIDO2 hardware keys, both with hardware-bound private keys and phishing-resistant verification. The same credentials work for AAL1 and AAL2 use cases too, one platform, one credential lifecycle, all three assurance levels.

AAL1
Some confidence
Single-factor authentication, low-risk applications.
AAL2
High confidence
Multi-factor with software cryptographic authenticator.
AAL3
Very high confidence
Hardware-bound cryptographic auth, phishing-resistant. MyID delivers this.
Frequently Asked Questions

Common questions

Need something specific? Contact our team →

AAL2 requires two factors but allows software-based cryptographic authenticators (e.g., FIDO2 platform authenticator on a phone). AAL3 requires hardware-bound keys, verifier-impersonation resistance and FIPS 140-validated cryptographic modules. AAL3 is the federal target for sensitive systems.

Yes. MyID issues credentials onto FIPS 140-2 and FIPS 140-3 validated smart cards (Idemia, Gemalto, Swissbit, Yubico) and supports FIPS 140 validated HSMs such as Thales Luna and Entrust nShield (cloud HSM services including AWS CloudHSM and Azure Dedicated HSM are also supported) for the issuing CA.

Yes. The same MyID platform issues AAL3 PIV cards for high-risk systems while supporting AAL2 push and AAL1 OTP for lower-risk applications. Risk-based authentication policy decides which credential satisfies which application.

Yes. MyID is a GSA Approved Products List entry under FIPS 201 PIV and is deployed across multiple federal agencies including DoD, civilian departments and the intelligence community.

NIST 800-63B Compliance

Meet NIST 800-63B with MyID.

Our solutions architects can show you how MyID maps to NIST 800-63B authentication assurance levels.