NIST SP 800-63A Revision 4 is now the active standard for identity proofing assessments. If your team is managing Identity Assurance Level certification processes or planning to pursue IAL2/IAL3 trust marks, you're working under new criteria.
The Kantara Initiative has released the SP 800-63A-4 Service Assessment Criteria, replacing the 800-63-3A framework that's guided identity proofing assessments since 2017. This isn't a minor update. The new standard restructures how you approach evidence collection, validation, and verification. Your existing IAL processes need review.
Transition Checklist Overview
This checklist guides you through the transition from SP 800-63-3A to SP 800-63-4 assessment criteria. It's designed for IAM architects managing identity proofing systems requiring formal IAL certification, especially those serving federal agencies or operating in regulated sectors where NIST alignment is required.
You'll use this to:
- Audit your current identity proofing implementation against the new criteria.
- Identify gaps between your 800-63-3A certification and 800-63-4 requirements.
- Prepare documentation for Kantara-managed assessments.
- Plan your renewal or initial certification timeline.
Prerequisites
Before starting, ensure you have:
□ Access to the SP 800-63A-4 Service Assessment Criteria document
Request it through Kantara's form. You can't conduct a meaningful gap analysis without the actual criteria. The public-facing NIST SP 800-63A-4 standard tells you what to do; the Service Assessment Criteria tells you how assessors will measure whether you did it.
□ Your current identity proofing process documentation
Gather your evidence collection workflows, validation procedures, verification methods, and fraud detection protocols. If you hold an existing 800-63-3A trust mark, you already have this. If you're pursuing IAL certification for the first time, document your current state before comparing it to the criteria.
□ Stakeholder alignment on transition timing
Kantara encourages but doesn't require immediate transition for current trust mark holders. Decide whether to transition at renewal or migrate sooner. This decision affects your engineering roadmap, budget allocation, and re-assessment timeline.
□ Direct contact with Kantara Initiative
All assessments now go through Kantara directly at [email protected]. If you previously worked through an independent assessor, that relationship changes. Kantara assigns accredited assessors and manages the engagement.
Transition Checklist
1. Map your evidence strength requirements to the new framework
□ Done when: You've documented which evidence types (SUPERIOR, STRONG, FAIR, WEAK) you currently accept at each IAL, and identified where 800-63-4 changes the classification or acceptance rules.
Good looks like: A matrix showing old vs. new evidence categories with specific examples (e.g., mobile driver's license treatment, digital birth certificate acceptance, biometric matching thresholds).
2. Review your identity validation process for scoring changes
□ Done when: You've confirmed whether your validation logic still meets the evidence strength requirements under the updated standard.
Good looks like: Test cases demonstrating that your validation engine correctly scores evidence combinations that satisfy IAL2 or IAL3 under 800-63-4 rules, with documented changes from your 800-63-3A implementation.
3. Audit your verification methods against updated requirements
□ Done when: You've verified that your identity verification procedures (biometric comparison, knowledge-based verification, address confirmation) align with 800-63-4 specifications.
Good looks like: Side-by-side comparison of your current verification workflows and the new criteria, with flagged deviations and remediation plans.
4. Update your fraud detection and mitigation controls
□ Done when: Your fraud prevention mechanisms reflect any new threat models or detection requirements introduced in 800-63-4.
Good looks like: Updated fraud rule sets, monitoring thresholds, and incident response procedures that reference specific 800-63-4 requirements.
5. Document your privacy and security controls for Personally Identifiable Information
□ Done when: You've confirmed your PII handling, retention, and disposal practices meet the updated standard's privacy requirements.
Good looks like: Data flow diagrams showing PII lifecycle from collection through destruction, with retention periods and access controls mapped to specific criteria sections.
6. Prepare your Statement of Criteria Applicability (SoCA)
□ Done when: You've drafted your SoCA explaining which criteria apply to your service and how you meet them.
Good looks like: A complete SoCA document that assessors can use to scope your evaluation, with clear statements about which IAL you're targeting and which optional criteria you implement.
7. Conduct an internal pre-assessment
□ Done when: You've walked through the assessment criteria as if you were the assessor, identifying gaps before the formal evaluation.
Good looks like: A gap analysis report with prioritized remediation items, timeline estimates, and assigned owners for each finding.
8. Submit your initial application to Kantara
□ Done when: You've sent your application to [email protected] and received confirmation of receipt and next steps.
Good looks like: A project plan covering the assessment timeline, assessor assignment, evidence submission deadlines, and expected certification date.
Common Mistakes
Assuming your 800-63-3A certification automatically satisfies 800-63-4 requirements. The standards diverge on evidence handling, validation scoring, and verification methods. Conduct a formal gap analysis even if you hold a current trust mark.
Waiting until your certification expires to review the new criteria. If you discover significant gaps during renewal, you're under time pressure. Start your gap analysis now, even if you're not transitioning until renewal.
Treating the NIST standard and the Service Assessment Criteria as identical. NIST SP 800-63A-4 defines the requirements; Kantara's SAC defines how assessors evaluate compliance. You need both documents.
Underestimating documentation requirements. Assessors need to see evidence that your processes work as documented. If your validation logic exists only in code without specification documents, you're not assessment-ready.
Ignoring the assessor assignment change. You can't hire your preferred assessor directly anymore. Kantara manages the assignment. Factor this into your timeline and stakeholder communication.
Next Steps
If you hold an 800-63-3A trust mark: Request the SP 800-63A-4 Service Assessment Criteria, conduct your gap analysis, and decide whether to transition before renewal or wait. The 800-63-3A criteria remain available, but you're working against a deprecated standard.
If you're pursuing IAL certification for the first time: Submit your initial application to [email protected]. Kantara will guide you through the process and assign an accredited assessor. Budget 3-6 months for the assessment cycle depending on your implementation's complexity.
If you're unsure whether you need IAL certification: Review your contracts and compliance obligations. Federal agencies increasingly require NIST-aligned identity proofing. If you're providing identity services to government entities or operating in sectors with regulatory identity requirements, IAL certification may be contractual, not optional.
Questions about implementation or transition should go to [email protected]. The Assurance Program team manages the criteria interpretation and assessment logistics.
The previous criteria served well for seven years. The new framework reflects evolved threats, updated evidence types, and refined verification methods. Your identity proofing system needs to evolve with it.





