NIST 800-63-3 IAL2 / AAL2: The Federal Identity Assurance Framework That Drives IDV Cost
NIST Special Publication 800-63-3 defines the assurance levels that US federal agencies require from identity verification providers. IAL2 is the operational baseline for most federal and state government IDV; IAL3 is the in-person or supervised remote tier. The assurance level a vendor targets materially affects what they charge per verification.
The three Identity Assurance Levels
- IAL1. Self-asserted identity. No evidence required, no validation. Suitable for low-risk applications where false claims have minimal consequences. Cheapest per verification; typically bundled in consumer KYC starter tiers.
- IAL2. Remote or in-person identity proofing with documentary evidence (government-issued ID document) and validation against an authoritative source. Biometric binding is required. This is the operational baseline for most US federal IDV: IRS account creation, VA login, state unemployment insurance.
- IAL3. In-person identity proofing, or supervised remote proofing with a trained agent. Highest assurance; used for security-clearance-related identities, healthcare provider credentialling, and other high-risk roles. Most expensive per verification.
The three Authenticator Assurance Levels
- AAL1. Single-factor authentication. Username and password, possibly with PIN. Low assurance.
- AAL2. Multi-factor with cryptographic authentication. Something you know (password) plus something you have (cryptographic device, push notification, OTP from authenticator app). The operational baseline for US federal sign-in.
- AAL3. Hardware-backed cryptographic authentication. Hardware security key (FIDO2, WebAuthn) or smartcard. Highest assurance; required for some classified or healthcare-credential applications.
IAL and AAL are independent: a system can require IAL2 identity proofing but only AAL1 authentication (you proved your identity once at sign-up but log in with a password thereafter). Most US federal systems pair IAL2 with AAL2.
What IAL2 actually requires
IAL2 identity proofing requires the subject to present a government-issued photo ID, the document to be validated against an authoritative source (DMV record, USPS address verification, credit bureau identity-confirmation), and biometric binding (selfie matched to the document photo). The proofing event creates an identity record that can be reused for subsequent verifications.
Why this affects per-verification cost
A vendor offering IAL2-compliant verification carries certification and audit costs that a non-IAL2 vendor does not. The certification process is meaningful: independent assessment against NIST 800-63-3 controls, ongoing monitoring, periodic recertification. Vendors typically price IAL2 verification 2x to 5x higher than basic document-OCR-only verification.
Reuse changes the economics. A vendor that runs IAL2 once and lets the verified identity be re-used across multiple sites can charge a higher per-first-verification fee and a lower per-reuse fee. ID.me operates this model with the ID.me wallet. The implication for buyers: if your use case has high reuse (the same verified user authenticates to your system repeatedly), IAL2 may be cheaper per transaction than it appears on the per-first-verification rate.
Commercial IAL2 providers
- ID.me, the leading commercial IAL2 provider in the US, with deep penetration into federal (IRS, VA) and state government identity verification.
- Login.gov, the federal-government-operated IAL2 service. Free for federal agencies; not a commercial vendor.
- Other commercial vendors offer IAL2 capability through partnerships and direct certification; this varies and is best confirmed against the NIST and FedRAMP marketplace listings for current status.
For regulated-finance KYC (Persona, Onfido, Veriff, Trulioo, Jumio, Socure), the relevant framework is typically AML / CIP rather than NIST 800-63-3, though several of those vendors support both. See sister site kycpricing.com for pricing across regulated-finance vendors.
Source documents
- NIST SP 800-63-3 Digital Identity Guidelines, the canonical reference.
- NIST 800-63A Enrollment and Identity Proofing, IAL technical detail.
- NIST 800-63B Authentication and Lifecycle Management, AAL technical detail.
What this means for procurement
If you are integrating with a US federal agency, you almost certainly need IAL2; ID.me or Login.gov are the operational defaults. If you are running consumer KYC for a marketplace or fintech, IAL2 is rarely required; the regulatory framework is AML / CIP and document-OCR-plus-biometric is sufficient. The cost gap between "IAL2-certified" and "reasonably good remote IDV" is meaningful and worth confirming you actually need the certification before paying for it.
Related reading
- ID.me dossier, the leading commercial IAL2 provider.
- ID.me vs Yoti, US federal vs UK age-estimation positioning.
- Consumer KYC category, the broader space.
- Methodology, source URLs and verification dates.