Independent reference. No vendor sponsorships, no affiliate links, no email capture.
IdentityVerificationCost.com
Regulatory anchor · Verified 17 June 2026

NIST 800-63-3 IAL2 / AAL2: The Federal Identity Assurance Framework That Drives IDV Cost

NIST Special Publication 800-63-3 defines the assurance levels that US federal agencies require from identity verification providers. IAL2 is the operational baseline for most federal and state government IDV; IAL3 is the in-person or supervised remote tier. The assurance level a vendor targets materially affects what they charge per verification.

Direct answer
What are NIST IAL and AAL levels?
NIST 800-63-3 separates identity proofing (Identity Assurance Level, IAL) from authentication (Authenticator Assurance Level, AAL). IAL1 is self-asserted, IAL2 is remote or in-person identity proofing with documentary evidence, IAL3 requires in-person or supervised remote proofing. AAL1 is single-factor, AAL2 is multi-factor with cryptographic authentication, AAL3 is hardware-backed cryptographic. Most US federal IDV targets IAL2 / AAL2.

The three Identity Assurance Levels


The three Authenticator Assurance Levels

IAL and AAL are independent: a system can require IAL2 identity proofing but only AAL1 authentication (you proved your identity once at sign-up but log in with a password thereafter). Most US federal systems pair IAL2 with AAL2.


What IAL2 actually requires

IAL2 identity proofing requires the subject to present a government-issued photo ID, the document to be validated against an authoritative source (DMV record, USPS address verification, credit bureau identity-confirmation), and biometric binding (selfie matched to the document photo). The proofing event creates an identity record that can be reused for subsequent verifications.


Why this affects per-verification cost

A vendor offering IAL2-compliant verification carries certification and audit costs that a non-IAL2 vendor does not. The certification process is meaningful: independent assessment against NIST 800-63-3 controls, ongoing monitoring, periodic recertification. Vendors typically price IAL2 verification 2x to 5x higher than basic document-OCR-only verification.

Reuse changes the economics. A vendor that runs IAL2 once and lets the verified identity be re-used across multiple sites can charge a higher per-first-verification fee and a lower per-reuse fee. ID.me operates this model with the ID.me wallet. The implication for buyers: if your use case has high reuse (the same verified user authenticates to your system repeatedly), IAL2 may be cheaper per transaction than it appears on the per-first-verification rate.


Commercial IAL2 providers

For regulated-finance KYC (Persona, Onfido, Veriff, Trulioo, Jumio, Socure), the relevant framework is typically AML / CIP rather than NIST 800-63-3, though several of those vendors support both. See sister site kycpricing.com for pricing across regulated-finance vendors.


Source documents


What this means for procurement

If you are integrating with a US federal agency, you almost certainly need IAL2; ID.me or Login.gov are the operational defaults. If you are running consumer KYC for a marketplace or fintech, IAL2 is rarely required; the regulatory framework is AML / CIP and document-OCR-plus-biometric is sufficient. The cost gap between "IAL2-certified" and "reasonably good remote IDV" is meaningful and worth confirming you actually need the certification before paying for it.

Related reading

Last verified 17 June 2026