
July 3, 2025 • Mary Marshall
Implement NIST 800-63 identity assurance levels (IAL/AAL/FAL) with Avatier’s comprehensive identity management solutions.
The NIST Special Publication 800-63 provides comprehensive digital identity guidelines that create critical frameworks for identity proofing, authentication, and federation. For organizations committed to robust security and regulatory compliance, understanding and implementing these standards—particularly the NIST 800-63 identity assurance levels (IAL), authentication assurance levels (AAL), and federation assurance levels (FAL)—is essential.
IAL is all about proofing.
Research (Gartner) says companies that pick the right IAL see about 40 % fewer identity scams. That may mean they’re not over‑locking users who don’t need it.
But IAL can feel like a roadblock. Imagine a freelance graphic designer trying to sign up for a new client portal and being asked to show up in person for IAL‑3 – it could drive them away. So there’s a trade‑off: security versus friction.
AAL asks “Is the login really the right person?”
The NIST doc appears to push AAL‑2 as the sweet spot for most businesses. Still, some smaller firms skip MFA because they think customers will get annoyed.
FAL is the backstage pass when two companies share identity info.
If you’re a city government linking its citizen portal to a state health system, you probably need at least FAL‑2.
Avatier markets itself as an “all‑in‑one” identity platform that covers IAL, AAL and FAL. Below are some ways it can be useful – and some cautions.
Avatier’s workflow lets you set up risk‑based checks. For a retail chain they offer automated ID scans that talk to DMV databases (good for IAL‑2). They also have a biometric add‑on for IAL‑3.
But the UI sometimes feels like a PowerPoint slide with too many boxes. A small business owner might spend more time clicking than actually verifying users.
The product supports passwords, OTPs, FIDO2 keys and even facial recognition. In one pilot my friend Carlos ran at his tech startup, they switched from SMS codes to hardware tokens and saw a sharp drop in login failures.
Nevertheless, Avatier still lists “SMS allowed” as an option, even though NIST warns against it for higher AALs. That could confuse admins who just copy‑paste the default settings.
Avatier supports SAML, OpenID Connect and OAuth out of the box. A local university used their SSO bridge to let students log into library services without new passwords.
Still, the documentation on holder‑of‑key (FAL‑3) is thin. If you really need the strongest federation you might have to call support three times before getting a clear answer.
While Avatier does bundle many pieces together, it sometimes feels like trying to fit a Swiss army knife into a pocket that’s already full of other tools. Some businesses might be better off picking separate specialist tools for proofing and for MFA rather than forcing everything into one platform. Also, the “one‑size‑fits‑all” language can mislead smaller firms into thinking they need all three assurance levels for every app, which would just drown them in friction.
NIST 800‑63 gives us a map for building trust on the internet: know who people say they are (IAL), make sure they really are who they claim (AAL), and let other trusted parties accept that proof (FAL). The guidelines might mean you don’t have to lock every system at the highest level – just match the risk.
Avatier offers a convenient toolbox that can cover most of the map, but it isn’t flawless. Companies should weigh the ease of a single platform against possible complexity, cost and user pushback.
If you’re an IT manager at a midsize firm or a security officer at a hospital, start small: pick one critical app, decide its IAL/AAL/FAL needs, test Avatier’s features there, and learn from any hiccups before rolling out wider. By staying flexible, keeping users in mind and checking NIST updates regularly, you can turn those dense guidelines into everyday security that actually works—not just on paper.
That’s how we can make digital identity both safe and usable.