IAL3 Identity Proofing: In-Person, Biometrics, Superior Evidence

IAL3 is the highest identity proofing tier defined in the National Institute of Standards and Technology’s SP 800-63 Digital Identity Guidelines. To meet it, you appear in person before a trained proofing agent, present high-quality identity documents, and submit to a mandatory biometric capture that is matched against your evidence. Federal agencies reserve this level for situations where accepting a fake identity would cause serious harm, such as issuing credentials that unlock classified systems or critical infrastructure.1National Institute of Standards and Technology. NIST Special Publication 800-63A – Identity Proofing and Enrollment Requirements

One boundary worth setting up front: IAL only measures how confident a system is that you are who you claim to be when you first enroll. Passwords, multi-factor authentication, and how credentials move between systems fall under separate NIST dimensions (AAL and FAL) and are not part of IAL3.

What IAL3 Requires

In-Person Appearance

Every IAL3 proofing session happens with you physically present to a trained agent working for a Credential Service Provider (CSP). Present can mean two things: a traditional face-to-face session at a physical location, or a supervised remote session over a live video connection where an operator monitors the entire process in real time. Supervised remote is not the same as the unsupervised remote proofing allowed at IAL2, where you take your own photos of an ID on your own schedule. At IAL3, someone is watching the whole event. Knowledge-based verification — those questions about old addresses or former car loans — is explicitly banned for in-person sessions at IAL2 and IAL3 alike.1National Institute of Standards and Technology. NIST Special Publication 800-63A – Identity Proofing and Enrollment Requirements

Documentary Evidence

You must present one of the following combinations:

  • Two pieces of SUPERIOR evidence.
  • One SUPERIOR and one STRONG piece, provided the STRONG evidence’s issuing source originally confirmed identity using two or more forms of SUPERIOR or STRONG evidence and the CSP validates it directly with the issuer.
  • Two pieces of STRONG evidence plus one piece of FAIR evidence.

By contrast, IAL2 will accept a single STRONG piece plus two FAIR pieces, or two STRONG pieces alone. IAL3 raises the floor on both quantity and quality.1National Institute of Standards and Technology. NIST Special Publication 800-63A – Identity Proofing and Enrollment Requirements

Mandatory Biometric Capture

Biometrics are optional at IAL2 and mandatory at IAL3. The CSP captures a biometric, typically a facial image, and compares it against the photograph or biometric template on your strongest piece of evidence. Liveness detection is required whether the comparison is done through physical examination or an automated system, which is what stops someone from holding a printed photo up to a camera. The biometric also lets the system detect duplicate or fraudulent enrollments and gives the CSP a way to re-bind you to your credential later if something goes wrong.2National Institute of Standards and Technology. SP 800-63A Identity Verification – Implementation Resources

Verification at SUPERIOR Strength

IAL2 requires the CSP to verify your binding to your evidence at a strength of STRONG. IAL3 raises that threshold to SUPERIOR. In practice, an agent’s visual glance at a passport photo is not enough. Automated biometric comparison meeting specific performance standards must be part of the process.2National Institute of Standards and Technology. SP 800-63A Identity Verification – Implementation Resources

How Evidence Gets Rated SUPERIOR, STRONG, or FAIR

The evidence tiers that drive the IAL3 combinations above are defined by specific qualities of the document and its issuer.

  • FAIR evidence comes from an issuing source that confirmed your identity through some proofing process, contains either a unique reference number or a photograph or biometric (or has ownership confirmable through knowledge-based verification), and carries physical security features that require specialized knowledge to reproduce.
  • STRONG evidence goes further. The issuing source must have followed written procedures subject to regulatory oversight, such as the Customer Identification Program under the USA PATRIOT Act. The document must carry both a unique reference number and a photograph or biometric, and the full legal name cannot be a pseudonym or initials.
  • SUPERIOR evidence carries the highest bar: cryptographic security features the CSP can verify, and issuance through a process that itself meets IAL3-equivalent rigor.

A U.S. passport is the standard example of SUPERIOR evidence. A state driver’s license typically qualifies as STRONG. Utility bills and similar documents land in FAIR at best.1National Institute of Standards and Technology. NIST Special Publication 800-63A – Identity Proofing and Enrollment Requirements

When Agencies Actually Choose IAL3

Federal agencies do not default to IAL3. NIST’s decision framework starts with whether a service needs to know who the user is at all; if not, IAL1 is fine. Once identity matters, the choice between IAL2 and IAL3 turns on consequences. If a fraudulently accepted identity could cause serious financial harm, endanger safety, or compromise national security, IAL3 is warranted. If the impact is moderate, IAL2 handles the risk.3National Institute of Standards and Technology. NIST Special Publication 800-63-3 – Digital Identity Guidelines

Where You Are Likely to Encounter IAL3

The most widespread real use of IAL3 is the federal Personal Identity Verification (PIV) card carried by federal employees and long-term contractors. FIPS 201-3, the standard governing PIV credentials, states that PIV issuance follows a tailored process based on IAL3 requirements. The PIV standard does accept a slightly reduced evidence set — one STRONG and one FAIR piece — because the mandatory federal background investigation is treated as a compensating control.4National Institute of Standards and Technology. FIPS 201-3 – Personal Identity Verification of Federal Employees and Contractors

For the general public interacting with federal websites, IAL3 is rare. Login.gov, the shared sign-in platform used by many federal agencies, currently offers IAL2-compliant identity verification, which lets you verify remotely by photographing your ID and entering your Social Security number.5Login.gov. Login.gov Now Offers an IAL2-Compliant Identity Verification Service Agencies that need IAL3 for public-facing services must build or contract for that capability separately, which is part of why IAL3 stays uncommon outside credentialing for federal personnel.

Trusted Referees for People Who Cannot Meet the Requirements Alone

Not everyone can produce two SUPERIOR documents or complete the process independently. NIST allows a trusted referee — a notary, legal guardian, medical professional, or person with power of attorney — to vouch for or act on behalf of an applicant. Trusted referees can be used for both in-person and remote sessions.

The rules are strict. The referee must themselves be proofed at the same IAL level as the applicant, so an unverified person cannot vouch for someone going through IAL3. The CSP must have written policies for how referees are approved, how long that status lasts, and when it can be revoked, and the goal is to re-proof the applicant through normal channels once they can meet the standard requirements. For minors, the CSP must comply with the Children’s Online Privacy Protection Act (COPPA) and should involve a parent or legal guardian as the referee.1National Institute of Standards and Technology. NIST Special Publication 800-63A – Identity Proofing and Enrollment Requirements

What Changed in Revision 4

NIST released the final version of SP 800-63 Revision 4 in July 2025, the first update since Revision 3 in 2017.6National Institute of Standards and Technology. NIST SP 800-63-4 Digital Identity Guidelines The core of IAL3 is unchanged: in-person proofing with a trained agent and mandatory biometric capture. Revision 4 expands security and privacy considerations, adds performance metrics for ongoing evaluation, introduces requirements addressing artificial intelligence and machine learning in identity services, adds a section on redress for applicants, and includes a user-controlled wallet federation model that reflects the growing use of digital wallets and mobile driver’s licenses.7National Institute of Standards and Technology. NIST Special Publication 800-63-4 – Digital Identity Guidelines

If you are going through IAL3 proofing today, the day-of experience looks much the same. You show up in person, present strong documents, and provide a biometric. The updates mostly sit behind the counter, in the guidance the CSP and the sponsoring agency now follow.