FIPS 201 is the federal standard that tells every U.S. government agency how to verify the identity of its employees and contractors and issue them a single type of secure credential, the Personal Identity Verification (PIV) card, used for both building entry and computer network access.1Computer Security Resource Center. FIPS 201-3 Personal Identity Verification (PIV) of Federal Employees and Contractors Written by the National Institute of Standards and Technology (NIST), the current version is FIPS 201-3, published in January 2022.
Where the Standard Came From
In 2004, President Bush signed Homeland Security Presidential Directive 12 (HSPD-12), which ordered federal agencies to adopt a common, interoperable credentialing standard. NIST wrote that standard, and it became Federal Information Processing Standard 201.1Computer Security Resource Center. FIPS 201-3 Personal Identity Verification (PIV) of Federal Employees and Contractors
Before HSPD-12, each agency ran its own badge system with no shared technical baseline. A Department of Energy contractor with legitimate business at a Department of Defense facility couldn’t use their badge to get in. FIPS 201 eliminated that patchwork by specifying, in one document, the card’s physical layout, chip contents, cryptographic keys, biometric data, and the processes for issuing and revoking credentials. The standard has been updated twice since its original release.
What FIPS 201 Actually Covers
The standard governs the entire life of a federal credential. It sets the rules for how an agency confirms who you are before issuing a card, what background investigation you must pass, what data goes on the card, how the card is activated, how it authenticates you at a door or a keyboard, and what the agency must do when you leave. Every person who needs ongoing access to a federal facility or information system goes through this process, regardless of which agency employs them.
Getting a PIV Card
Identity Proofing
Before anyone receives a PIV card, they go through identity proofing at a designated enrollment center, in person. The applicant presents two original identity source documents. At least one must be a strong form of identification such as a U.S. passport or passport card, a REAL ID-compliant driver’s license, a permanent resident card, or a U.S. military ID.2National Institute of Standards and Technology. Personal Identity Verification (PIV) of Federal Employees and Contractors (FIPS 201-3)
The second document can come from a broader list that includes a Social Security card, a certified birth certificate, a voter registration card, a U.S. Coast Guard Merchant Mariner card, a certificate of citizenship or naturalization, or a government-issued photo ID from a federal, state, or local agency.2National Institute of Standards and Technology. Personal Identity Verification (PIV) of Federal Employees and Contractors (FIPS 201-3) The two documents cannot be of the same type. Both must be genuine, unexpired originals. No photocopies.
Biometrics
During enrollment, the agency captures biometric data that lives on the card and is used for future authentication. Two categories are mandatory: fingerprints and a facial image. FIPS 201-3 requires at least two fingerprint images for off-card comparison, plus a full set of ten fingerprints for applicants without an existing background investigation on record. An electronic facial photograph is always required.2National Institute of Standards and Technology. Personal Identity Verification (PIV) of Federal Employees and Contractors (FIPS 201-3) Agencies may also capture iris images and two additional fingerprints for on-card comparison, a feature that lets the card verify a fingerprint internally without sending data anywhere.
Not everyone can provide usable fingerprints. NIST SP 800-76-2 establishes iris and facial recognition as alternative biometrics specifically to cover people whose fingerprints consistently fail quality thresholds due to injury, disability, or physical condition.3National Institute of Standards and Technology. Biometric Specifications for Personal Identity Verification FIPS 201-3 also requires agencies to comply with Section 508 of the Rehabilitation Act throughout the credentialing process, so enrollment stations, card readers, and authentication workflows must be accessible.2National Institute of Standards and Technology. Personal Identity Verification (PIV) of Federal Employees and Contractors (FIPS 201-3)
Background Investigation
Every applicant must pass a background investigation before the card is issued. At minimum, that’s a Tier 1 investigation (formerly the National Agency Check with Inquiries). More sensitive positions require Tier 2 through Tier 5, with increasing scrutiny. Low-risk positions use Standard Form 85; positions needing a security clearance use Standard Form 86.4Defense Counterintelligence and Security Agency. Help Filling Out Forms Timelines vary widely. Tier 1 is generally the fastest; higher tiers involving interviews, financial reviews, and overseas checks take considerably longer.
What’s on the Card
The PIV card is a credit-card-sized smart card with both a contact chip (the gold pad you insert into a reader) and a contactless interface for tapping at doors. The chip holds the cardholder’s biometric templates, cryptographic keys, and digital certificates.
Keys and Certificates
FIPS 201-3 requires four asymmetric key pairs, each with a matching X.509 certificate:
- The PIV Authentication Key proves the cardholder’s identity when logging into federal systems. Mandatory on every card.
- The Card Authentication Key proves the card itself is genuine, without a PIN. Also mandatory.
- The Digital Signature Key signs documents and emails. It must be generated on the card and cannot be exported.
- The Key Management Key handles encryption and decryption, mostly for email. The card can also store up to 20 retired key management keys so older encrypted messages remain readable.
The digital signature and key management keys are mandatory unless the cardholder has no government email account at the time of issuance.2National Institute of Standards and Technology. Personal Identity Verification (PIV) of Federal Employees and Contractors (FIPS 201-3) Most cards carry all four.
Identifiers and Surface Layout
Each card carries two unique identifiers: the Federal Agency Smart Card Number (FASC-N), a fixed-length 25-byte object that has been the primary identifier for physical access control since the standard’s early versions,5National Institute of Standards and Technology Computer Security Resource Center. FASC-N Glossary and a card UUID that FIPS 201-3 added alongside it. Both must be maintained in agency databases and both must be invalidated when a card is terminated.
The face of the card follows a fixed zone layout. A frontal photograph sits in the upper left corner at a minimum of 300 dots per inch. The cardholder’s full name, surname first, prints below it in Arial Bold between 7 and 10 point depending on length, with no abbreviations. Mandatory elements also include the issuing agency, an expiration date, and a color-coded strip indicating whether the holder is a federal employee, contractor, or foreign national.2National Institute of Standards and Technology. Personal Identity Verification (PIV) of Federal Employees and Contractors (FIPS 201-3)
Activation and Everyday Use
After the investigation clears and the card is produced, the applicant returns to the enrollment center for a final in-person appointment. An authorized official compares the applicant’s live fingerprints or facial image against the templates captured during enrollment, confirming the person picking up the card is the person who enrolled. The cardholder then sets a Personal Identification Number (PIN) that unlocks the card’s privileged functions. The card locks after 10 consecutive failed PIN attempts, and only a reset at the enrollment center clears it.2National Institute of Standards and Technology. Personal Identity Verification (PIV) of Federal Employees and Contractors (FIPS 201-3)
Physical Access to Buildings
At building entry points, the card uses its contactless interface. NIST SP 800-116 sets a risk-based model with four security tiers: Unrestricted, Controlled, Limited, and Exclusion. Each step up requires stronger authentication. Crossing into Controlled space usually takes just a tap of the card. Limited areas add a second factor. Exclusion areas require three-factor authentication.6IDManagement.gov. Personal Identity Verification (PIV) in Enterprise Physical Access Control Systems
Computer Logins and Secure Email
For network access, the cardholder inserts the card into a reader and enters the PIN, and the PIV Authentication certificate proves identity to the system. For email, the digital signature certificate (SHA-256) verifies the sender and prevents tampering, and the key management certificate (AES 256-bit) encrypts contents so only the intended recipient can read them.7IDManagement.gov. Sign and Encrypt Email in Microsoft Outlook
Derived Credentials for Phones and Tablets
Smartphones and tablets don’t accept smart cards. NIST SP 800-157 Revision 1 addresses that with derived PIV credentials: standards-based credentials issued to someone who already holds a valid PIV card and can prove control of it.8Computer Security Resource Center. Guidelines for Derived Personal Identity Verification (PIV) Credentials Two approaches are allowed. PKI-based derived credentials use the same certificate infrastructure as the card. Non-PKI derived credentials use phishing-resistant multi-factor authenticators like FIDO2 keys, relying on federation for cross-agency use.9National Institute of Standards and Technology. SP 800-157r1 Derived PIV Credentials A derived credential is tied to the cardholder’s PIV identity account. If the underlying card is terminated, every credential linked to that account must be invalidated too.
Keeping the Card Valid
A PIV card requires active management. The physical card expires five years after issuance, and renewal means returning to an enrollment center to update biometric data and receive a new card.10Interior Business Center. PIV Card Renewal (PIV Card Expiration) The digital certificates on the chip run on a shorter cycle, typically three years from activation. When certificates lapse, encryption and signing functions stop even though the card looks fine. Certificate updates are a separate process and usually don’t require a new physical card.11General Services Administration. Federal Credentialing Services This is the lifecycle event that catches the most people off guard.
A lost or stolen card must be reported immediately to the cardholder’s supervisor and the agency credentialing office.12IBC Customer Central. Lost, Stolen or Damaged PIV Card Replacement repeats the in-person identity steps, and the lost card’s certificates are revoked so a finder or thief can’t use them.
When someone leaves federal service or moves to a role that no longer requires access, the agency must terminate the credential. FIPS 201-3 spells out the steps: collect and destroy the card if possible, revoke all four certificates, update the Central Verification System, and mark both the FASC-N and card UUID invalid in agency databases. If the card can’t be recovered, the agency has 18 hours from notification to complete termination, and emergency procedures allow faster action when security demands it. Any derived credentials tied to the same identity account must also be invalidated.2National Institute of Standards and Technology. Personal Identity Verification (PIV) of Federal Employees and Contractors (FIPS 201-3)
Criminal Penalties for Fraud and Misuse
Because the card opens federal facilities and sensitive systems, misuse carries serious consequences under several federal statutes.
Lying on a PIV application, including the SF-85 or SF-86, falls under 18 U.S.C. § 1001, the federal false statements statute. A conviction carries up to five years in prison, or up to eight years when the false statement involves terrorism.13Office of the Law Revision Counsel. 18 U.S. Code 1001 – Statements or Entries Generally
Forging, counterfeiting, or tampering with a PIV card itself falls under 18 U.S.C. § 499, covering military, naval, and official passes. Using a forged credential or impersonating the person to whom one was issued carries up to five years.14Office of the Law Revision Counsel. 18 USC 499 – Military, Naval, or Official Passes
Manufacturing or possessing an unauthorized copy of a federal badge or ID card, or even making something that just looks like one, violates 18 U.S.C. § 701, with penalties up to six months in prison.15Office of the Law Revision Counsel. 18 U.S. Code 701 – Official Badges, Identification Cards, Other Insignia
The broadest statute is 18 U.S.C. § 1028, which covers fraud involving identification documents generally. Producing or transferring a false federal ID carries up to 15 years. That ceiling climbs to 20 years when the fraud facilitates drug trafficking or a crime of violence, and to 30 years when it is connected to domestic or international terrorism.16Office of the Law Revision Counsel. 18 USC 1028 – Fraud and Related Activity in Connection With Identification Documents