About assurance levels
Assurance levels (also called “Service levels,” or “Levels of Assurance”) is a general term referring to the trustworthiness of a given transaction. Generally, the higher the assurance level, the greater the confidence in the authentication and/or identity verification processes that occurred for a specific transaction. Selecting the right level of identity assurance helps balance security, usability and fraud mitigation based on the risks associated with your application.
Guidance on assurance levels from NIST
NIST Special Publication 800-63 Revision 4 provides federal agencies with a risk-based framework for selecting and implementing appropriate digital identity controls. The guidelines include a Digital Identity Risk Management (DIRM) process that helps agencies assess the potential impacts of digital identity failures, select initial assurance levels, and ensure your selected assurance level with Login.gov meets those needs.
Understanding Login.gov’s identity services
Login.gov offers authentication and identity verification services that can support a range of agency use cases:
Authentication Only (Self-asserted identity and authentication):
For applications that do not require knowing the real-world identity of the individual using their service, Login.gov provides secure authentication without verifying a user’s real-world identity. Consistent with NIST SP 800-63-4, agencies may determine that identity proofing is not necessary when their application does not require validated information about a user’s identity, also referred to as an “Authentication Only” account. Login.gov offers configurable options for authentication that may change the Authentication Assurance Level (AAL), including phishing-resistant authenticator options and "remember device" functionality. See Authentication Overview for more information.
Basic identity verification (IAL1 aligned to NIST SP 800-63-4):
Login.gov offers an Identity Assurance Level 1 (IAL1) option for agency use cases that call for identity verification but do not require an Identity Assurance Level 2 (IAL2) service. IAL1 uses identity evidence, validation, verification, and other controls to establish confidence in a user's claimed identity. Per NIST SP 800-63-4, this is appropriate when access to personal information is required but limited and user actions are limited (e.g., viewing and making modifications to individual personal information. See NIST SP 800-63-4, Table 1 and Identity Verification Overview for more information.
Enhanced identity verification (IAL2 compliant with NIST 800-63 Revision 3 and aligned to Revision 4):
For applications that require greater assurance that an individual is who they claim to be, Login.gov provides enhanced identity verification services aligned with NIST SP 800-63-4 requirements for IAL2. In addition to the identity evidence, validation, verification, and other controls in Basic identity verification, the Enhanced identity verification service also requires a biometric facial match and more evidence to establish higher confidence in a user's claimed identity. Per NIST SP 800-63-4, IAL2 is appropriate when users can view or change financial information. See NIST SP 800-63-4, Table 1 and Enhanced identity verification with biometric facial matching (IAL2) for more information.
How to decide which assurance level is right for a given use case
Agency partners are responsible for selecting the levels appropriate for their service, based on their own DIRM assessment. Part of the Login.gov onboarding process includes reviewing the Login.gov Digital Identity Acceptance Statement (DIAS) for the agency partners selected service option. Contact partners@login.gov for more information.