Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Derived PIV Application and Data Model Test Guidelines



David Cooper, Hildegard Ferraiolo, Ramaswamy Chandramouli, Nabil Ghadiali, Jason Mohler, Steven Brady


NIST Special Publication (SP) 800-157 contains technical guidelines for the implementation of standards-based, secure, reliable, interoperable Public Key Infrastructure (PKI)-based identity credentials that are issued for mobile devices by federal departments and agencies to individuals who possess and prove control over a valid Personal Identity Verification (PIV) Card. This document, SP 800-166, contains the requirements and test assertions for testing the Derived PIV Application and associated Derived PIV data objects implemented on removable hardware tokens and within mobile devices. The tests reflect the design goals of interoperability and interface functions.
Special Publication (NIST SP) - 800-166
Report Number


authentication, derived PIV application, derived PIV application data model, derived PIV credential, derived test requirements (DTR), FIPS 201, implementation under test (IUT), mobile devices, Personal Identity Verification (PIV), test assertions, token command interface.


Cooper, D. , Ferraiolo, H. , Chandramouli, R. , Ghadiali, N. , Mohler, J. and Brady, S. (2016), Derived PIV Application and Data Model Test Guidelines, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online],, (Accessed February 23, 2024)
Created June 5, 2016, Updated October 14, 2021