Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Electronic Authentication Guideline



William E. Burr, Donna F. Dodson, Elaine M. Newton, Ray Perlner, William Polk, Sarbari Gupta, Emad A. Nabbus


[Superseded by SP 800-63-2 (August 2013):] This recommendation provides technical guidelines for Federal agencies implementing electronic authentication and is not intended to constrain the development or use of standards outside of this purpose. The recommendation covers remote authentication of users (such as employees, contractors, or private individuals) interacting with government IT systems over open networks. It defines technical requirements for each of four levels of assurance in the areas of identity proofing, registration, tokens, management processes, authentication protocols and related assertions. [Supersedes SP 800-63 Ver. 1.0.2 (April 2006):]
Special Publication (NIST SP) - 800-63-1
Report Number


authentication, authentication assurance, credential service provider, cryptography, electronic authentication, electronic credentials, electronic transactions, electronic government, identity proofing, passwords, PKI, Public Key Infrastructure, tokens


Burr, W. , Dodson, D. , Newton, E. , Perlner, R. , Polk, W. , Gupta, S. and Nabbus, E. (2011), Electronic Authentication Guideline, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD (Accessed June 19, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created December 11, 2011, Updated October 12, 2021