NOTICE: Due to a lapse in annual appropriations, most of this website is not being updated. Learn more.
Form submissions will still be accepted but will not receive responses at this time. Sections of this site for programs using non-appropriated funds (such as NVLAP) or those that are excepted from the shutdown (such as CHIPS and NVD) will continue to be updated.
An official website of the United States government
Here’s how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
NIST Updates Personal Identity Verification (PIV) Guidelines
Published
Author(s)
Hildegard Ferraiolo, Larry Feldman, Gregory A. Witte
Abstract
This bulletin summarized the information presented in NIST SP 800-156: Derived PIV Application and Data Model Test Guidelines and NIST SP 800-166: Representation of PIV Chain-of-Trust for Import and Export. These publications support Federal Information Processing Standard (FIPS) 201, Personal Identity Verification (PIV) of Federal Employees and Contractors , which specifies the model for identity credentials that are hosted on a smart card (i.e., the PIV card) and/or on mobile devices (i.e., Derived PIV Credentials).
authentication, derived PIV application, derived PIV application data model, derived PIV credential, derived test requirements (DTR), FIPS 201, implementation under test (IUT), mobile devices, Personal Identity Verification (PIV), test assertions, token command interface.
Ferraiolo, H.
, Feldman, L.
and Witte, G.
(2016),
NIST Updates Personal Identity Verification (PIV) Guidelines, ITL Bulletin, National Institute of Standards and Technology, Gaithersburg, MD, [online], https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=921562
(Accessed November 4, 2025)