Skip to main content

← Back to glossary

Term · 28. International Regulations

AAL AAL

Term from Law

Definition

NIST SP 800-63B Authenticator Assurance Level — measures the robustness of the authentication process. AAL1: single-factor (low confidence); AAL2: multi-factor MFA with verifier-impersonation resistance (medium confidence); AAL3: hardware-backed cryptographic authenticators with verifier impersonation + replay resistance + biometric verification (high confidence). Federal agencies require AAL2 for sensitive operations, AAL3 for highly sensitive.

Synonyms
  • Authentication Assurance Level (NIST)
Discouraged variants
  • **NIST SP 800-63-4** SP-B (Authentication)
Application
Regulatory: NIST SP 800-63 (Digital Identity Guidelines)
Standards & regulations
  • NIST «AAL2 provides high confidence that the claimant controls authenticator(s) bound to the subscriber's account. Proof of possession and control of two different authentication factors is required through secure authentication protocol(s). Approved cryptographic techniques are required at AAL2 and above. (NIST SP 800-63B)»
Sources