Kantara Initiative has formally published assessment criteria aligned with NIST Special Publication 800-63A Revision 4, opening the way for Identity Assurance Level assessments under the updated federal identity-proofing standard. In a March 24 publication notice, Kantara said the new Service Assessment Criteria and Statement of Criteria Applicability are final and effective immediately following public review.
The change matters because it gives relying parties, assessors and identity providers a usable yardstick for the latest version of NIST’s identity proofing requirements rather than the older 63-3A framework alone. Kantara said initial applications for SP 800-63A-4 assessments can now be submitted, and organizations seeking assessment and certification will need to contract directly with Kantara, which will manage assessor assignment.
The group also said the previous SP 800-63-3A criteria will remain available for organizations that still need them. Existing trust mark holders and registered applicants are being encouraged, but not required, to transition to the new 63A-4 criteria at renewal. That should give vendors some room to plan migrations while agencies and enterprise buyers update procurement language and certification expectations around the revised NIST baseline. It should also help procurement teams align RFP language with the newer framework instead of relying on older mappings and case-by-case interpretation.
The notice closes a process Kantara opened late last year when it sought public comment on draft assessment criteria tied to NIST revision 4. It also lands as governments are putting more structure around digital identity procurement and assurance, including the UK’s move to publish a digital verification services trust framework and related compliance guidance for identity providers.
NIST finalized SP 800-63A-4 earlier this year as part of the broader 800-63 revision 4 digital identity guidelines. Kantara’s publication does not change the federal standard itself, but it does translate that standard into an assessment and certification path that buyers can reference and providers can work against. For identity vendors selling into regulated public-sector and enterprise markets, the practical effect is that 63A-4 is now not just a document to read, but a benchmark against which services can be examined.
Sources: Kantara Initiative, NIST
–
By the ID Tech Editorial Team







Follow Us