Source record · tier 1 standards and regulators
NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management
- Publisher
- National Institute of Standards and Technology
- URL
- https://pages.nist.gov/800-63-4/sp800-63b.html
- Published
- 2025-08-26
- Updated
- unknown
- Accessed
- 2026-09-30
- HTTP status
- 200
- License
- US government work; public domain in the US; public domain; short excerpts and locators used anyway
Source notes citing this source
- NIST SP 800-63B-4 is dated August 26, 2025 and supersedes the previous SP 800-63B. in context
- NIST SP 800-63B-4 allows biometrics only as part of multi-factor authentication with a physical authenticator, never as a standalone factor. in context
- NIST SP 800-63B-4 requires a biometric system to operate at a false match rate of one in 10,000 or better for all demographic groups. in context
- NIST SP 800-63B-4 says verifiers and CSPs SHALL NOT prompt subscribers to use knowledge-based authentication or security questions when choosing passwords. in context
- The explicit KBA prohibition found in SP 800-63B-4 is scoped to password selection, so the document does not by that sentence alone ban a contact center from asking knowledge questions; it simply gives KBA no standing as an authenticator. inferred in context
- NIST SP 800-63B-4 requires an out-of-band authentication to be treated as invalid unless it is completed within 10 minutes. in context
- NIST SP 800-63B-4 states that out-of-band authentication is not phishing-resistant. in context
- NIST SP 800-63B-4 classifies out-of-band authentication over the PSTN (SMS or voice) as a restricted authenticator. in context
- NIST SP 800-63B-4 says verifiers SHOULD consider risk indicators such as device swap, SIM change and number porting before using the PSTN to deliver an out-of-band secret. in context
- For restricted authenticators, NIST SP 800-63B-4 says verifiers SHALL make alternative authenticator types available to all subscribers. in context
- NIST SP 800-63B-4 prohibits biometric comparison based on voice. in context
- Because SIM swap and number porting redirect a customer's number to an attacker, an SMS or voice OTP sent to that number can reach the attacker, which is why NIST lists SIM change and porting as risk indicators and the FCC regulates carrier-side SIM change authentication. inferred in context
- A contact-center voiceprint program cannot be presented as a NIST SP 800-63B-4 conformant authenticator, because the guideline both bans voice comparison and forbids biometrics as a standalone factor; NIST 800-63B does not bind private contact centers. inferred in context
Cite this source record
APA
WarmTransfer. (2025, August 26). NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management. WarmTransfer. https://warmtransfer.net/knowledge/sources/nist-sp-800-63b-4
BibTeX
@misc{warmtransfer-nist-sp-800-63b-4,
title = {NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management},
author = {{WarmTransfer}},
year = {2025},
url = {https://warmtransfer.net/knowledge/sources/nist-sp-800-63b-4},
note = {National Institute of Standards and Technology, accessed 2026-09-30}
}