
What the document says
NIST published Special Publication 800-63-4, the fourth revision of its Digital Identity Guidelines, on 31 July 2025, superseding Revision 3, which had stood since 2017. The summary of changes lists several substantive shifts: expanded fraud-detection requirements for identity proofing, new controls addressing injection attacks and forged media such as deepfakes, a subscriber-controlled wallet option added to the federation model, and explicit integration of syncable authenticators, meaning synced passkeys, into the authenticator catalogue. The authentication component, SP 800-63B-4, keeps the three Authenticator Assurance Levels from Revision 3 but changes what each level requires: AAL2 now states that verifiers shall offer at least one phishing-resistant authentication option, and AAL3 requires the authenticator itself to provide phishing resistance. Syncable passkeys are explicitly permitted at AAL1 and AAL2, but the document states they shall not be used at AAL3, because a syncable credential's private key is, by design, exportable to other devices.
Confidence and limits
The publication date, title and the specific requirement language summarised above come from NIST's own current guidance pages, which is strong, direct evidence for what changed on paper. What this account does not establish is how quickly federal agencies or vendors have actually implemented the new AAL2 and AAL3 requirements, since conformance and adoption data were not published on the pages opened here. Revision 3's own definition of verifier impersonation resistance, now folded into the plainer term phishing resistance, is included for comparison from NIST's still-published Revision 3 page.
Why it mattered
Making phishing-resistant authentication a requirement rather than a recommendation at AAL2, the level most consumer and enterprise services actually target, raised the practical bar for what counts as adequate multi-factor authentication under a federal reference standard. Explicitly addressing syncable passkeys mattered because the technology had already spread through consumer platforms before this guidance caught up, leaving agencies and vendors without a clear answer on where a synced credential fit until this revision drew the line at AAL3.
Defensive takeaway
If your organisation cites an AAL2 requirement in policy, check whether your current authenticators actually meet the phishing-resistance requirement in Revision 4, not only the weaker Revision 3 baseline.
- Do we know which AAL our critical systems are meant to meet, and was that target set under Revision 3 or Revision 4?
- Are any of our AAL3 use cases relying on a syncable passkey, which this revision now excludes?
- Does our authenticator policy distinguish phishing-resistant options from ordinary one-time-code multi-factor authentication?
A revised assurance level is a paper requirement until it is checked against the authenticators actually deployed. Reconciling a policy written under the old revision with what Revision 4 now requires is a concrete, checkable task rather than a general aspiration.
Check whether authenticators used at AAL2 and AAL3 meet Revision 4's phishing-resistance requirements, and confirm no syncable passkey is relied on at AAL3.
NIST's own final publication page and its summary of changes establish the publication date and the shift on syncable passkeys and phishing-resistance requirements. Actual agency and vendor adoption of the new revision is not documented in the sources opened here.
Sources & reading trail
Confirms the 31 July 2025 final publication date, title and supersession of Revision 3.
government-primary · Source published: 31 July 2025 · Retrieved: 16 September 2026
Lists the key changes from Revision 3, including integration of syncable passkeys and subscriber-controlled wallets in federation.
government-primary · Source published: Not established · Retrieved: 16 September 2026
States the AAL2 and AAL3 phishing-resistance requirements and the restriction of syncable authenticators from AAL3.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Establishes the Revision 3 baseline definition of AAL1 through AAL3 and the verifier impersonation resistance terminology superseded by Revision 4.
government-primary · Source published: 1 June 2017 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.