RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Defense

Defense / From the archive · 31 July 2025 event · prepared 16 September 2026

NIST's 2025 identity guidance drew a line around syncable passkeys

Revision 4 requires phishing-resistant authentication at higher assurance levels and bars synced keys from the top tier.

Visual for this record: NIST's 2025 identity guidance drew a line around syncable passkeys
Visual published by pages.nist.gov, shown for identification of the record. Credit: pages.nist.gov · source page ↗ Rights: owner-review-pending.

What the document says

NIST published Special Publication 800-63-4, the fourth revision of its Digital Identity Guidelines, on 31 July 2025, superseding Revision 3, which had stood since 2017. The summary of changes lists several substantive shifts: expanded fraud-detection requirements for identity proofing, new controls addressing injection attacks and forged media such as deepfakes, a subscriber-controlled wallet option added to the federation model, and explicit integration of syncable authenticators, meaning synced passkeys, into the authenticator catalogue. The authentication component, SP 800-63B-4, keeps the three Authenticator Assurance Levels from Revision 3 but changes what each level requires: AAL2 now states that verifiers shall offer at least one phishing-resistant authentication option, and AAL3 requires the authenticator itself to provide phishing resistance. Syncable passkeys are explicitly permitted at AAL1 and AAL2, but the document states they shall not be used at AAL3, because a syncable credential's private key is, by design, exportable to other devices.

Confidence and limits

The publication date, title and the specific requirement language summarised above come from NIST's own current guidance pages, which is strong, direct evidence for what changed on paper. What this account does not establish is how quickly federal agencies or vendors have actually implemented the new AAL2 and AAL3 requirements, since conformance and adoption data were not published on the pages opened here. Revision 3's own definition of verifier impersonation resistance, now folded into the plainer term phishing resistance, is included for comparison from NIST's still-published Revision 3 page.

Why it mattered

Making phishing-resistant authentication a requirement rather than a recommendation at AAL2, the level most consumer and enterprise services actually target, raised the practical bar for what counts as adequate multi-factor authentication under a federal reference standard. Explicitly addressing syncable passkeys mattered because the technology had already spread through consumer platforms before this guidance caught up, leaving agencies and vendors without a clear answer on where a synced credential fit until this revision drew the line at AAL3.

Defensive takeaway

If your organisation cites an AAL2 requirement in policy, check whether your current authenticators actually meet the phishing-resistance requirement in Revision 4, not only the weaker Revision 3 baseline.

  • Do we know which AAL our critical systems are meant to meet, and was that target set under Revision 3 or Revision 4?
  • Are any of our AAL3 use cases relying on a syncable passkey, which this revision now excludes?
  • Does our authenticator policy distinguish phishing-resistant options from ordinary one-time-code multi-factor authentication?

A revised assurance level is a paper requirement until it is checked against the authenticators actually deployed. Reconciling a policy written under the old revision with what Revision 4 now requires is a concrete, checkable task rather than a general aspiration.

Defensive takeaway

Check whether authenticators used at AAL2 and AAL3 meet Revision 4's phishing-resistance requirements, and confirm no syncable passkey is relied on at AAL3.

NIST's own final publication page and its summary of changes establish the publication date and the shift on syncable passkeys and phishing-resistance requirements. Actual agency and vendor adoption of the new revision is not documented in the sources opened here.

Sources & reading trail

Digital Identity Guidelines (NIST SP 800-63-4) ↗

Confirms the 31 July 2025 final publication date, title and supersession of Revision 3.

government-primary · Source published: 31 July 2025 · Retrieved: 16 September 2026

SP 800-63-4: Digital Identity Guidelines - Summary of Changes ↗

Lists the key changes from Revision 3, including integration of syncable passkeys and subscriber-controlled wallets in federation.

government-primary · Source published: Not established · Retrieved: 16 September 2026

Digital Identity Guidelines: Authentication and Authenticator Management (SP 800-63B-4) ↗

States the AAL2 and AAL3 phishing-resistance requirements and the restriction of syncable authenticators from AAL3.

government-primary · Source published: Not established · Retrieved: 16 September 2026

Digital Identity Guidelines: Authentication and Lifecycle Management (SP 800-63B, Revision 3) ↗

Establishes the Revision 3 baseline definition of AAL1 through AAL3 and the verifier impersonation resistance terminology superseded by Revision 4.

government-primary · Source published: 1 June 2017 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.