# Frequently asked questions about IAL2

> Common IAL2 questions: whether a selfie or NFC is required, non-US documents, fuzzy matching, and how IAL2 compares with FedRAMP, IAL3, AAL2 and EPCS.

Source: https://help.withpersona.com/articles/FQRg0lhm5WyVqQ1tMLl5zU/
Section: Solutions > Overview > IAL2 identity proofing

## Overview

These are the questions that come up most often when organizations set up an IAL2 flow with Persona. For the full picture, start with [IAL2 identity proofing with Persona](https://help.withpersona.com/articles/QC1OAt4zLihlELoVNJ5jmK/).

## Is a selfie required for IAL2?

For a remote flow with no human reviewer, effectively yes. IAL2 requires you to confirm the person owns the evidence, and NIST names three ways to do it: a biometric comparison, a non-biometric method, or digital evidence. The biometric option, a live selfie compared to the ID photo, is the only one that is fully automated. The non-biometric options are a code mailed to a validated postal address or a visual comparison by a trained agent.

So a selfie is **required by IAL2** in practice for remote, unattended proofing, and Persona's IAL2 templates include a Selfie Verification on every pathway.

## Is NFC required for IAL2?

No. Reading a passport's NFC chip is one way to get SUPERIOR evidence, which meets IAL2 on its own. Other pathways reach IAL2 without NFC, for example a US REAL ID checked with AAMVA plus a selfie.

NFC is **required by IAL2** only for the passport-with-chip pathway, because that pathway depends on the chip's cryptographic validation. If you use it, keep the PKI validation check required.

## Can people use non-US documents?

Yes, with a condition. A non-US driver's license or ID counts as STRONG evidence only if its details can be checked against an issuing or authoritative source in that country. Otherwise it counts as FAIR evidence, which must be paired with STRONG evidence.

To support non-US documents in a fully compliant flow, you can add an international Database Verification for each country you accept, or treat those documents as FAIR. The [IAL2 framework templates solution](https://help.withpersona.com/articles/0jfM3U58A4LXRbPumx7FZb/#making-the-flow-fully-ial2-compliant) lists the options.

## Do non-US passports work?

A passport whose NFC chip is read and validated is SUPERIOR evidence, whatever country issued it. A passport without a chip read counts as STRONG only when it is validated with an issuing or authoritative source.

## Does fuzzy name matching affect IAL2 compliance?

No. How strictly names are matched, for example allowing a nickname or a missing middle name, does not decide IAL2 compliance. What carries the weight is the evidence and its validation against an issuing source.

## Are knowledge-based questions allowed?

No. Under NIST SP 800-63A-4, knowledge-based verification, such as questions about past addresses, is not allowed as a way to confirm the person owns the evidence.

## Is IAL2 the same as FedRAMP?

No. FedRAMP authorizes a cloud service provider for US government use. Some FedRAMP audits cite NIST 800-63, which is how IAL2 requirements come up, but the two are different. Persona separately holds a FedRAMP Moderate authorization. See [Persona for Government and FedRAMP Overview](https://help.withpersona.com/articles/BRAFibxOAvSmc3gN4FAeZI/).

## Is IAL2 the same as IAL3?

No. IAL3 is a higher level that requires identity proofing in person, or supervised remotely by a trained operator. Persona does not offer an IAL3 flow.

## Is IAL2 the same as AAL2?

No. IAL2 is about proving who someone is when they first sign up. AAL2, defined in NIST SP 800-63B, is about how strongly a returning user signs in. They are independent: a flow can meet one without the other.

## Does IAL2 cover DEA EPCS?

Only part of it. IAL2 covers the identity proofing step for prescribers. Electronic Prescriptions for Controlled Substances (EPCS) also requires two-factor authentication, credentialing and audit trails, which IAL2 does not cover.

## Is a selfie required for KYC?

No. KYC and CIP are a different set of rules, and they do not require a selfie. If your flow only needs KYC, see the [KYC Solution](https://help.withpersona.com/articles/2OOWdhAoEeVrMRKRFENneW/).

## Which NIST revision does Persona follow?

The current specification is **NIST SP 800-63A-4**, published in July 2025. Revision 3 was withdrawn on August 1, 2025. Persona's Kantara approval for IAL2 identity proofing was assessed under revision 3. The evidence combinations that meet IAL2 are the same in both revisions.

## Are the IAL2 framework templates compliant out of the box?

No. They are aligned with IAL2. Two of the four pathways meet IAL2 as configured, and the other two need changes for full compliance. The [IAL2 framework templates solution](https://help.withpersona.com/articles/0jfM3U58A4LXRbPumx7FZb/) explains which changes. Persona provides the components, and you are responsible for deciding whether your implementation meets your requirements.

## Do I need the IAL2 or the TEFCA solution?

Most organizations need the **IAL2 framework templates** solution. Use the **TEFCA** solution only if you are a TEFCA Individual Access Services provider that needs an OIDC ID token with verified patient details. TEFCA is one application of IAL2. See [TEFCA Individual Access Services (IAS)](https://help.withpersona.com/articles/ARLLoIOGw9P5nGlnC53uc/).
