# IAL2 identity proofing with Persona

> What NIST IAL2 identity proofing requires, which parts of a Persona flow the standard asks for, and which ones Persona adds to raise pass rates or stop fraud.

Source: https://help.withpersona.com/articles/QC1OAt4zLihlELoVNJ5jmK/
Section: Solutions > Overview > IAL2 identity proofing

## Overview

Persona supports identity proofing flows built to NIST Identity Assurance Level 2 (IAL2). This article explains what IAL2 asks for, how a Persona flow meets each part of it, and where Persona adds checks the standard does not require.

Small differences between flows can make it hard to tell what is actually needed for IAL2. So this article keeps two things apart:

- **Required by IAL2:** what the NIST specification asks for, and nothing more.
- **Persona addition:** an extra verification, field, or check that Persona includes to raise pass rates or reduce fraud. Useful, but not required by the standard.

To build a flow, start from the [IAL2 framework templates solution](https://help.withpersona.com/articles/0jfM3U58A4LXRbPumx7FZb/), which you can add to your Sandbox from the Solutions Library.

## What IAL2 is

IAL2 is a level of identity assurance defined by the US National Institute of Standards and Technology (NIST) in Special Publication 800-63A. The current version is **NIST SP 800-63A-4**, published in July 2025. It replaced revision 3, which was withdrawn on August 1, 2025.

IAL2 means you have good evidence that a person is who they claim to be, and that the person in front of you is the owner of that identity. It can be reached remotely, without an in-person visit.

IAL2 is a US federal standard. Other regions have their own equivalents, such as eIDAS (levels Substantial and High) in the EU and the UK Digital Identity and Attributes Trust Framework (DIATF, with GPG 45).

Organizations usually meet IAL2 requirements in settings like these:

- Workforce identity verification, often because a FedRAMP audit cites NIST 800-63
- Higher education, for federal student aid verification
- Healthcare provider onboarding
- DEA Electronic Prescriptions for Controlled Substances (EPCS) prescriber verification
- Federal contractors and government programs
- Patient access under TEFCA, which is one application of IAL2

## The three steps of identity proofing

NIST splits identity proofing into three steps. All three are required by IAL2.

| Step             | What it means                                                                                             | Example in a Persona flow                                     |
| ---------------- | --------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
| **Resolution**   | Collect the minimum details that uniquely identify the person, typically name, date of birth and address. | The details read from the person's ID.                        |
| **Validation**   | Collect identity evidence, confirm it is genuine, and confirm its details are accurate.                   | A Government ID Verification plus an AAMVA or NFC chip check. |
| **Verification** | Confirm the person is the one the evidence belongs to.                                                    | A Selfie Verification compared to the photo on the ID.        |

## Evidence that meets IAL2

NIST grades identity evidence by strength. In plain terms:

| Strength     | What it is                                                                                                     | Examples                                                                                      |
| ------------ | -------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- |
| **SUPERIOR** | The issuer saw the person in person, and the evidence carries a photo, a biometric and cryptographic security. | A passport whose chip is read over NFC and validated cryptographically.                       |
| **STRONG**   | Issued under regulated identity proofing, with a photo and security features that are hard to copy.            | A US driver's license or state ID, a passport without a chip read, a permanent resident card. |
| **FAIR**     | The issuer did some proofing of the person.                                                                    | A recent bank statement or utility bill showing name and address.                             |
| **WEAK**     | Little or no proofing by the issuer.                                                                           | A library card. Not usable for IAL2.                                                          |

Revision 4 tightened STRONG so that the evidence must carry a photo or a biometric.

Any one of these combinations meets IAL2. They are the same in revisions 3 and 4.

| Combination         | Example                                                           |
| ------------------- | ----------------------------------------------------------------- |
| 1 SUPERIOR          | A passport with its NFC chip read and validated                   |
| 2 STRONG            | A US driver's license and a passport                              |
| 1 STRONG and 1 FAIR | A US driver's license and a recent bank statement or utility bill |

## Validating evidence against the issuing source

Holding a STRONG document is not enough on its own. **To count as STRONG, the document's details have to be confirmed with the issuing source or another authoritative source.** This is the part of IAL2 that most often decides whether a flow is fully compliant.

How Persona does this:

- **US driver's licenses and state IDs:** an [AAMVA Verification](https://help.withpersona.com/articles/1wiQ7wAhmnKh6mesCGopKl/) checks the license details with the issuing state's records. This works for states that take part in AAMVA's service.
- **Passports with a chip:** an [NFC chip read](https://help.withpersona.com/articles/1iu1Fak8y9RiOE2FddXrHJ/) checks the chip's cryptographic signature, which proves the issuer created the data.
- **Non-US IDs:** these count as STRONG only if Persona can check the details against an issuing or authoritative source in that country. Otherwise they count as FAIR.

A check against a general US database of names, dates of birth and addresses is useful, but it is not the same as checking with the document's issuer. The [IAL2 framework templates solution](https://help.withpersona.com/articles/0jfM3U58A4LXRbPumx7FZb/) explains where this matters.

## Verifying the person: three options

Revision 4 names three ways to confirm the person owns the evidence. A provider should support more than one.

| Option               | How it works                                                                                                                                                                                                    |
| -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Biometric**        | An automated comparison of a live selfie with the photo on or in the evidence. It must include presentation attack detection (liveness).                                                                        |
| **Non-biometric**    | A confirmation code mailed to a validated postal address, or a visual comparison by a trained agent.                                                                                                            |
| **Digital evidence** | Proof of possession through a strongly authenticated account tied to the evidence, or a cryptographically verifiable credential such as a mobile driver's license, an EU digital identity wallet or a PIV card. |

Biometric comparison is the only fully automated remote option. That is why a selfie is effectively required for a remote, unattended IAL2 flow, and why Persona's IAL2 templates use a Selfie Verification.

ℹ️

Knowledge-based questions, such as "Which of these streets have you lived on?", are not allowed for verification under revision 4. Under the current specification, EU-issued eIDs can stand in for biometric comparison for people in the EU.

## Required by NIST and added by Persona

The two tables below separate what IAL2 asks for from what Persona includes on top. The labels match the ones used in the [IAL2 framework templates solution](https://help.withpersona.com/articles/0jfM3U58A4LXRbPumx7FZb/).

### Required by IAL2

| Requirement                                             | How Persona meets it                                                                 |
| ------------------------------------------------------- | ------------------------------------------------------------------------------------ |
| Resolve the identity with minimum attributes            | Name, date of birth and address are collected from the ID.                           |
| Evidence that meets one of the combinations             | Pathways for 1 SUPERIOR, 2 STRONG, and 1 STRONG plus FAIR evidence.                  |
| Validate STRONG evidence with the issuing source        | AAMVA Verification for US licenses and IDs, NFC chip validation for passports.       |
| Verify the person owns the evidence                     | Selfie Verification compared to the ID photo, with liveness detection.               |
| Enrollment code to confirm contact details (revision 3) | A one-time code sent at the start of the flow. Persona sends it by email by default. |

### Persona addition

| Addition                                                 | Why Persona includes it                                                                                                       |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- |
| Native mobile flow required                              | Barcode capture is hard on a webcam, and NFC chip reading only works on a phone. On iPhone, an App Clip means no app install. |
| Database check on every pathway, including NFC passports | Adds a further check of the person's details and lets the flow accept more documents.                                         |
| Two FAIR documents in the fair evidence pathway          | IAL2 needs one. The second adds assurance.                                                                                    |
| Email first for the one-time code, phone optional        | An email address changes less often than a phone number. NIST asks for a code, not for email specifically.                    |
| Fraud and quality checks inside the ID and selfie steps  | Checks such as injection detection catch more fraud. Liveness is also expected by the biometric option above.                 |

TEFCA flows add further fields for patient record matching, such as SSN collection and historical addresses. Those are needed for TEFCA, not for IAL2. See the [TEFCA guide](https://help.withpersona.com/articles/ARLLoIOGw9P5nGlnC53uc/).

## How IAL2 differs from related standards

IAL2 is often confused with other standards. Each one below answers a different question.

| Standard        | What it covers                                                                     | How it relates to IAL2                                                                                            |
| --------------- | ---------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| **IAL3**        | Identity proofing in person, or supervised remotely by a trained operator.         | A higher level than IAL2. Persona does not offer an IAL3 flow.                                                    |
| **AAL2**        | How strongly a returning user signs in, defined in NIST SP 800-63B.                | A separate dial. A flow can be IAL2 without being AAL2, and the reverse.                                          |
| **FedRAMP**     | Authorization of a cloud service provider for US government use.                   | Some FedRAMP audits cite NIST 800-63, which is how IAL2 requirements come up. It is not the same thing.           |
| **DEA EPCS**    | Rules for prescribers who send electronic prescriptions for controlled substances. | IAL2 covers only the identity proofing part. EPCS adds two-factor authentication, credentialing and audit trails. |
| **KYC and CIP** | Financial rules for knowing your customer.                                         | A different regime. A selfie is not required for KYC.                                                             |

Persona separately holds a FedRAMP Moderate authorization. See [Persona for Government and FedRAMP Overview](https://help.withpersona.com/articles/BRAFibxOAvSmc3gN4FAeZI/).

## Persona's Kantara approval, and your responsibility

Persona is approved by the Kantara Initiative for IAL2 identity proofing. The approval was assessed under NIST SP 800-63A revision 3, and it covers identity proofing only. It does not cover authenticators or federation.

⚠️

Persona provides the components for an IAL2 flow. You are responsible for deciding whether your implementation meets your own requirements. Persona's IAL2 framework templates are aligned with IAL2 but are not fully compliant out of the box. Check your configuration with your compliance team before you rely on it.

## IAL2 or TEFCA: which solution do I need?

More organizations need a general IAL2 flow than a TEFCA flow. TEFCA is one application of IAL2, for patient access to health records. Both are in the Solutions Library.

| If you need                                                                                                                      | Use                                                                                                                    |
| -------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- |
| IAL2 identity proofing for workforce, education, healthcare providers, EPCS, government or anything else                         | The **IAL2 framework templates** solution. See [IAL2 framework templates solution](https://help.withpersona.com/articles/0jfM3U58A4LXRbPumx7FZb/). |
| Identity proofing for a TEFCA Individual Access Services (IAS) provider, with an OIDC ID token carrying verified patient details | The **TEFCA** solution. See [TEFCA Individual Access Services (IAS)](https://help.withpersona.com/articles/ARLLoIOGw9P5nGlnC53uc/).                |

The IAL2 framework templates install directly into your Sandbox. The TEFCA solution also needs some setup steps that only Persona can complete, so your Persona account team finishes it with you.

## Where to go next

Ready to build? The [IAL2 framework templates solution](https://help.withpersona.com/articles/0jfM3U58A4LXRbPumx7FZb/) walks through what gets installed, which template to pick, and what to change for full compliance. If you have a specific question, such as whether NFC is required or whether non-US documents count, see [Frequently asked questions about IAL2](https://help.withpersona.com/articles/FQRg0lhm5WyVqQ1tMLl5zU/).
