📖New Article

The Resilience Imperative: Why Unified Storage and Immutable Backups Define 2026 Enterprise Strategy

SIAA - Identity & Access Assurance | NIST 800-63 IAL/AAL Compliance | Spictera
PRODUCTION READY

Identity first. Security always.

NIST 800-63 compliant identity and access assurance with progressive IAL/AAL levels. Match authentication strength to service risk.

NIST 800-63 Compliance

SIAA implements NIST SP 800-63 Digital Identity Guidelines with separate controls for Identity Assurance (IAL) and Authenticator Assurance (AAL)

Identity Assurance Levels (IAL)

Measures confidence in the claimed identity

  • IAL1: Self-asserted attributes
  • IAL2: Verified by reliable source (HR, government)
  • IAL3: Physical in-person verification

Authenticator Assurance Levels (AAL)

Measures authentication mechanism strength

  • AAL1: Username + Password
  • AAL2: Password + MFA (SMS/OTP/App)
  • AAL3: Hardware cryptographic token

Identity Assurance Levels (IAL)

IAL1

Self-Asserted Identity

Attributes are self-asserted or should be treated as self-asserted.

Example: User registration with email verification only

IAL2

Verified Identity

Remote or in-person identity proofing required. Identifying attributes verified using reliable sources (government database, HR system).

Example: Government ID verification or corporate HR system validation

IAL3

In-Person Identity Proofing

Physical in-person identity proofing required. Attributes verified by authorized representative through examination of physical documentation.

Example: Physical ID card presentation to certified authority

Authenticator Assurance Levels (AAL)

AAL1

Single-Factor Authentication

Proof of possession and control of authenticator through secure protocol. Single-factor authentication using a wide range of technologies.

Example: Username + Password

AAL2

Two-Factor Authentication

High confidence through proof of possession of two different authentication factors. Approved cryptographic techniques required.

Example: Username + Password + MFA (SMS/OTP/Authenticator App)

AAL3

Hardware Cryptographic Authentication

Very high confidence based on proof of possession of a key through cryptographic protocol. Requires 'hard' cryptographic authenticator with verifier impersonation resistance.

Example: PIV card, YubiKey, Smart Card, or device-stored certificates in tamper-proof area

Service-Level Assurance Matrix

Service TypeIALAALAuthentication Methods
Public Website
IAL1
AAL1
Username/Password
Employee Portal
IAL2
AAL2
Password + MFA (SMS/OTP)
Financial Transactions
IAL2
AAL3
YubiKey, Smart Card, PIV
Government Services
IAL3
AAL3
Physical ID + Smart Card

Production-Ready Authentication Methods

✓ Verified

Microsoft EntraID

Full integration with Azure AD/EntraID

IAL1-IAL2
AAL1-AAL3
✓ Verified

Freja eID

Swedish BankID-level authentication with organization ID support

IAL2-IAL3
AAL2-AAL3
✓ Verified

Smart Cards & YubiKey

Hardware token authentication (PIV, FIDO2)

IAL2-IAL3
AAL3
✓ Verified

Kerberos SSO

Single Sign-On integration with Active Directory

IAL2
AAL1-AAL2
✓ Verified

FIDO2/Passkeys

Windows Hello, Face ID, Touch ID support

IAL1-IAL2
AAL2-AAL3
✓ Verified

Directory Federation

User sync with groups, roles, and permissions

IAL2
AAL1-AAL2

Enterprise-Grade Features

Time-Limited Access

Grant temporary access with automatic expiration—perfect for contractors, support staff, and third-party auditors.

Just-in-Time Provisioning

Access is granted only when needed and automatically revoked when the session ends or time expires.

Directory Integration

Sync users, groups, and roles from existing LDAP/AD directories with automatic updates.

Policy-Based Access

Match authentication strength to service risk with per-application assurance level requirements.

Industry Applications

🏥

Healthcare

  • IAL3 + AAL3 for e-prescriptions and EHR
  • Freja eID + smart cards for clinicians
  • Time-limited contractor access
  • Geo-fencing for cross-border access
🏦

Financial Services

  • AAL3 with YubiKey + FIDO2 for transactions
  • Kerberos SSO for internal systems
  • Microsoft EntraID federation
  • Hardware token support (PIV cards)
🏛️

Government

  • IAL3 + AAL3 for citizen services
  • Smart card PKI authentication
  • Time-limited support access
  • Multi-level assurance (IAL/AAL 1-3)
💼

Enterprise IT

  • IAL2 + AAL2 for corporate apps
  • Microsoft EntraID SSO
  • Kerberos for Windows networks
  • FIDO2 passwordless auth

Core Capabilities

Per-Service Protection

  • Each service declares minimum IAL and AAL requirements
  • Risk signals from device posture, geolocation, network, and behavior
  • Actions: allow, step-up authentication, deny, time-box access

Enterprise Integration

  • AD/LDAP user federation for central account lifecycle
  • SSO via Kerberos across web, desktop, and mobile
  • End-to-end audit trails with non-repudiation

Spictera Product Synergy

+ Unified Storage

Secure data access with authentication-based policies and immutable audit logs stored in SPIR snapshots

+ Secure Workspace

Authenticated remote sessions with identity verification and session recording

+ Geo-Fencing

Location-based authentication policies combined with geo-fencing for complete access control

Outcomes

Reduce Account Takeover

99.9% threat detection with hardware tokens and MFA

Faster Login

Passwordless and SSO authentication in seconds

Audit Ready

NIST 800-63 compliant with immutable audit trails

Frequently Asked Questions