Authentication Assurance Level (AAL)

NIST SP 800-63's three-step scale for the strength of an authentication process: AAL1 basic, AAL2 two distinct factors, AAL3 phishing-resistant hardware-backed keys.

The authentication assurance level (AAL) is NIST SP 800-63B-4’s measure of how strong an authentication process is, and so how much confidence a relying party can have that the claimant controls the authenticators bound to the account. It is sometimes written “authenticator assurance level”. There are three levels. AAL1 gives basic confidence and permits single-factor or multi-factor authentication. AAL2 gives high confidence and requires two distinct authentication factors; verifiers must also offer a phishing-resistant option. AAL3 gives very high confidence and requires a cryptographic authenticator with a non-exportable private key that provides phishing resistance, which rules out syncable authenticators such as synced passkeys.

SP 800-63-4 keeps AAL separate from the identity assurance level, which grades proofing, and the federation assurance level, which grades assertions. Each is selected on its own scale for the harm a failure could cause. A high AAL shows that the same subscriber is returning; it does not show who that subscriber really is unless the IAL behind the account is also adequate.

Exam relevance: a scenario is likely to describe an authenticator and ask which level it meets, or to mix up the three scales. Candidates are expected to link AAL to authentication strength only, and to associate AAL3 with phishing-resistant, hardware-protected keys.