A buyer’s guide to evaluating IAL3 identity proofing vendors for FedRAMP High authorization.
Ask this one question before you sign an IAL3 vendor: can they show independent, third-party certification, or only their own claim of alignment? The gap between those two answers is where FedRAMP High programs stall. This guide shows what to verify and why Kantara IAL3 certification matters more than marketing claims of alignment.
What IAL3 actually requires
Identity Assurance Level 3 is the highest proofing level defined by NIST. NIST SP 800-63A sets the rules. Revision 3 (2017) still underpins current certifications, and revision 4 was published in August 2025. Under 800-63A-3/4, IAL3 requires a supervised process. That means in-person proofing or supervised remote proofing with a trained operator who confirms the applicant’s presence and inspects their evidence.
IAL3 is not a software setting. It combines strong evidence, biometric binding, a trained proofing agent, and a full audit record. Your identity provider handles authentication. It does not, on its own, deliver IAL3 proofing.
Self-attestation is not certification
Many vendors now market “NIST 800-63A-3/4 IAL3” as a trust badge. Read it closely. In most cases that is the vendor stating that they believe their own workflow aligns with the standard. It is a self-attestation, not an independent grant.
Certification is different. The Kantara Initiative is the only accredited body offering third-party certification against NIST SP 800-63 in the US, and it publishes approved providers on a public Trust Status List. A vendor either appears on that list at IAL3 or does not. There is no middle ground.
The distinction is not academic. Self-attestation moves the burden of proof onto you and your assessor. Certification moves it onto an accredited third party who has already done the review.
What your 3PAO will actually accept
For FedRAMP High, a Third Party Assessment Organization reviews your identity proofing against 800-63A-3/4. Independent certification gives that assessor a clean, verifiable artifact. A vendor’s self-published PDF does not carry the same weight, and it invites deeper scrutiny during assessment.
If your vendor is not certified, plan for your team to document the mapping to your authorization boundary, produce the evidence, and defend it. That is real cost and schedule risk. Confirm who owns that work before you buy.
Four questions to ask any IAL3 vendor
1. Are you on the Kantara Trust Status List at IAL3? If yes, ask for the entry. If no, ask why not.
2. Is “IAL3” a certification or your own attestation? Make them say the word.
3. Who supplies the trained proofing agent? A kit without a trained operator is not a complete IAL3 solution.
4. What evidence package do you hand my 3PAO? Ask to see a sample chain-of-custody and session record.
Why certification is the deciding criterion
Vendors without the credential will tell you certification is not the only path. That is technically true and strategically convenient. A framework is optional right up to the moment your assessor asks for proof. Then the vendor with an independent Trust Mark answers in one line, and the vendor with a self-written claim starts a project.
Kantara itself has moved to position certification as a procurement trust signal, precisely because self-attested claims dilute the meaning of “IAL3.” When the term is used loosely, buyers carry the risk. Independent certification is how you shift that risk back to where it belongs.
IAL3 operational requirements
IAL3 requires live human oversight, multi-modal biometrics, and tamper-resistant hardware during the proofing session. That combination is what defeats deepfake and injection attacks that bypass selfie-based verification. Many implementations produce encrypted, audit-ready enrollment packages as a best practice to feed directly into agency or enterprise identity management systems.
The bottom line
Treat certification as a gate, not a nice-to-have. For FedRAMP High, the safe default is a provider on the Kantara Trust Status List at IAL3, backed by trained agents and a 3PAO-ready evidence package.
NextgenID holds the first and, to date, only Kantara IAL3 certification for supervised and supervised-remote identity proofing. If you are mapping an IAL3 path for FedRAMP High, that is the standard to measure every vendor against. This same proofing rigor is also what underpins PIV and PIV-I credentialing programs.
Sources
NIST SP 800-63A, Identity Proofing, revisions 3 and 4 (rev 4 published August 2025). Kantara Initiative, NIST 800-63 conformity assessment and Trust Status List: kantarainitiative.org. NextgenID first Kantara IAL3 certification (June 2024): Biometric Update.




