NIST finalized SP 800-63, Revision 4 ("Digital Identity Guidelines") in July 2025, formally superseding Revision 3 as of August 1, 2025. The DoD CIO's October 24, 2025 Multi-Factor Authentication memorandum, which establishes the current non-PKI MFA framework for personal-device BYOD access to DoD unclassified and Secret networks, was issued after Revision 4 became the current version of the standard. Organizations verifying which SP 800-63 revision underlies a specific DoD non-PKI MFA requirement should confirm this against the current text of the DoD CIO memo and its attachments, since NIST's identity-assurance framework is the technical basis DoD policy builds upon rather than a DoD-specific document.
What changed in Revision 4
NIST's Revision 4 of SP 800-63 represents a comprehensive update from Revision 3, following an almost four-year process that included two public drafts and roughly 6,000 individual public comments. Notable changes include expanded fraud-detection requirements and recommendations for identity-proofing processes, restructured identity-proofing controls, new controls addressing injection attacks and forged media ("deepfakes"), and — most relevant to non-PKI MFA — the integration of syncable authenticators, including synced passkeys, into the authentication and authenticator-management guidance (SP 800-63B-4).
How this connects to DoD non-PKI MFA policy
The DoD CIO's October 2025 MFA memorandum builds its non-PKI MFA framework, including requirements for identity-proofing users who do or do not already hold a DoD-approved PKI credential, on top of the current federal digital-identity-assurance baseline. Because Revision 4 was already the current, non-superseded version of SP 800-63 by the time that memo was issued, any DoD guidance describing non-PKI MFA assurance levels, syncable-authenticator treatment, or identity-proofing tiers should be read against Revision 4's requirements rather than the withdrawn Revision 3 text, unless a specific DoD document states otherwise.
This entry restates publicly available technical and policy sources and asserts nothing beyond them. It is not legal or compliance advice. BYODPolicy.org is not affiliated with, endorsed by, or accredited by NIAP, NIAP-CCEVS, or any government body.