BYODPolicy.org
Primary sources, restated with receipts. No products. No vendor opinions.

Which NIST SP 800-63 revision governs DoD non-PKI MFA?

MFA & Credentialing
Claims Verified
2
Last Verified
July 27, 2026

NIST finalized SP 800-63, Revision 4 ("Digital Identity Guidelines") in July 2025, formally superseding Revision 3 as of August 1, 2025. The DoD CIO's October 24, 2025 Multi-Factor Authentication memorandum, which establishes the current non-PKI MFA framework for personal-device BYOD access to DoD unclassified and Secret networks, was issued after Revision 4 became the current version of the standard. Organizations verifying which SP 800-63 revision underlies a specific DoD non-PKI MFA requirement should confirm this against the current text of the DoD CIO memo and its attachments, since NIST's identity-assurance framework is the technical basis DoD policy builds upon rather than a DoD-specific document.

What changed in Revision 4

NIST's Revision 4 of SP 800-63 represents a comprehensive update from Revision 3, following an almost four-year process that included two public drafts and roughly 6,000 individual public comments. Notable changes include expanded fraud-detection requirements and recommendations for identity-proofing processes, restructured identity-proofing controls, new controls addressing injection attacks and forged media ("deepfakes"), and — most relevant to non-PKI MFA — the integration of syncable authenticators, including synced passkeys, into the authentication and authenticator-management guidance (SP 800-63B-4).

How this connects to DoD non-PKI MFA policy

The DoD CIO's October 2025 MFA memorandum builds its non-PKI MFA framework, including requirements for identity-proofing users who do or do not already hold a DoD-approved PKI credential, on top of the current federal digital-identity-assurance baseline. Because Revision 4 was already the current, non-superseded version of SP 800-63 by the time that memo was issued, any DoD guidance describing non-PKI MFA assurance levels, syncable-authenticator treatment, or identity-proofing tiers should be read against Revision 4's requirements rather than the withdrawn Revision 3 text, unless a specific DoD document states otherwise.

This entry restates publicly available technical and policy sources and asserts nothing beyond them. It is not legal or compliance advice. BYODPolicy.org is not affiliated with, endorsed by, or accredited by NIAP, NIAP-CCEVS, or any government body.

  1. NIST — SP 800-63 Digital Identity Guidelines, Revision 4 (published July 2025, effective Aug. 1, 2025). https://pages.nist.gov/800-63-4/
  1. NIST — SP 800-63-4 publication landing page (volumes: 800-63-4, 800-63A-4, 800-63B-4, 800-63C-4). https://pages.nist.gov/800-63-4/sp800-63.html
  1. NIST — SP 800-63-3 archive notice (superseded by SP 800-63-4 as of Aug. 1, 2025). https://pages.nist.gov/800-63-3/
  1. DoD CIO Memorandum, "Multi-Factor Authentication (MFA) for Unclassified & Secret DoD Networks," Oct. 24, 2025 (cleared for open publication Dec. 1, 2025). https://dodcio.defense.gov/Portals/0/Documents/Library/MFA-U-S-DoDNetworks.pdf