NIST IAL2 · Title IV Identity Verification

MFA Proves It's the Same Person.Verified Identity Proves It's the Right One.


Stolen and synthetic identities are drawing federal student aid. The Department of Education now accepts identity verification performed by a NIST IAL2 compliant entity and requires you to keep the record. QuickLaunch Verified Identity puts that check inside the account claim your students already complete, using the verification provider you already chose.

See It to Believe It

Bring your own provider · Audit record written automatically

Built to the standards your auditors will name
Why This Became Urgent

Aid Fraud Became an Identity Problem. Then It Became Your Compliance Problem.

Organized fraud rings learned that an open-enrollment institution will create an account, enroll a student, and disburse aid without ever meeting the person. The Department of Education has called the resulting rate of stolen-identity fraud a threat that imperils the Title IV programs themselves and the response landed on financial aid offices as new, mandatory, manual work.

The relief the Department offered is specific: identity verified by a NIST IAL2 compliant entity counts. That single sentence turned identity proofing from a policy debate into a procurement and orchestration question.

1

Every applicant is screened

As of April 26, 2026 the FAFSA screens all applicants, and some are asked to photograph a government-issued photo ID inside the form itself.

2

The requirement reaches backward.

Previously submitted 2026–2027 forms were re-screened, creating new verification requirements for students who had already been offered or had accepted aid.

3

Third-party IAL2 verification is accepted.

Dear Colleague Letter GEN-25-10 added it as acceptable documentation alongside in-person and live video.

4

You must keep the receipt.

The institution has to retain the date the identity was verified and the entity that performed the verification..

5

Fraud has to be reported

Suspected or confirmed misrepresentation goes to the Office of Inspector General, which means the evidence trail matters as much as the check.

The Regulatory Record

How Identity Verification Became a Title IV Requirement

Twelve months of federal action, in the order it happened. Every item below is published guidance, not interpretation.

June 6, 2025

Federal Student Aid calls stolen-identity fraud a threat to the programs

An electronic announcement states that the rate of fraud through stolen identities has reached a level that imperils the federal student aid programs authorized under Title IV. It expands V4 verification selections, and it introduces the provision that matters most: the Department will consider a student's identity verified if it was verified by an entity compliant with NIST IAL2, provided the institution retains the date and the entity. Federal Student Aid electronic announcement.

Summer 2025

Scale becomes visible

The Department reports that focused fraud-detection work identified roughly 150,000 suspect identities in then-current FAFSA forms, all marked for required identity validation by schools before aid could be disbursed, and projected on the order of 125,000 students needing summer verification. Department of Education press release.

August 1, 2025

NIST SP 800-63-4 becomes the current standard

Revision 4 of the Digital Identity Guidelines supersedes revision 3. Volume 800-63A-4 governs identity proofing and enrollment, and confirms that IAL2 may be delivered remotely and can be satisfied without an automated biometric comparison. National Institute of Standards and Technology.

November 26, 2025

Dear Colleague Letter GEN-25-10 codifies the new methods

For the 2026–2027 award year the Department updated acceptable documentation for identity verification, adding a live video call as a substitute for the notary statement, and third-party verification satisfying NIST IAL2. In-person remains the preferred method; IAL2 is an accepted alternative. Dear Colleague Letter GEN-25-10.

April 26, 2026 — in effect now

Every FAFSA applicant is screened, and the net reaches backward

The FAFSA began screening all applicants for identity, with some asked to submit a photo of a government-issued ID before submitting the form. Students who cannot complete it must present identification to the financial aid office before receiving aid. Previously submitted 2026–2027 forms were also re-screened, so new requirements can land on students who were already offered or had accepted aid. Federal Student Aid guidance and institutional advisories.

“The Department will consider a student's identity to be verified if the student's identity was verified by an entity that is compliant with National Institute of Standards and Technology (NIST) Identity Assurance Level 2. In this instance, an institution must retain documentation of the date that the student's identity was verified and the entity that performed the verification.”

— U.S. Department of Education, Federal Student Aid
Why It Ranks With MFA

Two Different Questions. Two Different Standards.

NIST does not treat authentication strength and identity confidence as one measurement. It defines them as separate, independently rated components. Most campuses have invested heavily in one of them.

Authenticator Assurance · AAL

Adaptive MFA

“Is this the same person who set up the account?”

  • Blocks stolen and reused credentials at sign-in
  • Steps up on risky context: new device, new country, odd hour
  • Reaches phishing resistance with passkeys at AAL2
  • Protects the account for its entire life
  • Already deployed on most campuses
Identity Assurance · IAL

Verified Identity

“Who is that person, actually?”

  • Validates government-issued evidence against its issuing source
  • Binds a real human to the institutional record at claim time
  • Stops a synthetic applicant at the claim, before any credential exists
  • Produces the documentation the Department requires you to keep
  • The half of the standard most campuses have not deployed
Perfect MFA on a fraudulent identity is a locked door on a house the fraudster owns. Verified Identity is how you know whose house it is. That is why identity proofing belongs beside multi-factor authentication in the identity program, not somewhere behind it.
Lifecycle & Security

The Source Decides. The Portal Follows.

Because RTDS runs independent of login, lifecycle is enforced by the system of record not by whether someone happens to sign in. Joiners get accounts before they arrive, movers get updated access as their record changes, and leavers lose access when the source says so.

Verification Provider NIST IAL2 Standing Higher-Education Practice
ID.me Kantara-approved
First credential service provider approved conformant to NIST SP 800-63-3 at IAL2 and AAL2, 2018
Published community-college deployments verifying students at IAL2
Persona Kantara-certified
States Kantara certification and IAL2-aligned verification
Dedicated higher-education practice covering aid fraud and account recovery
Socure States IAL2
Real-time identity proofing and fraud scoring
Higher-education practice focused on aid and refund fraud
Nametag States IAL2
Deepfake-resistant verification engine
Purpose-built for student aid applicant verification and help-desk identity
VerifiNow States IAL2
Remote proofing with FSA-oriented audit output
Ghost-student detection and Title IV disbursement workflows

How to read this table. The Department's requirement is that verification be performed by an entity compliant with NIST IAL2. The Kantara Initiative operates the recognized conformity-assessment program against NIST SP 800-63, so a Kantara approval is independent evidence of conformance; the remaining entries reflect each provider's own published IAL2 positioning. The Kantara approval listed here was granted against SP 800-63-3, which revision 4 superseded on August 1, 2025 — confirm current standing and revision with your provider during procurement. Listing is market context for institutions evaluating options, not a QuickLaunch endorsement or a reseller relationship. If your provider is not listed and meets IAL2, QuickLaunch can orchestrate it.

Inside the Claim Flow

One New Step in a Flow Your Students Already Complete

QuickLaunch Account Activation already walks every new student from invited, to verified, to secured, to live. Verified Identity is what the word verified becomes when the Department wants proof.

1

The student starts their claim

The account already exists. Enrollment posted, it was created in Active Directory, and the invitation to claim it went to the student. They open the same self-service claim experience they would have used anyway — nothing new to learn, no separate portal, no second set of instructions from the aid office.

2

QuickLaunch decides whether proofing is required

Policy lives with the institution, evaluated per person: everyone, first-time aid applicants only, students flagged for V4 or V5, a specific cohort or program, or a risk signal on the claim itself. Students who do not need proofing never see it.

3

Your provider runs the verification

QuickLaunch opens a verification session with your IAL2 provider, carrying a reference that binds the session to this student's institutional identity, and hands off to the provider's hosted experience by single-use link. The student presents evidence to the provider, never to a staff inbox.

In-person and live video paths remain available for students who need them.

4

The result comes back authoritatively

QuickLaunch does not trust the browser. The outcome is confirmed server-to-server with the provider and normalized to a single institutional vocabulary: verified, failed, needs review, abandoned, or provider error. A provider outage routes to an operational queue, never to a false rejection of a real student.

5

The assurance record is written

Date of verification, the entity that performed it, the outcome, and the identity it is bound to, recorded against the student the moment the result lands. This is the documentation the Department asks institutions to retain, created as a by-product of the flow rather than as an afterthought.

6

The account is handed over, and MFA is enrolled

A proven student finishes the claim and sets their own credentials — no temporary password is ever issued, so there is nothing sitting in an inbox to phish. They enroll multi-factor authentication or a passkey and walk into single sign-on across campus. Both halves of the standard are satisfied before the account is ever used: the right person, and from now on, the same person.

Watch

Ninety Seconds: The Student Who Isn't Read

Two applicants claim an account on the same morning. Only one of them exists. Watch where the difference gets caught.

Audit Readiness

The Record the Department Asks You to Keep

Guidance is unusually specific about documentation. When identity is verified by a third party, the institution must retain the date the verification happened and the entity that performed it. Institutions must also preserve identification documentation, and report suspected misrepresentation to the Office of Inspector General.

That is a records problem, and records problems are where compliance programs actually fail. A verification that happened but cannot be evidenced is, to an auditor, a verification that did not happen.

QuickLaunch writes the assurance record as part of the transaction and keeps it attached to the identity for the life of the account. Because it lives in the identity platform rather than in a vendor's console or someone's inbox, it is reportable next to everything else you already track: who claimed, when, from where, with which factors, and now with which verification.

Aid officers get a queue instead of an errand. Completed verifications arrive with their evidence already recorded, so staff attention goes to genuine exceptions: the students who need a video call, a trusted referee, or a second attempt.

Assurance Record

Verified On · required
The date verification completed
Verified By · required
The NIST IAL2 entity that performed it
Assurance Level
IAL2
Method
Remote, live video, or in person
Outcome
Verified, failed, or referred for review
Bound Identity
The institutional person record
Reference
Provider session identifier for lookup
Results Across the Network

The Numbers Institutions See

IAL2
the assurance level the Department accepts from a third party
~150K
suspect identities identified in then-current FAFSA forms
Apr 26
2026: every FAFSA applicant screened for identity
2 of 2
NIST assurance axes covered, with MFA already in place
1
flow for the student, with no separate portal to learn
FAQ

Frequently Asked Questions

What is QuickLaunch Verified Identity?
Verified Identity brings NIST IAL2 identity proofing into the moment a student claims their account. QuickLaunch decides when proofing is required, hands the student to your institution's verification provider, receives the authoritative result server-to-server, writes the assurance record the Department of Education asks you to retain, and releases the account once the person behind it is proven.
Does this satisfy the Department of Education's identity verification requirement?
The Department accepts a student's identity as verified when it is verified by an entity compliant with NIST Identity Assurance Level 2, and it requires the institution to retain the date of verification and the entity that performed it. QuickLaunch orchestrates a NIST IAL2 provider and writes exactly that record against the student's institutional identity, so the documentation exists the moment verification completes rather than being assembled later for an audit.
Which verification providers work with QuickLaunch?
Bring your own. QuickLaunch is provider-agnostic by design. If your institution already runs ID.me, Persona, Socure, Nametag, VerifiNow, or another NIST IAL2 provider, QuickLaunch hooks into what you already have and slips it into the flow you already run. You keep your provider relationship and your pricing. QuickLaunch supplies the orchestration, the binding to the student record, and the audit trail.
Isn't multi-factor authentication already handling this?
MFA and identity proofing answer two different questions, and NIST treats them as two independent measures. MFA earns authenticator assurance: confidence that the person signing in is the same person who set the account up. Identity proofing earns identity assurance: confidence in who that person actually is. Verified Identity is the second axis, and it belongs at account claim, where a digital identity is first bound to a real human being.
How much work does this take off the financial aid office?
Verification moves from a manual errand per student into an automated step of a flow students already complete. Instead of scheduling video calls, collecting notary statements, and chasing photo ID over email, staff open a queue where completed verifications already carry the date, the entity, and the outcome. The aid office spends its time on genuine exceptions instead of on the paperwork around every case.
Does IAL2 require biometrics or an in-person visit?
IAL2 proofing can be delivered remotely, and NIST SP 800-63A-4 defines a non-biometric pathway that reaches the same assurance level without an automated comparison of biometric samples. In-person verification remains the Department's preferred method, and QuickLaunch supports in-person and live video paths alongside remote proofing, so each institution sets policy by cohort and risk rather than being forced into one experience.

The Student Identity Journey

Verified Identity is the gate in front of the journey the moment a real person becomes a campus identity.

Case Studies

Institutions Already on One Login

Ready for a Portal That Always
Reflects the Source of Truth?

Users, groups, and memberships synced from your directory validated, audited, and in place before the first login.

Request a Demo