Scope - What This Guide Covers
This guide focuses on implementing FIPS 201-2 for federal agencies and contractors issuing Personal Identity Verification (PIV) credentials. It includes requirement breakdowns, implementation paths, and integration checkpoints for identity management systems that support PIV card issuance, authentication, and lifecycle management.
This guide does NOT cover:
- CAC (Common Access Card) military-specific requirements
- State or local government ID programs outside federal scope
- Commercial identity verification programs (NIST 800-63 digital identity guidelines are separate)
Key Concepts and Definitions
Personal Identity Verification (PIV) Card: A dual-interface smart card issued to federal employees and contractors containing cryptographic keys, biometric data, and identity credentials for physical and logical access.
FIPS 201-2: Federal Information Processing Standard Publication 201-2, specifying PIV requirements. It defines credential lifecycle, card topology, biometric capture, authentication mechanisms, and interoperability requirements.
PIV-I (PIV-Interoperable): A credential following FIPS 201 technical specifications but issued outside the federal PIV infrastructure, typically for contractors or non-federal personnel requiring comparable authentication.
Card Management System (CMS): Software that handles PIV credential issuance, personalization, activation, suspension, and revocation across your organization's identity lifecycle.
FICAM (Federal Identity, Credential, and Access Management): The federal architecture integrating PIV credentials with access control systems, directories, and authentication services.
Requirements Breakdown
Identity Proofing and Registration (FIPS 201-2 Section 2.1-2.7)
Your registration process must achieve Identity Assurance Level 3, requiring:
- Two forms of identity source documents in original form (one must be a valid government-issued photo ID)
- Biometric capture: fingerprints (two) and facial image
- Background investigation appropriate to the position's risk level
- Sponsorship by an authorized official
Identity proofing must occur in person. Remote identity proofing doesn't satisfy FIPS 201-2 for initial PIV issuance.
Card Activation and Issuance (FIPS 201-2 Section 2.8-2.9)
Once identity proofing clears:
- Generate and load cryptographic keys on the card (PIV Authentication, Digital Signature, Key Management, Card Authentication)
- Capture and encode biometric data onto the card
- Print visual credential elements (photo, name, agency, expiration)
- Activate the card with a PIN known only to the cardholder
Deliver the activated card directly to the cardholder, not through intermediaries.
Authentication Mechanisms (FIPS 201-2 Section 3)
FIPS 201-2 defines six authentication mechanisms with different assurance levels:
- PKI-CAK: PIV Authentication certificate with card activation
- PKI-AUTH: PIV Authentication certificate without card activation
- OCC-AUTH: On-Card Comparison using biometric match
- VIS: Visual inspection of printed credential
- BIO: Biometric match against off-card reference
- BIO-A: Attended biometric match
Your access control systems must support at least PKI-AUTH for logical access to federal systems. Physical access typically uses PKI-CAK or BIO.
Lifecycle Management (FIPS 201-2 Section 2.9)
You're responsible for:
- Reissuance: Every three years maximum, or when credentials are compromised
- Termination: Within 18 hours of separation or loss of eligibility
- Suspension: Immediate when a card is reported lost or stolen
- PIN reset: Self-service or help desk process that doesn't compromise authentication
Your CMS must log every lifecycle event with timestamps, operator IDs, and reason codes.
Implementation Guidance
Phase 1: Infrastructure Readiness
Before issuing your first PIV card, confirm:
- Your PKI infrastructure is cross-certified with the Federal Bridge CA or operates under the Federal Common Policy CA
- Card readers are deployed at workstations requiring logical access (contact and contactless interfaces)
- Physical access control systems support PIV authentication (check manufacturer compatibility lists)
- Your directory service (typically Active Directory) is configured with certificate mapping for PIV authentication
Phase 2: Enrollment Process Design
Map your enrollment workflow:
- Appointment scheduling (avoid walk-ins; you need time to verify documents)
- Document verification station (train staff on acceptable identity documents)
- Biometric capture station (fingerprint quality checks are critical)
- Background check integration (how does your HR system signal clearance?)
- Card personalization and activation (separate from enrollment for security)
Build waiting periods into your timeline. Background investigations can take weeks. Don't promise same-day issuance.
Phase 3: Integration Testing
Test authentication against:
- VPN gateways
- Email systems (S/MIME signing and encryption)
- Web applications (certificate-based authentication)
- Physical access panels
- Privileged access workstations
Create test accounts that mirror your actual user roles. PIV authentication often breaks due to certificate chain validation issues or incorrect certificate mappings in directories.
Phase 4: Rollout and Training
Train cardholders on:
- PIN management (it's NOT their network password)
- Physical security of the card (treat it like a building key)
- Reporting procedures for lost or stolen cards
- How to use the card for different authentication scenarios
Train help desk staff separately. They'll field PIN reset requests, card reader troubleshooting, and "my card doesn't work" calls that require methodical diagnosis.
Common Pitfalls
Certificate expiration mismatch: Your PIV certificates might expire before the three-year card validity period. Plan certificate renewal workflows that don't require card reissuance.
Biometric quality failures: Fingerprint scanners reject prints due to worn fingers, moisture, or technique. You need fallback processes and multiple capture attempts.
Contractor credential confusion: Contractors need PIV cards if they have long-term access (typically six months or more). Short-term contractors may use PIV-I or facility access badges, but these don't satisfy FIPS 201-2 for system access.
Offline authentication gaps: Some physical access scenarios require authentication when network connectivity is unavailable. Your readers must support card authentication certificates and cached authorization decisions.
PIN complexity theater: FIPS 201-2 requires a six to eight-digit PIN. Don't invent additional complexity rules (like requiring letters). The standard specifies numeric PINs.
Revocation checking failures: Your systems must check certificate revocation status (CRL or OCSP). Network issues that block revocation checks will lock out valid cardholders. Build fallback logic.
Quick Reference Table
| Requirement | Standard Section | Implementation Checkpoint |
|---|---|---|
| Identity proofing in-person | 2.1-2.7 | Two source documents + biometrics captured |
| Background investigation | 2.2 | HR system integration for clearance status |
| Biometric capture | 2.7 | Two fingerprints + facial image, quality checked |
| Card activation | 2.8 | PIN set by cardholder, not pre-assigned |
| PKI cross-certification | 3.1 | Federal Bridge CA or Common Policy CA |
| Certificate mapping | 3.1.2 | Directory configured with UPN or altSecurityIdentities |
| Physical access readers | 3.2.1 | Contact + contactless interfaces deployed |
| Termination timeline | 2.9.2 | Credentials revoked within 18 hours |
| Reissuance cycle | 2.9.1 | Maximum three years from issuance |
| Audit logging | 2.9.3 | All lifecycle events logged with operator ID |
Your PIV program isn't a one-time project. It's an identity infrastructure that requires ongoing maintenance, periodic audits, and updates as NIST revises the standard. Bookmark this guide, but also bookmark NIST's FIPS 201 page for errata and clarifications.





