ConceptioArchiveNIST
NISTpublic full text

NIST SP 1800-42 ipd: Digital Identities – Mobile Driver’s License (mDL): Accelerating Development and Adoption of Digital Identity for Financial Institutions

Yee-Yin Choong (NIST); William Fisher (NIST); Ryan Galluzzo (NIST); Jason Ajmo (MITRE); Christopher Brown (MITRE); Sudhi Umarji (MITRE); Ellen Nadeau (Coralline); Heather Flanagan (Spherical Cow Consulting) · National Institute of Standards and Technology (NIST)
NIST · Standards · License: Public Domain
Open Source ↗
cybersecuritypracticeimplementationguidenccoenist
cybersecurity practice, NCCoE, implementation guide, NIST

You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 1800-42 (Initial Public Draft) Digital Identities – Mobile Driver’s License (mDL): Accelerating Development and Adoption of Digital Identity for Financial Institutions Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: March 18, 2026 Comments Due: May 8, 2026 (public comment period is CLOSED) Email Questions to: [email protected] Author(s) Yee-Yin Choong (NIST) , William Fisher (NIST) , Ryan Galluzzo (NIST) , Jason Ajmo (MITRE) , Christopher Brown (MITRE) , Sudhi Umarji (MITRE) , Ellen Nadeau (Coralline) , Heather Flanagan (Spherical Cow Consulting) Announcement Today, the NCCoE published technical resources to help financial institutions use mobile driver’s licenses (mDLs) for customer identification. NIST Special Publication 1800-42 ipd provides an updated reference architecture, implementation details, and key findings from the project. Compared to physical driver’s licenses, mobile driver’s licenses (mDLs) are easier to use for digital transactions and offer improved protections against fraud, identity theft, and unauthorized access. The NCCoE’s technology demonstration is tackling the security, privacy, and interoperability issues with mDLs. This publication reflects insights from industry collaborators and lessons learned by developing a functional online demonstration using mDLs for customer identification. The publication provides a practical roadmap to enable adoption and implementation of mDLs for online financial management. Feedback You can improve this guide by contributing feedback. As an initial public draft, this document intends to gain critical feedback from stakeholders across government and industry on the implementation of mDL to support Customer Identification Programs and high assurance use cases more broadly. Comments are welcome on all aspects of this document and specifically encouraged on the following areas: Implementation and Adoption Challenges. This document highlights challenges to the adoption of mDL technology learned through engagement with collaborators and stakeholders spanning technology providers, financial institutions, standards bodies and government agencies. However, additional insights on barriers to adoption can help focus the project and future phases of work and NIST’s engagement with standards development organizations. Regulatory and Compliance Alignment. This document offers insights into the ways in which mDL online presentation aligns with existing regulatory structures. Additional insights on other regulatory mappings, views on the degree to which alignment is achieved, and suggested clarifications are encouraged. Technology Transfer and Resources. This document as well as supporting resources are intended to aid in implementation of the technology in real world environments. The project team is highly interested in additional resources and tools which may further aid in both technical implementation and broader adoption of the technology. Threats and Threat Model. The threat model proposed here is intended to act as a starting point for members of the ecosystem to identify and prepare for how attacks may shift in an mDL environment. Input on approach, specific threats, and mitigations will be highly valuable in maturing this view and providing greater visibility into future risks. Abstract Mobile Driver’s Licenses, and Verifiable Digital Credentials more broadly, represent an emerging technology with the capability to enhance the methods we use to prove identity both in-person and online. Many sectors stand to benefit from this emerging technology, including financial institutions seeking to enhance the security, privacy, usability, and reliability of online identity services. This practice guide captures insights generated through engagement with a robust cohort of industry collaborators and the lessons learned by developing a functional online mDL demonstration to provide a practical roadmap to enable adoption and implementation of mDLs for online financial account management. Mobile Driver’s Licenses, and Verifiable Digital Credentials more broadly, represent an emerging technology with the capability to enhance the methods we use to prove identity both in-person and online. Many sectors stand to benefit from this emerging technology, including financial institutions... See full abstract Mobile Driver’s Licenses, and Verifiable Digital Credentials more broadly, represent an emerging technology with the capability to enhance the methods we use to prove identity both in-person and online. Many sectors stand to benefit from this emerging technology, including financial institutions seeking to enhance the security, privacy, usability, and reliability of online identity services. This practice guide captures insights generated through engagement with a robust cohort of industry collaborators and the lessons learned by developing a functional online mDL demonstration to provide a practical roadmap to enable adoption and implementation of mDLs for online financial account management. Hide full abstract Keywords authentication ; credentials ; identity ; mobile driver’s license (mDL) ; verifiable digital credentials Control Families Access Control ; Audit and Accountability ; Assessment, Authorization and Monitoring ; Identification and Authentication Documentation Publication: SP 1800-42A ipd (pdf) Supplemental Material: Project homepage mDL Project: Supporting Resources mDL Community of Interest Related NIST Publications: Project Description Document History: 03/18/26: SP 1800-42 (Draft) Topics Security and Privacy access authorization , authentication , public key infrastructure , security controls , threats Technologies biometrics , mobile HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov

Related documents

Record · ID 2849 · SHA-256 a2ca01276224382b
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.