US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.9
Identity Proofing
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Key Requirements
Identity proofing establishes that a user (both organization and non-organizational) is
who the user claims to be. Identity proofing is the process of collecting, validating, and
verifying user’s identity information for the purposes of issuing credentials for accessing
a system.
Assuring appropriate identity evidence, such as documentary evidence or a combination
of documents and biometrics, reduces the likelihood of individuals using fraudulent
identification to establish an identity, or at least increases the work factor of potential
adversaries.
Care should be taken to ensure that only the absolute necessary information be obtained
in order to keep the amount of PII that is collected to a minimum.
Business partners shall assure that users are effectively identity proofed in accordance with ARS
control requirements. To assure that users are properly identified and validated, it is imperative that
business partners apply consistent identity proofing concepts.
To properly identity proof users, business partners shall implement a process that meets the
requirements identified within NIST 800-63A and meets or exceeds standards for IAL2.
It is not a requirement that identity proofing be done in person.
Exceptions and situations that require further clarification should be discussed with CMS before
implementation.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
214252bb6c72cf6c5a6849f4e262ace58abee62acb5b28600bbe4ccc862c32c0
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.