{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/select-piv-door-authentication-from-consequence-and-assurance/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/",
        "slug": "select-piv-door-authentication-from-consequence-and-assurance",
        "url": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/select-piv-door-authentication-from-consequence-and-assurance/"
        },
        "title": "Select PIV door authentication from consequence and assurance",
        "summary": "A PIV card supports multiple authentication mechanisms with different assurance characteristics. Select the mechanism from risk rather than treating card presence as one uniform control.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:35:53+00:00",
        "modified_at": "2026-08-25T21:36:17+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 2,
        "word_count": 419,
        "potentially_affected": "Federal facilities and other organizations using PIV credentials with physical access control systems or planning risk-based authentication upgrades.",
        "dse_recommendation": "Map doorway consequences and access populations to an approved PIV authentication mechanism, then verify the complete reader, controller, validation, and exception workflow.",
        "primary_source": {
            "name": "NIST SP 800-116 Rev. 1 - Guidelines for the Use of PIV Credentials in Facility Access",
            "url": "https://csrc.nist.gov/pubs/sp/800/116/r1/final",
            "published_on": "2018-06-29",
            "authority": "National Institute of Standards and Technology"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> reading something from a PIV card is not a single level of authentication. The selected mechanism, validation path, doorway consequence, and local exception handling determine the assurance the facility actually receives.</p>\n<h2>Source fact: NIST provides a risk-based PIV-to-PACS strategy</h2>\n<p><a href=\"https://csrc.nist.gov/pubs/sp/800/116/r1/final\" target=\"_blank\" rel=\"noopener noreferrer\">NIST SP 800-116 Rev. 1</a> provides guidelines for using PIV credentials in facility access and describes a risk-based strategy for selecting authentication mechanisms in physical access control systems. The publication addresses PIV use, PACS integration, and migration rather than treating every reader transaction as equivalent.</p>\n<p>The central design decision is what must be proven at a particular boundary. The answer may differ for a public-to-controlled entrance, a high-consequence room, an after-hours condition, or a degraded network state.</p>\n<h2>Source boundary and applicability</h2>\n<p>SP 800-116 Rev. 1 is federal guidance and does not itself classify a specific facility, set every agency&#8217;s risk tolerance, certify products, or replace binding agency policy. FIPS 201, current agency requirements, credential issuer practices, procurement rules, and the exact PACS architecture must also be reviewed. Nonfederal adopters should state whether the guidance is mandatory or a design reference.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>What is the consequence of an unauthorized entry at this boundary and time?</li>\n<li>Which approved PIV authentication mechanisms do the credential, reader, controller, and validation services support?</li>\n<li>Is freshness, cardholder verification, credential status, or online validation required?</li>\n<li>What happens during network, validation-service, controller, or reader failure?</li>\n<li>How are visitors, non-PIV users, emergency responders, and accessibility needs handled?</li>\n</ul>\n<h2>DSE recommendation: create a doorway assurance profile</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<p>For each controlled boundary, record facility zone, operating condition, threat and consequence, authorized population, required mechanism, validation dependencies, decision owner, and approved degraded mode. Design from the highest consequence that the boundary actually controls, while preserving emergency egress and accessibility under applicable requirements.</p>\n<p>Test a valid card, expired or revoked credential where safely available, wrong cardholder action, failed PIN or biometric if used, unavailable validation service, controller offline state, and recovery. Confirm the event record says which mechanism completed rather than merely logging a card number. Govern any temporary downgrade with approval, expiration, compensating controls, and retrospective review.</p>\n<h2>Verification and evidence</h2>\n<p>Retain the risk assessment, doorway assurance matrix, agency policy references, approved product and configuration records, credential test cases, validation logs, offline-mode results, exception approvals, operator runbook, and acceptance signatures. Redact or protect credential identifiers in shared evidence.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://csrc.nist.gov/pubs/sp/800/116/r1/final\" target=\"_blank\" rel=\"noopener noreferrer\">NIST SP 800-116 Rev. 1 &#8211; Guidelines for the Use of PIV Credentials in Facility Access</a> &#8211; National Institute of Standards and Technology; finalized June 29, 2018</li>\n</ul>",
        "content_text": "Bottom line: reading something from a PIV card is not a single level of authentication. The selected mechanism, validation path, doorway consequence, and local exception handling determine the assurance the facility actually receives.\nSource fact: NIST provides a risk-based PIV-to-PACS strategy\nNIST SP 800-116 Rev. 1 provides guidelines for using PIV credentials in facility access and describes a risk-based strategy for selecting authentication mechanisms in physical access control systems. The publication addresses PIV use, PACS integration, and migration rather than treating every reader transaction as equivalent.\nThe central design decision is what must be proven at a particular boundary. The answer may differ for a public-to-controlled entrance, a high-consequence room, an after-hours condition, or a degraded network state.\nSource boundary and applicability\nSP 800-116 Rev. 1 is federal guidance and does not itself classify a specific facility, set every agency’s risk tolerance, certify products, or replace binding agency policy. FIPS 201, current agency requirements, credential issuer practices, procurement rules, and the exact PACS architecture must also be reviewed. Nonfederal adopters should state whether the guidance is mandatory or a design reference.\nApplicability questions\n\nWhat is the consequence of an unauthorized entry at this boundary and time?\nWhich approved PIV authentication mechanisms do the credential, reader, controller, and validation services support?\nIs freshness, cardholder verification, credential status, or online validation required?\nWhat happens during network, validation-service, controller, or reader failure?\nHow are visitors, non-PIV users, emergency responders, and accessibility needs handled?\n\nDSE recommendation: create a doorway assurance profile\nThe following steps are DSE recommendations based on the cited source.\nFor each controlled boundary, record facility zone, operating condition, threat and consequence, authorized population, required mechanism, validation dependencies, decision owner, and approved degraded mode. Design from the highest consequence that the boundary actually controls, while preserving emergency egress and accessibility under applicable requirements.\nTest a valid card, expired or revoked credential where safely available, wrong cardholder action, failed PIN or biometric if used, unavailable validation service, controller offline state, and recovery. Confirm the event record says which mechanism completed rather than merely logging a card number. Govern any temporary downgrade with approval, expiration, compensating controls, and retrospective review.\nVerification and evidence\nRetain the risk assessment, doorway assurance matrix, agency policy references, approved product and configuration records, credential test cases, validation logs, offline-mode results, exception approvals, operator runbook, and acceptance signatures. Redact or protect credential identifiers in shared evidence.\nOfficial references\n\nNIST SP 800-116 Rev. 1 – Guidelines for the Use of PIV Credentials in Facility Access – National Institute of Standards and Technology; finalized June 29, 2018",
        "content_markdown": "Bottom line: reading something from a PIV card is not a single level of authentication. The selected mechanism, validation path, doorway consequence, and local exception handling determine the assurance the facility actually receives.\n\n## Source fact: NIST provides a risk-based PIV-to-PACS strategy\n\n[NIST SP 800-116 Rev. 1](https://csrc.nist.gov/pubs/sp/800/116/r1/final) provides guidelines for using PIV credentials in facility access and describes a risk-based strategy for selecting authentication mechanisms in physical access control systems. The publication addresses PIV use, PACS integration, and migration rather than treating every reader transaction as equivalent.\n\nThe central design decision is what must be proven at a particular boundary. The answer may differ for a public-to-controlled entrance, a high-consequence room, an after-hours condition, or a degraded network state.\n\n## Source boundary and applicability\n\nSP 800-116 Rev. 1 is federal guidance and does not itself classify a specific facility, set every agency’s risk tolerance, certify products, or replace binding agency policy. FIPS 201, current agency requirements, credential issuer practices, procurement rules, and the exact PACS architecture must also be reviewed. Nonfederal adopters should state whether the guidance is mandatory or a design reference.\n\n## Applicability questions\n\n- What is the consequence of an unauthorized entry at this boundary and time?\n\n- Which approved PIV authentication mechanisms do the credential, reader, controller, and validation services support?\n\n- Is freshness, cardholder verification, credential status, or online validation required?\n\n- What happens during network, validation-service, controller, or reader failure?\n\n- How are visitors, non-PIV users, emergency responders, and accessibility needs handled?\n\n## DSE recommendation: create a doorway assurance profile\n\nThe following steps are DSE recommendations based on the cited source.\n\nFor each controlled boundary, record facility zone, operating condition, threat and consequence, authorized population, required mechanism, validation dependencies, decision owner, and approved degraded mode. Design from the highest consequence that the boundary actually controls, while preserving emergency egress and accessibility under applicable requirements.\n\nTest a valid card, expired or revoked credential where safely available, wrong cardholder action, failed PIN or biometric if used, unavailable validation service, controller offline state, and recovery. Confirm the event record says which mechanism completed rather than merely logging a card number. Govern any temporary downgrade with approval, expiration, compensating controls, and retrospective review.\n\n## Verification and evidence\n\nRetain the risk assessment, doorway assurance matrix, agency policy references, approved product and configuration records, credential test cases, validation logs, offline-mode results, exception approvals, operator runbook, and acceptance signatures. Redact or protect credential identifiers in shared evidence.\n\n## Official references\n\n- [NIST SP 800-116 Rev. 1 – Guidelines for the Use of PIV Credentials in Facility Access](https://csrc.nist.gov/pubs/sp/800/116/r1/final) – National Institute of Standards and Technology; finalized June 29, 2018"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/",
                "url": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Select PIV door authentication from consequence and assurance",
                        "item": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/#article",
                "identifier": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/",
                "url": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/",
                "headline": "Select PIV door authentication from consequence and assurance",
                "description": "A PIV card supports multiple authentication mechanisms with different assurance characteristics. Select the mechanism from risk rather than treating…",
                "abstract": "A PIV card supports multiple authentication mechanisms with different assurance characteristics. Select the mechanism from risk rather than treating card presence as one uniform control.",
                "articleBody": "Bottom line: reading something from a PIV card is not a single level of authentication. The selected mechanism, validation path, doorway consequence, and local exception handling determine the assurance the facility actually receives.\nSource fact: NIST provides a risk-based PIV-to-PACS strategy\nNIST SP 800-116 Rev. 1 provides guidelines for using PIV credentials in facility access and describes a risk-based strategy for selecting authentication mechanisms in physical access control systems. The publication addresses PIV use, PACS integration, and migration rather than treating every reader transaction as equivalent.\nThe central design decision is what must be proven at a particular boundary. The answer may differ for a public-to-controlled entrance, a high-consequence room, an after-hours condition, or a degraded network state.\nSource boundary and applicability\nSP 800-116 Rev. 1 is federal guidance and does not itself classify a specific facility, set every agency’s risk tolerance, certify products, or replace binding agency policy. FIPS 201, current agency requirements, credential issuer practices, procurement rules, and the exact PACS architecture must also be reviewed. Nonfederal adopters should state whether the guidance is mandatory or a design reference.\nApplicability questions\n\nWhat is the consequence of an unauthorized entry at this boundary and time?\nWhich approved PIV authentication mechanisms do the credential, reader, controller, and validation services support?\nIs freshness, cardholder verification, credential status, or online validation required?\nWhat happens during network, validation-service, controller, or reader failure?\nHow are visitors, non-PIV users, emergency responders, and accessibility needs handled?\n\nDSE recommendation: create a doorway assurance profile\nThe following steps are DSE recommendations based on the cited source.\nFor each controlled boundary, record facility zone, operating condition, threat and consequence, authorized population, required mechanism, validation dependencies, decision owner, and approved degraded mode. Design from the highest consequence that the boundary actually controls, while preserving emergency egress and accessibility under applicable requirements.\nTest a valid card, expired or revoked credential where safely available, wrong cardholder action, failed PIN or biometric if used, unavailable validation service, controller offline state, and recovery. Confirm the event record says which mechanism completed rather than merely logging a card number. Govern any temporary downgrade with approval, expiration, compensating controls, and retrospective review.\nVerification and evidence\nRetain the risk assessment, doorway assurance matrix, agency policy references, approved product and configuration records, credential test cases, validation logs, offline-mode results, exception approvals, operator runbook, and acceptance signatures. Redact or protect credential identifiers in shared evidence.\nOfficial references\n\nNIST SP 800-116 Rev. 1 – Guidelines for the Use of PIV Credentials in Facility Access – National Institute of Standards and Technology; finalized June 29, 2018",
                "datePublished": "2026-08-25T21:35:53+00:00",
                "dateModified": "2026-08-25T21:36:17+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/select-piv-door-authentication-from-consequence-and-assurance/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Select PIV door authentication from consequence and assurance"
                },
                "articleSection": [
                    "Access Control",
                    "Cybersecurity"
                ],
                "keywords": [
                    "Access Control",
                    "Cybersecurity",
                    "Guide",
                    "Important priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    }
                ],
                "wordCount": 419,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "NIST SP 800-116 Rev. 1 - Guidelines for the Use of PIV Credentials in Facility Access",
                    "url": "https://csrc.nist.gov/pubs/sp/800/116/r1/final",
                    "datePublished": "2018-06-29"
                }
            }
        ]
    }
}