What you need to know
A PIV card supports multiple authentication mechanisms with different assurance characteristics. Select the mechanism from risk rather than treating card presence as one uniform control.
Potentially affected
Federal facilities and other organizations using PIV credentials with physical access control systems or planning risk-based authentication upgrades.
DSE recommendation
Map doorway consequences and access populations to an approved PIV authentication mechanism, then verify the complete reader, controller, validation, and exception workflow.
Bottom line: reading something from a PIV card is not a single level of authentication. The selected mechanism, validation path, doorway consequence, and local exception handling determine the assurance the facility actually receives.
Source fact: NIST provides a risk-based PIV-to-PACS strategy
NIST SP 800-116 Rev. 1 provides guidelines for using PIV credentials in facility access and describes a risk-based strategy for selecting authentication mechanisms in physical access control systems. The publication addresses PIV use, PACS integration, and migration rather than treating every reader transaction as equivalent.
The central design decision is what must be proven at a particular boundary. The answer may differ for a public-to-controlled entrance, a high-consequence room, an after-hours condition, or a degraded network state.
Source boundary and applicability
SP 800-116 Rev. 1 is federal guidance and does not itself classify a specific facility, set every agency’s risk tolerance, certify products, or replace binding agency policy. FIPS 201, current agency requirements, credential issuer practices, procurement rules, and the exact PACS architecture must also be reviewed. Nonfederal adopters should state whether the guidance is mandatory or a design reference.
Applicability questions
- What is the consequence of an unauthorized entry at this boundary and time?
- Which approved PIV authentication mechanisms do the credential, reader, controller, and validation services support?
- Is freshness, cardholder verification, credential status, or online validation required?
- What happens during network, validation-service, controller, or reader failure?
- How are visitors, non-PIV users, emergency responders, and accessibility needs handled?
DSE recommendation: create a doorway assurance profile
The following steps are DSE recommendations based on the cited source.
For each controlled boundary, record facility zone, operating condition, threat and consequence, authorized population, required mechanism, validation dependencies, decision owner, and approved degraded mode. Design from the highest consequence that the boundary actually controls, while preserving emergency egress and accessibility under applicable requirements.
Test a valid card, expired or revoked credential where safely available, wrong cardholder action, failed PIN or biometric if used, unavailable validation service, controller offline state, and recovery. Confirm the event record says which mechanism completed rather than merely logging a card number. Govern any temporary downgrade with approval, expiration, compensating controls, and retrospective review.
Verification and evidence
Retain the risk assessment, doorway assurance matrix, agency policy references, approved product and configuration records, credential test cases, validation logs, offline-mode results, exception approvals, operator runbook, and acceptance signatures. Redact or protect credential identifiers in shared evidence.
Official references
- NIST SP 800-116 Rev. 1 – Guidelines for the Use of PIV Credentials in Facility Access – National Institute of Standards and Technology; finalized June 29, 2018
Review the official source
NIST SP 800-116 Rev. 1 - Guidelines for the Use of PIV Credentials in Facility Access · Published June 29, 2018
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE