{"id":13349,"date":"2018-09-05T16:42:23","date_gmt":"2018-09-05T20:42:23","guid":{"rendered":"https:\/\/fidodev.wpengine.com\/?page_id=13349"},"modified":"2025-11-12T16:04:17","modified_gmt":"2025-11-12T21:04:17","slug":"authenticator-level-3-plus","status":"publish","type":"page","link":"https:\/\/fidoalliance.org\/certification\/authenticator-certification-levels\/authenticator-level-3-plus\/","title":{"rendered":"Authenticator Level 3+"},"content":{"rendered":"<p>Authenticator Certification Level 3+ (L3+) evaluates FIDO Authenticator protection against moderate or high effort software and hardware attacks. The confidence in the Authenticator\u2019s security properties is high and the risk for having a successful attack is mitigated.<\/p>\n<p>At this level, an attacker should be hindered from performing successful attacks at the chip level (e.g. IC package opened\/decapsulated and attack equipment can act directly on the silicon chip) with high professional electronic lab equipment within weeks to months.<\/p>\n<p>For L3+, the Authenticator is required to conform to a solution included in FIDO Allowed Restricted Operating Environment and Allowed Cryptography lists as part of the Authenticator Security Requirements.<\/p>\n<p>Examples of implementations that will meet Level 3+ Security Requirements:<\/p>\n<ul>\n<li>An authenticator implemented on a Common Criteria Certified Secure Element or TPM<\/li>\n<\/ul>\n<p>If your implementation does not meet these requirements, please visit <a href=\"\/?page_id=6746\">Authenticator Level 2<\/a>.<\/p>\n<hr \/>\n<h2>Next Steps<\/h2>\n<p>Depending on your current implementation and the Level you wish to complete the process varies slightly. The scenarios below will help determine the next steps:<\/p>\n<h3>Client or Server Implementation<\/h3>\n<p>Certification levels are only for Authenticators; Clients and Servers can complete <a href=\"\/?page_id=250\">Functional Certification<\/a>.<\/p>\n<h3>New Authenticator Implementation<\/h3>\n<p>If you are completing FIDO Certification for the first time for this implementation, the first step for certification is to start with <a href=\"\/?page_id=250\">Functional Certification<\/a>.<\/p>\n<p>Functional Certification tests conformance to the specifications and Interoperability with FIDO Clients and Servers.<\/p>\n<p>No Security Requirements are tested during Interoperability Testing for L3+, but the <a href=\"\/?page_id=250\">Functional Certification<\/a> steps are still required.<\/p>\n<p>After Functional Certification, the implementation continues on to the process outlined in the Authenticator Certification Policy, and on the <a href=\"\/?page_id=6791\">Authenticator Certification Levels<\/a> page.<\/p>\n<p>It is required that the Level 3+ Vendor Questionnaire be evaluated by a FIDO Accredited Security Laboratory as part of the Security Evaluation step of Authenticator Certification. The Vendor is responsible for choosing and working with one of the <a href=\"\/?page_id=6740\">FIDO Accredited Security Laboratories<\/a> to complete the Security Evaluation.<\/p>\n<p>All L3+ implementers must create an account for FIDO Certification, you can <a href=\"\/?page_id=7161\">request an account<\/a>, or <a href=\"\/?page_id=7169\">login<\/a>.<\/p>\n<h3>Functionally Certified Authenticator Implementation<\/h3>\n<p>Functionally Certified Authenticators seeking L3+ Certification do not have added interoperability requirements as these were already met during the functional certification process. The next required step is to complete the Vendor Questionnaire &#8211; as is detailed in the Authenticator Certification Policy and on the <a href=\"\/?page_id=6791\">Authenticator Certification Levels<\/a> page.<\/p>\n<p>It is required that the Level 3+ Vendor Questionnaire be evaluated by a FIDO Accredited Security Laboratory as part of the Security Evaluation step of Authenticator Certification. The Vendor is responsible for choosing and working with one of the <a href=\"\/?page_id=6740\">FIDO Accredited Security Laboratories<\/a> to complete the Security Evaluation.<\/p>\n<h3>Biometric Certification and Authenticator Certification Relationship<\/h3>\n<p>Implementations completing Authenticator Certification Level 3 or above that use biometric authentication is required to complete the <a href=\"https:\/\/fidoalliance.org\/certification\/resource-documentation-biometric\/\">Biometrics Certification<\/a> prior to starting Authenticator Certification (including the Security Evaluation).<\/p>\n<p>All L3+ implementers must create an account for FIDO Certification, you can <a href=\"\/?page_id=7161\">request an account<\/a>, or <a href=\"\/?page_id=7169\">login<\/a>.<\/p>\n<hr \/>\n<h2>Certification Fees<\/h2>\n<p>Fees are per implementation certified and must be paid before a Certificate will be issued.<\/p>\n<p>For an overview of the different Certification options and fees, please review the <a href=\"\/?page_id=7104\">Authenticator Certification Scenarios<\/a> page.<\/p>\n<p>For an overview of certification fee pricing for this level and all others, please review the\u00a0<a href=\"https:\/\/fidoalliance.org\/certification\/user-authentication-certification-registration-fees\/\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/fidoalliance.org\/certification\/user-authentication-certification-registration-fees\/&amp;source=gmail&amp;ust=1717861281718000&amp;usg=AOvVaw3uiKEMN-H8iXIJOwgoQmIH\">User Authentication Certification Fees page<\/a>.<\/p>\n<h3>Laboratory Security Evaluation Fees<\/h3>\n<p>There is no FIDO Alliance Fee for a Laboratory Evaluation. The cost for the Security Evaluation will depend on the <a href=\"\/?page_id=6740\">Accredited Security Laboratory<\/a> used by the Vendor.<\/p>\n<hr \/>\n<h3>Implementer Dashboard<\/h3>\n<p>Implementers can <a href=\"\/?page_id=7169\">Login<\/a> to view their Dashboard.<\/p>\n<p><a class=\"home-btn-fix\" href=\"\/?page_id=7169\"><button class=\"btn\" type=\"button\">Login<\/button><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authenticator Certification Level 3+ (L3+) evaluates FIDO Authenticator protection against moderate or high effort software and hardware attacks. The confidence in the Authenticator\u2019s security properties is high and the risk [&hellip;]<\/p>\n","protected":false},"author":59250,"featured_media":0,"parent":6791,"menu_order":2,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"inline_featured_image":false,"_EventAllDay":false,"_EventTimezone":"","_EventStartDate":"","_EventEndDate":"","_EventStartDateUTC":"","_EventEndDateUTC":"","_EventShowMap":false,"_EventShowMapLink":false,"_EventURL":"","_EventCost":"","_EventCostDescription":"","_EventCurrencySymbol":"","_EventCurrencyCode":"","_EventCurrencyPosition":"","_EventDateTimeSeparator":"","_EventTimeRangeSeparator":"","_EventOrganizerID":[],"_EventVenueID":[],"_OrganizerEmail":"","_OrganizerPhone":"","_OrganizerWebsite":"","_VenueAddress":"","_VenueCity":"","_VenueCountry":"","_VenueProvince":"","_VenueState":"","_VenueZip":"","_VenuePhone":"","_VenueURL":"","_VenueStateProvince":"","_VenueLat":"","_VenueLng":"","_VenueShowMap":false,"_VenueShowMapLink":false,"footnotes":""},"content-type":[],"class_list":["post-13349","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/fidoalliance.org\/wp-json\/wp\/v2\/pages\/13349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fidoalliance.org\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/fidoalliance.org\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/fidoalliance.org\/wp-json\/wp\/v2\/users\/59250"}],"replies":[{"embeddable":true,"href":"https:\/\/fidoalliance.org\/wp-json\/wp\/v2\/comments?post=13349"}],"version-history":[{"count":0,"href":"https:\/\/fidoalliance.org\/wp-json\/wp\/v2\/pages\/13349\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/fidoalliance.org\/wp-json\/wp\/v2\/pages\/6791"}],"wp:attachment":[{"href":"https:\/\/fidoalliance.org\/wp-json\/wp\/v2\/media?parent=13349"}],"wp:term":[{"taxonomy":"content-type","embeddable":true,"href":"https:\/\/fidoalliance.org\/wp-json\/wp\/v2\/content-type?post=13349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}