U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

SP 1800-17

Multifactor Authentication for E-Commerce: Risk-Based, FIDO Universal Second Factor Implementations for Purchasers

Date Published: July 2019


William Newhouse (NIST), Brian Johnson (MITRE), Sarah Kinling (MITRE), Jason Kuruvilla (MITRE), Blaine Mulugeta (MITRE), Kenneth Sandlin (MITRE)



electronic commerce (e-commerce) security; internet shopping security; multifactor authentication (MFA)
Control Families

None selected


SP 1800-17 (DOI)
Local Download

Supplemental Material:
SP 1800-17 files (web)
Project homepage (web)

Related NIST Publications:
White Paper

Document History:
08/22/18: SP 1800-17 (Draft)
07/30/19: SP 1800-17 (Final)