What is Identity Proofing?
Identity proofing is the organizational process of confirming that individuals are who they claim to be before granting them access to systems or sensitive data. At institutions, this process occurs in onboarding, credential issuance, account recovery, and is critical for the daily access of secure systems and federated identity.
By strengthening the security of institutional credentials, identity proofing reduces fraud, protects sensitive information, and supports secure access to research and educational services.
The rigor of your identity proofing processes determines the level of identity assurance, or how confidently your institution — and external partners — can trust that the person accessing a system is who they claim to be.
Why Now?
Identity proofing sits at the foundation for protecting research access, issuing trusted credentials, and reducing overall institutional risk.
A federal deadline is ahead
Service desks are frequent targets
Ghost students and false enrollment are rising
Student onboarding sets the foundation
Institutional risk is real
How Can I Start Today?
The NIH now requires institutions accessing CADRs to verify researcher identities at higher assurance levels by January 2027.
The deadline is approaching, but here are six simple ways your institution can begin today:
1. Determine if your institution has NIH CADR users. Identify researchers on your campus and find the answers to the following questions to determine where compliance is needed:
- Does the researcher access NIH CADRs?
- In which office does this person work?
2. Hear from the NIH itself. In case you missed it, check out the recording of our previous IAM Online webinar, where you’ll hear from the NIH about what’s expected as we approach the 2027 deadline.
3. Review “Identity Proofing Best Practices.” Get a head start on identity proofing by understanding best practices and the identity proofing framework to evaluate your current proofing practice, prioritize next steps, and build an actual plan.
4. Complete a preassessment. Capture what you already do today (onboarding, ID cards, account recovery, etc.) before making any changes.
5. Start small. Choose a single area: research access, service desk recovery, or student enrollment. Pilot the use-case for learning before scaling.
6. Plug into community support to avoid mistakes and increase success.
-
- Join InCommon’s Community Identity Proofing email discussion list.
- Send a message to sympa@internet2.edu
-
In the subject line of your message, type in: subscribe IDProofing@Internet2.edu
-
Leave the message body blank and hit send
-
Get priority access for the next Identity Proofing Accelerator
-
Attend workshops focusing on identity proofing at the Internet2 Technology Exchange
-
Connect with an InCommon Catalyst to accelerate planning and avoid reinventing the wheel
- Join InCommon’s Community Identity Proofing email discussion list.
InCommon Is Elevating Identity Proofing Awareness
Internet2 is supporting the research and education IAM and security community through a service evaluation to determine which identity proofing solution to add to the NET+ Program. Join peer institutions in evaluating the selected service. Test real use cases and help shape the service’s rollout for higher education and research institutions.
Interested? Contact Sue Gavazzi at sgavazzi@internet2.edu.
Be the First to Gain Access to our Next Accelerator
Work toward identity assurance and NIH compliance by expressing interest in the fall cohort and staying up to date.
Take A Deeper Dive into NIH Readiness
Participant in the federation? Find more support in Identity Assurance to help your researchers meet the NIH deadline.
Register for Our Technology Exchange Identity Proofing Workshop
Define your identity-proofing pitfalls, identify the stakeholders that should be involved, and develop a realistic plan to move forward at the 2026 Internet2 Technology Exchange, where we bridge strategic and operational perspectives across R&E.
Learn How Many Organizations Are Keeping Up With the Latest Identity Verification Standards Without Getting Overwhelmed
Making it Easier for Researchers: NIH’s use of InCommon for Controlled-Access Data
Hear Directly from the NIH about Identity Proofing and Their New Requirements
Beyond Authentication: When Secure Access Demands Identity Assurance
