Minimum Standards for Driver's Licenses and Identification Cards Acceptable by Federal Agencies for Official Purposes; Waiver for Mobile Driver's Licenses
Federal RegisterOct 25, 2024
Ask Donna
What actually matters in this document.
Text
DEPARTMENT OF HOMELAND SECURITY
6 CFR Part 37
[Docket No. TSA-2023-0002]
RIN 1652-AA76
Minimum Standards for Driver's Licenses and Identification Cards Acceptable by Federal Agencies for Official Purposes; Waiver for Mobile Driver's Licenses
AGENCY:
Transportation Security Administration (TSA), Department of Homeland Security (DHS).
ACTION:
Final rule.
SUMMARY:
The Department of Homeland Security (DHS) is amending the REAL ID regulations to waive, on a temporary and State-by-State basis, the regulatory requirement that mobile or digital driver's licenses or identification cards (collectively “mobile driver's licenses” or “mDLs”) must be compliant with REAL ID requirements to be accepted by Federal agencies for official purposes, as defined by the REAL ID Act, when full enforcement of the REAL ID Act and regulations begins on May 7, 2025.
DATES:
Effective date:
This rule is effective November 25, 2024.
Incorporation by Reference:
The incorporation by reference of certain material listed in the rule is approved by the Director of the Federal Register as of November 25, 2024. The incorporation by reference of certain other material listed in the rule was approved by the Director of the Federal Register as of January 14, 2016.
FOR FURTHER INFORMATION CONTACT:
Technical questions:
George Petersen, Senior Program Manager, REAL ID Program, Enrollment Services and Vetting Programs, Transportation Security Administration; telephone: (571) 227-2215; email:
george.petersen@tsa.dhs.gov.
Legal questions:
Anurag Maheshwary, Attorney Advisor, Office of Chief Counsel, Transportation Security Administration; telephone: (571) 227-4812; email:
anurag.maheshwary@tsa.dhs.gov.
SUPPLEMENTARY INFORMATION:
Availability of Rulemaking Document
You can find an electronic copy of this rulemaking using the internet by accessing the Government Publishing Office's web page at
https://www.govinfo.gov/app/collection/FR/
to view the daily published
Federal Register
edition or accessing the Office of the Federal Register's web page at
https://www.federalregister.gov.
Copies are also available by contacting the individual identified for “Technical Questions” in the
FOR FURTHER INFORMATION CONTACT
section. Make sure to identify the docket number of this rulemaking.
Abbreviations and Terms Used in This Document
AAMVA—American Association of Motor Vehicle Administrators
CA/Browser Forum—Certification Authority Browser Forum
CISA—Cybersecurity and Infrastructure Security Agency
DHS—U.S. Department of Homeland Security
EDL—Enhanced driver's license and identification card
FIPS—Federal Information Processing Standards
HSM—Hardware security module
IBR—Incorporation by reference or Incorporate by reference
IEC—International Electrotechnical Commission
ISO—International Organization for Standardization
IT—Information technology
mDL—Mobile driver's license and mobile identification card
NIST—National Institute for Standards and Technology
NPRM—Notice of proposed rulemaking
OFR—Office of Federal Register
OMB—Office of Management and Budget
PUB—Publication
RFI—Request for information
SP—Special publication
TSA—Transportation Security Administration
Table of Contents
I. Executive Summary
A. Purpose of this Rulemaking
B. Summary of the Major Provisions
C. Need for a Multi-Phased Rulemaking
D. Costs and Benefits
II. Background
A. REAL ID Act, Regulations, and Applicability to mDLs
B. Rulemaking History
C. mDL Overview
D. Industry Standards and Government Guidelines for mDLs
III. General Discussion of the Rulemaking
A. Changes Between NPRM and Final Rule
B. Summary of Regulatory Provisions
C. Specific Provisions
D. Impacted Stakeholders
E. Use Cases Affected by This Rule
F. Severability
IV. Discussion of Comments
A. Waiver Eligibility
B. Conditions on Federal Agencies Accepting mDLs
C. Waiver Application Criteria
D. TSA Waiver Application Guidance
E. General Concerns About mDLs
F. Scope of Rulemaking and mDL Acceptance
G. Privacy
H. Waiver Validity Period and Renewals
I. Vendor and Technology “Lock-in” Effects
J. Pseudonymous Validation and On-Device Biometric Matching
K. Access to Standards
L. Standards and Standards Development Generally
M. TSA's Identity Verification Policies
N. Paperwork Reduction Act
O. Legal Authority
P. Economic Impact Analysis
Q. Communicating Status of Waiver; System Disruptions
R. Impact of Waiver on States Currently Testing mDLs With TSA
S. Notice for Changes to State mDL Issuance Processes
T. Clarification Regarding “Days”
U. Audit Requirements
V. Appendix A to Subpart A: mDL Issuance Requirements
W. Protection of Sensitive Security Information in Waiver Applications
V. Consultation With States and the Department of Transportation
VI. Regulatory Analyses
A. Economic Impact Analyses
B. Paperwork Reduction Act
C. Federalism (E.O. 13132)
D. Customer Service (E.O. 14058)
E. Energy Impact Analysis (E.O. 13211)
F. Environmental Analysis
I. Executive Summary
A. Purpose of This Rulemaking
This rule is part of an incremental, multi-phased rulemaking that will culminate in the promulgation of comprehensive requirements that enable States to issue mobile driver's licenses and mobile identification cards (collectively “mDLs”) that comply with the REAL ID Act of 2005 (“REAL ID Act” or “Act”) and regulations
1
[hereinafter “REAL ID-Compliant”]. In this first phase, the Transportation Security Administration (TSA) is making two changes to the current regulations in 6 CFR part 37, “REAL ID Driver's Licenses and Identification Cards.” First, TSA is adding definitions for, among others, mobile driver's licenses and mobile identification cards. These definitions provide a precise explanation of those terms as referenced in the REAL ID Act, which applies to only State-issued driver's licenses and State-issued identification cards.
2
Any other types of identification cards, such
as those issued by a Federal agency, or commercial, educational, or non-profit entity, are beyond the scope of the REAL ID Act and regulations, and hence this rulemaking, because they do not meet the definition of driver's license or identification card as defined by the REAL ID Act. The definition of “mDL” as used in this rulemaking is limited strictly to the REAL ID Act and regulations and does not include “mDLs” as defined by other entities.
1
The REAL ID Act of 2005, Division B Title II of the FY05 Emergency Supplemental Appropriations Act, as amended, Public Law 109-13, 119 Stat. 302 (May 11, 2005) (codified at 49 U.S.C. 30301 note) [hereinafter “REAL ID Act”]; 6 CFR part 37. Effective May 22, 2023, authority to administer the REAL ID program was delegated from the Secretary of Homeland Security to the Administrator of TSA pursuant to DHS Delegation No. 7060.2.1.
2
See
sec. 201 of the REAL ID Act (defining a “driver's license” to include “driver's licenses stored or accessed via electronic means, such as mobile or digital driver's licenses, which have been issued in accordance with regulations prescribed by the Secretary”; mirroring definition for “identification card”).
Second, TSA is establishing a temporary waiver process that permits Federal agencies to accept mDLs for official purposes,
3
as defined in the REAL ID Act and regulations, on an interim basis when full enforcement begins on May 7, 2025,
4
but only if TSA has issued a waiver to the State. To qualify for the waiver, this final rule requires States to (1) be in full compliance with all applicable REAL ID requirements as defined in subpart E of this part, and (2) submit an application demonstrating that they meet the requirements specified in this rule, which are drawn from 19 industry standards and government guidelines. The rulemaking incorporates by reference (IBRs) those standards and guidelines, which cover technical areas such as mDL communication, digital identity, encryption, cybersecurity, and network/information system security and privacy.
3
The REAL ID Act defines official purposes as including but not limited to accessing Federal facilities, boarding Federally regulated commercial aircraft, entering nuclear power plants, and any other purposes that the Secretary shall determine.
See
REAL ID Act. Notably, because the Secretary has not determined any other official purposes, the REAL ID Act and regulations do not apply to Federal acceptance of driver's licenses and identification cards for other purposes, such as applying for Federal benefits programs, submitting immigration documents, or other Federal programs.
4
DHS, Final Rule, Minimum Standards for Driver's Licenses and Identification Cards Acceptable by Federal Agencies for Official Purposes, 88 FR 14473 (Mar. 9, 2023); DHS Press Release, DHS Announces Extension of REAL ID Full Enforcement Deadline (Dec. 5, 2022),
https://www.dhs.gov/news/2022/12/05/dhs-announces-extension-real-id-full-enforcement-deadline
(last visited July 17, 2024).
As noted above, this final rule is part of an incremental rulemaking that temporarily permits Federal agencies to accept mDLs for official purposes until TSA issues a subsequent rule that would set comprehensive requirements for mDLs. TSA believes it is premature to issue such requirements before the May 7, 2025 deadline due to the need for emerging industry standards and government guidelines
5
to be finalized.
5
See
TSA, Notice of Proposed Rulemaking, Waiver for Mobile Driver's Licenses, 88 FR 60056, 60063-64 (Aug. 30, 2023) [hereinafter “NPRM”].
The need for this rulemaking arises from TSA's desire to accommodate and foster the rapid pace of mDL innovation, while ensuring the intent of the REAL ID Act and regulations are met. Secure driver's licenses and identification cards are a vital component of our national security framework. In the REAL ID Act, Congress acted to implement the 9/11 Commission's recommendation that the Federal Government “set standards for the issuance of sources of identification, such as driver's licenses.” Under the REAL ID Act and regulations, a Federal agency may not accept for any official purpose a State-issued driver's license or identification card, either physical or an mDL, that does not meet specified requirements, as detailed in the REAL ID regulations (
see
Part II.A., below, for more discussion on these requirements).
This final rule will result in the development of mDLs with a higher level of security, privacy, and interoperability features necessary for Federal acceptance for official purposes. Because the current regulatory provisions do not include requirements that would enable States to issue REAL ID-compliant mDLs, several States are investing significant resources to develop mDLs based on varying and often proprietary standards, many of which may lack security and privacy safeguards commensurate with REAL ID requirements and the privacy needs of users. Without timely regulatory guidance concerning potential requirements for developing a REAL ID-compliant mDL, States risk investing in mDLs that are not aligned with emerging industry standards and government guidelines that may be IBR'd in a future rulemaking. States, therefore, may become locked-in to existing solutions and could face a substantial burden to redevelop products acceptable to Federal agencies under this future rulemaking.
This final rule addresses these concerns by enabling TSA to grant a temporary waiver to States whose mDLs TSA determines provide sufficient safeguards for security and privacy, pending finalization of emerging standards. Although this rule does not set standards for the issuance of REAL ID-compliant mDLs, it does establish minimum requirements that States must meet to be granted a waiver so that mDLs can be accepted by Federal agencies for official purposes. These minimum standards and requirements ensure that States' investments in mDLs provide minimum privacy and security safeguards consistent with information currently known to the TSA.
B. Summary of the Major Provisions
As further discussed in Part II.A., below, mDLs cannot be accepted by Federal agencies for official purposes when REAL ID full enforcement begins on May 7, 2025, unless 6 CFR part 37 is amended to address mDLs. This final rule establishes a process for waiving, on a temporary and State-by-State basis, the current prohibition on Federal acceptance of mDLs for official purposes, and enables Federal agencies to accept mDLs on an interim basis while the industry matures to a point sufficient to enable TSA to develop more comprehensive mDL regulatory requirements.
The current regulations prohibit Federal agencies from accepting non-compliant driver's licenses and identification cards, including both physical cards and mDLs, when REAL ID enforcement begins on May 7, 2025. Any modification of this regulatory provision must occur through rulemaking (or legislation). Until and unless TSA promulgates comprehensive mDL regulations that enable States to issue REAL ID-compliant mDLs, mDLs cannot be developed to comply with REAL ID, and Federal agencies therefore cannot accept mDLs for official purposes after REAL ID enforcement begins on May 7, 2025. The rule allows the Federal government to accept mDLs on an interim basis, but only if TSA has issued a waiver to such State based on that State's compliance with all applicable REAL ID requirements as defined in subpart E of this part, and with the minimum privacy, safety, and interoperability requirements in this rulemaking. Please see Part II.A., below, for an explanation of the REAL ID requirement that both cards and issuing States must be REAL ID compliant.
C. Need for a Multi-Phased Rulemaking
TSA recognizes both that regulations can influence long-term industry research and investment decisions, and that premature regulations can distort the choices of technologies, which could harm competition and innovation. As noted above, there are clear reasons for TSA to issue requirements for mDLs in the context of REAL ID. Simultaneously, however, TSA observes that this is a rapidly innovating market, with multiple industry and government standards and guidelines necessary to ensure mDL privacy and security still in development.
6
Accordingly, TSA has concluded that it is premature to promulgate comprehensive requirements for mDLs while key
standards are being finalized because of the risk of unintended consequences, such as chilling innovation and competition in the marketplace, and “locking-in” stakeholders to certain technologies. TSA is therefore establishing a temporary waiver process with clear standards and requirements to facilitate the acceptance of mDLs while the industry matures and moves to accepted standards.
6
See
NPRM, 88 FR at 60062-66.
TSA is proceeding with a multi-phased rulemaking approach. This “Phase 1” rule establishes a temporary waiver process that enables continuing Federal acceptance of mDLs for official purposes when REAL ID enforcement begins on May 7, 2025, and affords Federal agencies additional operational experience and data that would inform comprehensive regulations in the upcoming “Phase 2” rulemaking. The Phase 1 rule is intended to serve as a regulatory bridge until the emerging standards are finalized and a comprehensive Phase 2 rulemaking is effective.
TSA anticipates the future Phase 2 rulemaking would repeal the temporary waiver provisions established in Phase 1 and establish comprehensive requirements enabling States to issue mDLs that comply with REAL ID requirements. TSA envisions the Phase 2 rulemaking would draw heavily from pertinent parts of the emerging standards (pending review of those final, published documents) to set specific requirements for security, privacy, and interoperability. In addition, the Phase 2 rule would distinguish between existing regulatory requirements that apply only to mDLs versus physical cards. As one commenter
7
to a previously-issued Request for Information (RFI) urged (discussed in Part II.B., below), DHS is taking “a slow and careful approach” to regulation in order to fully understand the implications of mDLs.
7
See
comment from Electronic Privacy Information Center,
https://downloads.regulations.gov/DHS-2020-0028-0048/attachment_1.pdf
(last visited July 17, 2024); DHS, Request for Information, Mobile Driver's Licenses, 86 FR 20320 (Apr. 19, 2021).
This multi-phased rulemaking approach supports Executive Order (E.O.) 14058 of December 13, 2021 (Transforming Federal Customer Experience and Service Delivery to Rebuild Trust in Government), by using “technology to modernize Government and implement services that are simple to use, accessible, equitable, protective, transparent, and responsive for all people of the United States.”
8
As highlighted above and discussed in more detail below, allowing acceptance of mDLs issued by States that meet the waiver requirements enables the public to more immediately realize potential benefits of mDLs, including greater convenience, security, and privacy.
8
See
86 FR 71357 (Dec. 16, 2021).
D. Costs and Benefits
TSA estimates the 10-year total cost of the rule to be $829.8 million undiscounted, $698.1 million discounted at 3 percent ($81.8 million annualized), and $563.9 million discounted at 7 percent ($80.3 million annualized). Affected entities include States, TSA, and relying parties (Federal agencies that voluntarily choose to accept mDLs for official purposes).
States incur costs to familiarize themselves with the requirements of the final rule, purchase access to an industry standard, submit an mDL waiver application, submit mDL waiver reapplications, and comply with waiver application requirements. TSA estimates that 40 States will seek an mDL waiver over the next 10 years at a 10-year State cost of $813.1 million undiscounted, $683.7 million discounted at 3 percent, and $552.0 million discounted at 7 percent.
TSA incurs costs associated with purchasing access to industry standards, reviewing mDL waiver applications and mDL waiver reapplications, acquiring, installing, and operating mDL readers, and training transportation security officers. TSA estimates the 10-year cost to TSA is $10.13 million undiscounted, $8.87 million discounted at 3 percent, and $7.56 million discounted at 7 percent.
Relying parties will incur costs to procure mDL readers should they voluntarily choose to accept mDLs for official purposes. TSA estimates the 10-year cost to relying parties is $6.57 million undiscounted, $5.48 million discounted at 3 percent, and $4.38 million discounted at 7 percent.
TSA also identifies other non-quantified costs that affected parties may incur. States may incur incremental costs to: monitor and study mDL technology as it evolves; resolve underlying issues that could lead to a suspension or termination of an mDL waiver; report serious threats to security, privacy, or data integrity; report material changes to mDL issuance processes; remove conflicts of interest with an independent auditor; and request reconsideration of a denied mDL waiver application. TSA may incur costs to: investigate circumstances that could lead to suspension or termination of a State's mDL waiver; provide notice to States, relying parties, and the public related to mDL waiver suspensions or terminations; develop an IT solution that maintains an up-to-date list of States with valid mDL waivers; develop materials related to process changes to adapt to mDL systems; and resolve requests for reconsideration of a denied mDL waiver application. An mDL user may incur costs with additional application requirements to obtain an mDL. States may also pass on mDL related costs to the public.
9
Relying parties may incur costs to resolve any security or privacy issue with the mDL reader; report serious threats to security, privacy, or data integrity; verify the list of States with valid mDL waivers; train personnel to verify mDLs; and update the public on identification policies.
9
TSA does not possess data to quantify how States may implement a pass through or recoup costs associated with implementation of mDLs.
The final rule provides benefits to affected parties which include, but are not limited to: promoting higher security, privacy, and interoperability safeguards; reducing uncertainty in the mDL technology environment by helping to foster a minimum level of security, privacy and interoperability; and allowing Federal agencies to continue to accept mDLs for official purposes when REAL ID enforcement begins. Also, mDLs themselves may provide additional security benefits by offering a more secure verification of an individual's identity and authentication of an individual's credential compared to usage of physical cards.
II. Background
A. REAL ID Act, Regulations, and Applicability to mDLs
This rulemaking is authorized by the REAL ID Act of 2005 and REAL ID Modernization Act. The REAL ID Act authorizes the Secretary of Homeland Security, in consultation with the States and the Secretary of Transportation, to promulgate regulations to implement the requirements under the REAL Act.
10
The REAL ID Modernization Act amended the definitions of “driver's license” and “identification card” to specifically include mDLs that have been issued in accordance with regulations prescribed by the Secretary of Homeland Security.
11
10
Sec. 205 of the REAL ID Act.
11
Sec. 1001 of the REAL ID Modernization Act, Title X of Division U of the Consolidated Appropriations Act, 2021, Public Law 116-260, 134 Stat. 2304 [hereinafter “REAL ID Modernization Act”].
The REAL ID Act and implementing regulations, 6 CFR part 37, set minimum requirements for State-issued driver's licenses and identification cards accepted by Federal agencies for official purposes, including accessing Federal
facilities, boarding Federally regulated commercial aircraft, entering nuclear power plants, and any other purposes that the Secretary shall determine.
12
The Act defines “driver's licenses” and “identification cards” strictly as State-issued documents,
13
and the regulations further refine the definition of “identification card” as “a document made or issued by or under the authority of a State Department of Motor Vehicles or State office with equivalent function.”
14
The REAL ID Act and regulations do not apply to identification cards that are not made or issued under a State authority, such as cards issued by a Federal agency or any commercial, educational, or non-profit entity.
12
REAL ID Act; 6 CFR part 37.
13
Sec. 201 of the REAL ID Act.
14
6 CFR 37.3.
The regulations include a schedule describing when individuals must obtain a REAL ID-compliant driver's license or identification card intended for use for official purposes, known as “card-based” enforcement.
15
Card-based enforcement begins on May 7, 2025.
16
On this date, Federal agencies will be prohibited from accepting a State- or territory-issued driver's license or identification card for official purposes unless the card is compliant with the REAL ID Act and regulations.
17
15
See
6 CFR 37.5(b). The regulations also include a schedule for State-based compliance, known as “State-based enforcement.”
See
6 CFR 37.51(a).
16
See
6 CFR 37.5(b).
17
See
6 CFR 37.5(b). Additionally, TSA is conducting a separate rulemaking that would allow Federal agencies to implement the card-based enforcement provisions of the REAL ID regulations under a phased approach beginning on the May 7, 2025 enforcement deadline.
See
NPRM, Phased Approach for Card-Based Enforcement, 89 FR 74137 (Sept. 12, 2024).
On December 21, 2020, Congress passed the REAL ID Modernization Act,
18
which amended the REAL ID Act to update the definitions of “driver's license” and “identification card” to specifically include mDLs that have been issued in accordance with regulations prescribed by the Secretary, among other updates.
19
Accordingly, mDLs must be REAL ID-compliant to be accepted by Federal agencies for official purposes when card-based enforcement begins on May 7, 2025. However, States cannot issue REAL ID-compliant mDLs until the regulations are updated to include requirements to ensure that mDLs meet equivalent levels of security currently imposed on REAL ID-compliant physical cards.
18
REAL ID Modernization Act, 134 Stat. 2304.
19
Sec. 1001 of the REAL ID Modernization Act, 134 Stat. 2304.
B. Rulemaking History
In April 2021, DHS issued an RFI announcing DHS's intent to commence future rulemaking to set the minimum technical requirements and security standards for mDLs to enable Federal agencies to accept mDLs for official purposes. The RFI requested comments and information to inform DHS's rulemaking.
20
In response, DHS received 63 comments
21
through a twice-extended comment period of 180 days, which closed on October 18, 2021.
20
86 FR 20320 (Apr. 19, 2021).
21
The 63 total comments included three duplicates and one confidential submission.
In August 2023, TSA published a Notice of Proposed Rulemaking (NPRM)
22
drawing on comments to the RFI, which are summarized at 88 FR 60056, 60071-72. The NPRM comment period closed on October 16, 2023, and TSA received 31 comments. NPRM comments are discussed in detail in Part IV, below.
22
88 FR 60056.
C. mDL Overview
1. mDLs Generally
An mDL is generally recognized as the digital representation of an individual's identity information contained on a State-issued physical driver's license or identification card.
23
An mDL may be stored on a diverse range of portable or mobile electronic devices, such as smartphones, smartwatches, and storage devices containing memory. Like a physical card, mDL data originates from identity information about an individual that is maintained in the database of a State driver's licensing agency. An mDL has potential benefits for all stakeholders. For Federal agencies, mDLs may provide security and efficiency enhancements compared to physical cards, because mDLs rely on digital security features that are immune to many vulnerabilities of physical security features. For individuals, mDLs may provide a more secure, convenient, privacy-enhancing, and “touchless” method of identity verification compared to physical IDs.
23
A technical description of mDLs as envisioned by the American Association of Motor Vehicle Administrators may be found at
https://www.aamva.org/Mobile-Drivers-License/
(last visited July 17, 2024).
Unlike physical cards that employ physical security features to deter fraud and tampering, mDLs combat fraud through the use of digital security features that are not recognizable through human inspection, such as asymmetric cryptography/public key infrastructure (PKI). As discussed in the NPRM,
24
asymmetric cryptography generates a pair of encryption “keys” to encrypt and decrypt protected data. One key, a “public key,” is distributed publicly, while the other key, a “private key,” is held by the State driver's licensing agency (
e.g.,
a Department of Motor Vehicles). When the driver's licensing agency issues an mDL to an individual, the agency uses its private key to digitally “sign” the mDL data. A Federal agency accepting an mDL validates the integrity of the mDL data by obtaining the State driver's licensing agency's public key to verify the digital signature. Private keys and digital signatures are elements of data encryption that protect against unauthorized access, tampering, and fraud. Generally, mDL-based identity verification under REAL ID involves a triad of secure communications between a State driver's licensing agency, an mDL holder, and a Federal agency. Standardized communication interfaces are necessary to enable Federal agencies to exchange information with all U.S. States and territories that issue mDLs. Please see the NPRM for a more detailed discussion.
25
24
88 FR at 60060.
25
88 FR at 60060-61.
In contrast to physical driver's licenses that are read and verified visually through human inspection of physical security features, an mDL is read and verified electronically using a device known simply as a “reader. Any Federal agency that accepts mDLs for official purposes must use readers to validate an mDL holder's identity data from their mobile device and establish trust that the mDL is secure by using private-public key data encryption.
26
An mDL reader compliant with this requirement can take multiple forms, such as an app installed on a mobile device, or a dedicated device. Although reader development is evolving, some companies already offer reader apps for free, and TSA therefore expects readers will be offered in a wide range capabilities and associated price points.
27
26
Non-Federal agencies and other entities who choose to accept mDLs for uses beyond the scope of REAL ID should also recognize the need for a reader to ensure the validity of the mDL. Any verifying entity can validate in the same manner as a Federal agency if they implement the standardized communication interface requirements specified in this final rule, which would require investment to develop the necessary IT infrastructure and related processes.
27
Readers for mDLs have specific requirements and at this time are not interchangeable with readers for other types of Federal cards, such as the Transportation Worker Identification Credential (TWIC). Although TSA is evaluating some mDLs at select airport security checkpoints, cost estimates for readers used in the evaluations are not available because those readers are non-commercially
available prototypes designed specifically for integration into TSA-specific IT infrastructure that few, if any, other Federal agencies use. In addition, mDL readers are evolving and entities who accept mDLs would participate voluntarily. Accordingly, associated reader costs are not quantified at this time but TSA intends to gain a greater understanding of any costs to procure reader equipment as the technology continues to evolve.
2. State mDL Issuance and TSA Testing
As noted above, mDL issuance is proliferating rapidly among States, with at least half of all States believed to be preparing for or issuing mDLs.
28
Although detailed mDL adoption statistics are unavailable, anecdotal information and media reports indicates that mDLs are rapidly gaining public acceptance. For example, Maryland commented that it has issued more than 200,000 mDLs to residents following a pilot in 2017 and more recent expansion in 2022 and 2023.
29
Iowa commented that in the 3 months since it began offering its mDL app, it has been downloaded by more than 7,000 users.
30
28
See, e.g.,
AAMVA, Driver and Vehicle Services Data Map,
https://www.aamva.org/jurisdiction-data-maps#anchorformdlmap
(last visited July 17, 2024); PYMNTS,
States Embrace Mobile Driver's Licenses to Fight Fraud Amid Privacy Scrutiny
(Apr. 9, 2024),
https://www.pymnts.com/identity/2024/states-embrace-mobile-drivers-licenses-to-fight-fraud-amid-privacy-scrutiny/
(last visited July 17, 2024); Government Technology,
Digital IDs Are Here, but Where Are They Used and Accepted?
(Mar. 12, 2024),
https://www.govtech.com/biz/data/digital-ids-are-here-but-where-are-they-used-and-accepted
(last visited July 17, 2024).
29
Comment by Maryland MVA,
https://www.regulations.gov/comment/TSA-2023-0002-0032
(last visited July 17, 2024).
30
Comment by Iowa Department of Transportation,
https://www.regulations.gov/comment/TSA-2023-0002-0023
(last visited July 17, 2024).
TSA understands that States are issuing mDLs using widely varying technology solutions, raising concerns whether such technological diversity provides the safeguards and interoperability necessary for Federal acceptance. Since 2022, TSA has been collaborating with States and industry to test the use of mDLs issued by participating States at select TSA airport security checkpoints.
31
As of the date of this final rule, TSA is currently testing mDLs issued by 11 States (Arizona, California, Colorado, Georgia, Hawaii, Iowa, Louisiana, Maryland, New York, Ohio, Utah) at 27 airports.
32
31
See
NPRM, 88 FR at 60066-67.
32
See
TSA, Facial Recognition and Digital Identity Solutions,
https://www.tsa.gov/digital-id
(last visited Aug. 9, 2024).
D. Industry Standards and Government Guidelines for mDLs
The nascence of mDLs and absence of standardized mDL-specific requirements provide an opportunity for industry and government to develop standards and guidelines to close this void. TSA is aware of multiple such documents, published and under development, from both Federal and non-government sources. As discussed in Part III.C.8, below, this final rule amends § 37.4 by IBR'g into part 37 19 standards and guidelines that form the basis of many of the requirements in this final rule. TSA understands that these standards and guidelines discussed are the most comprehensive and relevant references governing mDLs today. TSA also acknowledges that many additional standards and guidelines are in development and may provide additional standardized mechanisms for mDLs.
33
33
See
NPRM, 88 FR at 60063-66, for a discussion of these standards.
III. General Discussion of the Rulemaking
A. Changes Between NPRM and Final Rule
After carefully considering all comments received to the NPRM (see detailed discussion of comments and TSA's responses in Part IV, below), TSA finalizes the NPRM with several revisions in response to public comments. Table 1 summarizes the changes made in the final rule compared to the NPRM.
Table 1—Summary of Changes Between the NPRM and the Final Rule
Section
Final rule
Reason for the change
37.3
Adds definition for “Provisioning.”
Technical change to add definition of a key term to improve clarity.
37.4
Revises points of contact for the public to contact TSA; provides additional means to access certain standards that are IBR'd in this rule
Technical changes to improve access to IBR materials.
37.4(c)(1)
Corrects title of “Cybersecurity Incident & Vulnerability Response Playbooks” to “Federal Government Cybersecurity Incident & Vulnerability Response Playbooks.”
Technical correction.
37.4(g)(4)
Updates standard NIST FIPS PUB 197 to NIST FIPS PUB 197-upd1 to reflect revised version of standard
Technical change to reflect revisions to standard to improve public access. Revisions include editorial improvements, but no technical changes to the algorithm specified in the earlier version.
37.4(g)(7)
Corrects website address to the cited standard
Technical change to correct a typo.
37.7(a)
Clarifies conditions under which TSA will issue a waiver
Clarification regarding impact of the waiver.
37.7(b)(3)
Deleted
Deleted proposed language that would have made a State ineligible to apply for a waiver if the State issues mDLs to individuals with non-REAL ID compliant physical cards (in addition to issuing mDLs to other individuals that have compliant physical cards).
37.8(c)
Adds paragraph (c) to require Federal agencies accepting mDLs to confirm, consistent with the deadlines set forth in § 37.5, that the mDL data element “DHS_compliance” is encoded “F,” as required by §§ 37.10(a)(4)(ii) & (a)(1)(vii)
Clarifies that when REAL ID enforcement begins, Federal agencies may accept mDLs from States only if the underlying physical card is REAL ID compliant.
37.8(d)
Renumbers § 37.8(c), as proposed in the NPRM, to § 37.8(d) in light of addition of new § 37.8(c)
Corrects website address from
dhs.gov
to
tsa.gov
Adds requirement regarding protection of SSI
Technical changes renumber provision from 37.8(c) to 37.8(d), update agency name and website address, and clarify the mechanics of reporting.
Provides that reports
may
contain sensitive security information (SSI)
34
and if so, would be subject to requirements of 49 CFR part 1520.
37.9(a)
Corrects agency name from DHS to TSA
Corrects website address from
dhs.gov
to
tsa.gov
Technical changes update agency name and website address.
37.9(b)
Revises “days” to “calendar days.”
Corrects website address from
dhs.gov
to
tsa.gov
Clarifies that “days” means calendar days, not business days.
Technical change updates agency website address.
37.9(c)
Revises “days” to “calendar days.”
Corrects website address from
dhs.gov
to
tsa.gov
Clarifies that “days” means calendar days, not business days.
Technical change updates agency website address.
37.9(e)(2)
Revises “days” to “calendar days.”
Corrects website address from
dhs.gov
to
tsa.gov
Provides a means for States to contact TSA if the State is unclear whether certain modifications to its mDL issuance processes require reporting
Clarifies that “days” means calendar days, not business days.
Technical change updates agency website address.
Provides a means for States to resolve potential questions regarding reporting requirements.
37.9(e)(4)(ii)
Revises “days” to “calendar days.”
Clarifies that “days” means calendar days, not business days.
37.9(e)(5)(i)
Corrects agency name from DHS to TSA
Technical change updates agency name.
37.9(e)(5)(ii)
Revises “days” to “calendar days.”
Clarifies that “days” means calendar days, not business days.
37.9(g)
Adds new paragraph (g), which provides that information submitted in response to requirements to apply for and maintain a waiver
may
contain SSI, and if so, would be subject to requirements of 49 CFR part 1520
SSI protection.
37.10(a)(1)(vii)
Replaces NPRM requirement that States must issue mDLs only to residents who have been issued physical cards that are valid, unexpired, and REAL ID-compliant with requirement that States must populate the “DHS_compliance” data field to correspond to the REAL ID-compliance status of the underlying physical driver's license or identification card, or as required by the AAMVA Guidelines
Proposed language would have required States to issue mDLs only to individuals to whom that State previously issued a physical card that is valid, unexpired, and REAL ID-compliant. This would have denied States the discretion to issue mDLs to holders of non-compliant physical cards.
Revisions require States to issue mDLs in a manner that reflects the REAL ID compliance status of the underlying physical card. This is consistent with the intent of the NPRM, which was to enable Federal agencies to determine the REAL ID-compliance status of the underlying physical card, and accept only compliant cards when enforcement begins.
37.10(a)(4)
Corrects version number of AAMVA Mobile Driver's License (mDL) Implementation Guidelines (Jan. 2023)
Updates NIST FIPS PUB 197 to NIST FIPS PUB 197-upd1 to reflect revised version of standard
Technical change corrects version number of AAMVA Guidelines.
Changes reflect current version of NIST FIPS PUB 197 to ensure continuing public access. Revisions to the standard include editorial improvements, but no technical changes to the algorithm specified in the earlier version.
37.10(b)(1)
Clarifies that “independent entity” includes State employees or contractors that are independent of the State's driver's licensing agency
Provides States additional options to select auditors. Reduces burdens without impact on security or privacy.
37.10(c)
Corrects website address from
dhs.gov
to
tsa.gov
Clarifies that TSA will publish in the
Federal Register
a notice advising of the availability of updated TSA mDL Waiver Application Guidance, which itself will be published at
www.tsa.gov/mDL/
Technical changes update agency website address, and clarify means of notifying and publishing updates to TSA mDL Waiver Application Guidance.
Appendix A, Throughout
Corrections to titles of:
CISA Federal Government Cybersecurity Incident & Vulnerability Response Playbooks
DHS National Cyber Incident Response Plan
NIST FIPS PUB 140-3
NIST Framework for Improving Critical Infrastructure Cybersecurity
Technical corrections.
Appendix A, paragraph 1.1
Adds section numbers to certain references
Deletes requirement to comply with NIST SP 800-53B
Technical changes clarify which parts of cited reference require compliance, and remove an unnecessary requirement.
Appendix A, paragraph 2.2
Revises “privileged account or service” in NPRM to “trusted role.”
Technical change corrects terminology.
Appendix A, paragraph 2.13
Adds section numbers to a certain reference
Technical change clarifies which parts of cited reference require compliance.
Appendix A, paragraph 5.13
Reduces requirements for minimum number of personnel to generate issuing authority certificate authority (IACA) root certificate keys from a minimum of three to two persons, consisting of at least one ceremony administrator and one qualified witness
Provides States greater freedom to select products. Does not impact security, privacy, or interoperability.
Appendix A, paragraph 5.14
Modifies requirements for minimum number of personnel to generate document signer keys. Final rule requires either at least one administrator and one qualified witness (other than a person involved in key generation), or at least 2 administrators using split knowledge processes
Provides States greater freedom to select products. Does not impact security, privacy, or interoperability.
Appendix A, paragraph 6.3
Revises “days” to “calendar days
Clarifies that “days” means calendar days, not business days.
Appendix A, paragraph 8.6
Modifies cyber incident reporting requirements to incidents as defined in the TSA Cybersecurity Lexicon available at
www.tsa.gov
that may harm state certificate systems
Corrects website address from
dhs.gov
to
tsa.gov
Adds SSI protection requirements
Clarifies types of incidents that must be reported, updates agency website address, and adds SSI protection.
B. Summary of Regulatory Provisions
34
SSI is information obtained or developed in the conduct of security activities, the disclosure of which would constitute an unwarranted invasion of privacy, reveal trade secrets or privileged or confidential information, or be detrimental to the security of transportation. The protection of SSI is governed by 49 CFR part 1520.
In addition to revising definitions applicable to the REAL ID Act to incorporate mDLs, this rule amends 6 CFR part 37 to enable TSA to grant a temporary waiver to States that TSA determines issue mDLs consistent with specified requirements concerning security, privacy, and interoperability. This rule enables Federal agencies, at their discretion, to accept for REAL ID official purposes, mDLs issued by a State that has been granted a waiver, provided that the underlying physical card upon which the mDL was based is REAL ID-compliant. The rule applies only to Federal agency acceptance of State-issued mDLs as defined in this final rule for REAL ID official purposes, but not other forms of digital identification, physical driver's licenses or physical identification cards, or non-REAL ID purposes. Any temporary waiver issued by TSA would be valid for a period of 3 years from the date of issuance.
To obtain a waiver, § 37.9(a) requires a State to submit an application, supporting data, and other documentation to establish that their mDLs meet the criteria specified in §§ 37.10(a) and (b) (discussed in Part III.C.4., below) concerning security, privacy, and interoperability. If TSA determines, upon evaluation of a State's application and supporting documents, that a State's mDL could be securely accepted under the terms of a waiver, TSA may issue such State a certificate of waiver. TSA intends to work with each State applying for a waiver on a case-by-case basis to ensure that its mDLs meet the minimum requirements necessary to obtain a waiver. This rulemaking establishes the full process for a State to apply for and maintain a waiver, including: instructions for submitting the application and responding to subsequent communications from TSA as necessary; specific information and documents that a State must provide with its application; requirements concerning timing, issuance of decisions, requests for reconsideration; and post-issuance reporting requirements and other terms, conditions, and limitations. To assist States that are considering applying for a waiver, TSA has developed guidelines, entitled, “Mobile Driver's License Waiver Application Guidance” (hereinafter “TSA Waiver Guidance” or “the Guidance”), which provides non-binding recommendations of some ways that States can meet the application requirements set forth in this rulemaking.
35
This final rule makes several technical and administrative changes to the NPRM, as set forth in Table 1, above. These changes are as follows:
35
The specific measures and practices discussed in the TSA Waiver Application Guidance are neither mandatory nor necessarily the “preferred solution” for complying with the requirements in this final rule. Rather, they are examples of measures and practices that a State issuer of mDLs may choose to consider as part of its overall strategy to issue mDLs. States have the ability to choose and implement other measures to meet these requirements based on factors appropriate to that State, so long as DHS determines that the measures implemented provide the levels of security and data integrity necessary for Federal acceptance of mDLs for official purposes as defined in the REAL ID Act and 6 CFR part 37. As provided in § 37.10(c), TSA may periodically update the Guidance as necessary to recommend mitigations of evolving threats to security, privacy, or data integrity.
• Corrections to agency name, website address, points of contact for access and compliance with reporting requirements:
See
§§ 37.4, 37.8(d), 37.9(a)-(c), (e)(2) & (e)(5)(i), 37.10(c), and Appendix A, paragraph 8.6.
• Corrections to inadvertent omissions, typographical errors, paragraph numbering, title/version number of publications:
See
§§ 37.3, 37.4, 37.4(c)(1), 37.8(d), 37.4(g)(4) & (7), 37.10(a)(4), Appendix A, paragraphs 1.1, 2.13, 2.2, 8.4, 8.5, 8.8.
• Clarifying that “days” means “calendar days”:
See
§§ 37.9(b), 37.9(c), 37.9(e)(2), (4)(i) & (5)(ii), and Appendix A, paragraph 6.3.
C. Specific Provisions
This section describes the final regulatory provisions in this rule, including the changes discussed above. Unless otherwise noted, these provisions were described in the NPRM.
1. Definitions
The final rule adds new definitions to subpart A, § 37.3, consistent with those proposed in the NPRM. In particular, new definitions for “mobile driver's license” and “mobile identification card” are necessary because the current regulations predated the emergence of mDL technology and, therefore, do not define these terms. Additionally, the definitions reflect changes made by the REAL ID Modernization Act, which amended the definitions of “driver's license” and “identification card” to specifically include “mobile or digital driver's licenses” and “mobile or digital identification cards.” The definitions in this rule provide a more precise definition of “mobile driver's license” and “mobile identification card” by clarifying that those forms of identification require a mobile electronic device to store the identification information, as well as an electronic device to read that information. The rule also adds a new definition of “mDL” that collectively refers to mobile versions of both State-issued driver's licenses and State-issued identification cards as defined in the REAL ID Act.
The final rule includes additional definitions to explain terms used in the waiver application criteria set forth in §§ 37.10(a)-(b) and Appendix A to subpart A of this part (Appendix A). Generally, this rule defines terms that lack a common understanding or that are common terms of art for information systems, and that require an explanation to enable stakeholders to comply with the rule. The definitions were informed by TSA's knowledge and experience, as well as a publication by the National Institute of Standards and Technology (NIST).
36
For example, the rule adds definitions for “digital certificates” and “certificate systems,” which are necessary elements of risk controls for the IT systems that States use to issue mDLs. In addition, this final rule adds a definition for “certificate policy,” which forms the governance framework for States' certificate systems. A State must develop, maintain, and execute a certificate policy to comply with the requirements set forth in Appendix A. In addition, “Digital Signatures” are mathematical algorithms that States use to validate the authenticity and integrity of a message. Each of these terms is fundamental to understanding the requirements set forth in this rule.
36
See
NIST, Computer Security Resource Center,
https://csrc.nist.gov/glossary
(last visited July 17, 2024).
The final rule adds a definition for “provisioning” which was not proposed in the NPRM.
See
§ 37.3. As defined by this final rule, “provisioning” means the process by which a State transmits and installs an mDL on an individual's mobile device. Although TSA did not receive any comments seeking clarity or requesting the addition of this or other definitions, TSA believes provisioning is a critical concept that requires a definition in order to facilitate stakeholder compliance.
2. TSA Issuance of Temporary Waiver and State Eligibility Criteria
The final rule adds to subpart A new § 37.7, entitled “Temporary waiver for mDLs; State eligibility.” This waiver framework temporarily allows Federal agencies to accept for official purposes mDLs (which today are all non-compliant) issued by States with a waiver, if the mDL is based on a REAL ID-compliant physical card, when REAL ID enforcement begins on May 7, 2025 (
see
§ 37.8, discussed in Part III.C.3., below). However, the waiver framework does not apply to any other requirements in 6 CFR part 37 or physical cards. Section 37.7(a) authorizes TSA to issue a temporary certificate of waiver to States that meet the waiver application criteria set forth in §§ 37.10(a) and (b). TSA's determination of whether a State satisfies these requirements will be based on TSA's evaluation of the information provided by the State in its application (
see
Part III.C.4., below), as well as other information available to TSA. Federal agencies are not required to accept mDLs, and retain discretion to determine their own policies regarding identity verification.
Although NPRM § 37.7(a) stated that a waiver would exempt a State's mDLs from meeting the card-based compliance requirement of § 37.5(b), the final rule deletes this clause because a waiver impacts Federal agency
acceptance,
not State
issuance,
of non-compliant mDLs. Stated differently, a waiver allows Federal agencies to accept non-compliant mDLs issued by States to whom TSA has granted a waiver. As discussed above in this preamble, the waiver application criteria set forth temporary security requirements commensurate with REAL ID standards for physical cards, ensuring that mDLs meeting the criteria are suitable for Federal acceptance. However, States cannot issue REAL ID-compliant mDLs until TSA sets forth such requirements in the subsequent Phase 2 rulemaking.
Section 37.7(b) sets forth criteria that a State must meet to be eligible for consideration of a waiver. These criteria require that the issuing State: (1) is in full compliance with all applicable REAL ID requirements as defined in subpart E of this part, and (2) has submitted an application, under §§ 37.10(a) and (b) demonstrating that the State issues mDLs that provide security, privacy, and interoperability necessary for Federal acceptance.
37
The NPRM proposed paragraph (b)(3) of this section, which provided an additional waiver eligibility criterion that a State must issue mDLs only to individuals who have been issued REAL ID-compliant physical cards. However, the final rule does not adopt this proposal given TSA's evaluation of public comments (see Part IV.A.) that this provision would have made a State ineligible for a waiver if the State issued mDLs to both individuals with REAL ID-compliant physical cards and individuals with non-compliant physical cards. The final rule similarly amends § 37.10(a)(1)(vii), as proposed by the NPRM, to remove a provision that would have required States to issue an mDL only to a resident who has been issued a valid, unexpired, and REAL ID-compliant physical card that underlies the mDL.
See
Part III.C.4, below.
37
Sections 37.7(b)(1) & (2).
3. Requirements for Federal Agencies that Accept mDLs
The final rule adds to subpart A new § 37.8, entitled “Requirements for Federal agencies accepting mDLs issued by States with temporary waiver.” This section requires that any Federal agency that elects to accept mDLs for REAL ID official purposes must meet four requirements in new § 37.8. First, under § 37.8(a), a Federal agency must confirm that the State holds a valid certificate of waiver. Agencies would make this confirmation by verifying that the State's name appears in a list of States to whom TSA has granted a waiver. TSA will publish this list on the REAL ID website at
www.tsa.gov/real-id/mDL
(as provided in § 37.9(b)(1)).
Second, § 37.8(b) requires Federal agencies to use an mDL reader to retrieve mDL data from an individual's mobile device and validate that the data is authentic and unchanged following the processes required by industry standard ISO/IEC 18013-5:2021(E).
38
38
See
NPRM, 88 FR at 60063-64, for a discussion of this standard.
Third, under § 37.8(c), Federal agencies may accept, consistent with the deadlines set forth in § 37.5, only those mDLs that are issued based on an underlying physical card that is REAL ID compliant. Agencies would make this determination by confirming that mDL data element “DHS_compliance” has a value of “F”. As discussed in Part III.C.8.a., below, the data field “DHS_compliance” (defined in the American Association of Motor Vehicle Administrators
Mobile Driver's License (mDL) Implementation Guidelines Version 1.2
(Jan. 2023) (AAMVA Guidelines)) enables an mDL to convey the REAL ID compliance status of the underlying physical card. TSA notes that § 37.8(c) is a new provision that was not included in the NPRM. TSA intended, in proposed §§ 37.7(b)(3) and 37.10(a)(1)(vii) of the NPRM, that Federal agencies would accept only mDLs issued by States to whom TSA has issued a waiver, and that are based on an underlying physical card that is REAL ID-compliant. Final rule § 37.8(c), together with revisions to § 37.10(a)(1)(vii) (see discussion in Part III.C.4., below), achieves that intent.
Finally, under § 37.8(d), if a Federal agency discovers that acceptance of a State's mDL is likely to cause imminent or serious threats to security, privacy, or data integrity, the agency must report the threats to TSA at
www.tsa.gov/real-id/mDL
within 72 hours of such
discovery. Examples of reportable threats include cyber incidents and other events that cause serious harm to a State's mDL issuance system. Reports
may
contain SSI, and if so, would be subject to requirements of 49 CFR part 1520. Although the NPRM did not propose the SSI protection provision, TSA evaluated comments to the NPRM (
see
Part IV.W., below) seeking clarification on SSI protection for other information (State waiver applications) and determined that SSI protection is warranted for Federal agency reports under this § 37.8(d), which has been added in this final rule. TSA will consider whether such information warrants suspension of that State's waiver under § 37.9(e)(4)(i)(B) (
see
discussion in Part III.C.6., below). If TSA elects not to issue a suspension, Federal agencies would continue to exercise their own discretion regarding continuing acceptance of mDLs.
4. Requirements for States Seeking To Apply for a Waiver
The final rule adds to subpart A new § 37.9, which sets forth a process for a State to request a temporary certificate of waiver established in new § 37.7. As provided in § 37.9(a), a State seeking a waiver must file a complete application as set forth in §§ 37.10(a) and (b), following instructions available at
www.tsa.gov/real-id/mDL.
Sections 37.10(a) and (b) set forth all information, documents, and data that a State must include in its application for a waiver. If TSA determines that the means that a State implements to comply with the requirements in §§ 37.10(a) and (b) provide the requisite levels of security, privacy, and data integrity for Federal acceptance of mDLs for official purposes, TSA would grant such State a waiver. This rule does not, however, prescribe specific means (other than the requirements specified in Appendix A, which is discussed further in Part III.C.4.iv, below) that a State must implement. Instead, States would retain broad discretion to choose and implement measures to meet these requirements based on factors appropriate to that State.
(i) Application Requirements
As set forth in §§ 37.10(a)(1) through (4), a State is required to establish in its application how it issues mDLs under the specified criteria for security, privacy, and interoperability suitable for acceptance by Federal agencies, as follows:
• Paragraph (a)(1) sets forth requirements for mDL provisioning. Specific requirements include:
○ Encryption of mDL data and an mDL holder's Personally Identifiable Information,
○ Escalated review of repeated failed provisioning attempts,
○ Authentication of the mDL applicant's mobile device,
○ Mobile device identification keys,
○ User identity verification controls,
○ Applicant presentation controls,
○ Encoding of the “DHS_compliance” data field. States must populate this data field to correspond to the REAL ID compliance status of the underlying physical driver's license or identification card that a State has issued to an mDL holder. Specifically, “DHS_compliance” should be populated with “F” if the underlying card is REAL ID compliant, or as required by American Association of Motor Vehicle Administrator (AAMVA) Mobile Driver's License (mDL) Implementation Guidelines v. 1.2, Section 3.2 (IBR'd; see § 37.4), or “N” if the underlying card is not REAL ID-compliant. Although § 37.10(a)(1)(vii) of the NPRM proposed requiring that States issue an mDL only to a resident who has been issued a valid, unexpired, and REAL ID-compliant physical card that underlies the mDL, the final rule does not adopt this provision, based on TSA's evaluation of public comments (see Part IV.A.), that this provision would have made a State ineligible to apply for a waiver if the State issued mDLs to both individuals with REAL ID-compliant physical cards and individuals with non-compliant physical cards,
○ Data record requirements, and
○ Records retention specifications.
• Paragraph (a)(2) specifies requirements for managing state certificate systems, which are set forth in Appendix A.
• Paragraph (a)(3) requires a State to demonstrate how it protects personally identifiable information of individuals during the mDL provisioning process.
• Paragraph (a)(4) requires a State to explain the means it uses to:
○ Issue mDLs that are interoperable with requirements set forth in standard ISO/IEC 18013-5:2021(E),
○ Comply with the “AAMVA mDL data element set” as defined in the AAMVA Guidelines v. 1.2, Section 3.2,
39
and
39
See
NPRM, 88 FR at 60062-65, for a discussion of these standards.
○ Use only those algorithms for encryption,
40
secure hash function,
41
and digital signatures that are specified in ISO/IEC 18013-5:2021(E), and in NIST FIPS PUB 180-4, 186-5, 197-upd1, 198-1, and 202.
40
Encryption refers to the process of cryptographically transforming data into a form in a manner that conceals the data's original meaning to prevent it from being read. Decryption is the process of restoring encrypted data to its original state. IETF RFC 4949, internet Security Glossary, Version 2, Aug. 2007,
https://datatracker.ietf.org/doc/html/rfc4949
(last visited July 17, 2024).
41
A function that processes an input value creating a fixed-length output value using a method that is not reversible (
i.e.,
given the output value of a function it is computationally impractical to find the function's corresponding input value).
(ii) Audit Requirements
Section 37.10(b) requires a State to submit an audit report prepared by an independent auditor verifying the accuracy of the information provided by the State in response to § 37.10(a), as follows:
• Paragraph (1) sets forth specific experience, qualifications, and accreditations that an auditor must meet.
• Paragraph (2) requires a State to provide information demonstrating the absence of a potential conflict of interest of the auditing entity.
The term “independent” does not exclude an entity that is employed or contracted by a State, so long as that entity is independent of (
i.e.,
not an employee or contractor) the State's driver's licensing agency. TSA provides this clarification at the request of commenters (see Part IV.U., below).
(iii) Waiver Application Guidance
As set forth in § 37.10(c), TSA has published Mobile Driver's License Waiver Application Guidance on the REAL ID website at
www.tsa.gov/real-id/mDL
to assist States in completing their applications. The Guidance provides TSA's recommendations for some ways that States can meet the requirements in § 37.10(a)(1). The Guidance does
not
establish legally enforceable requirements for States applying for a waiver. Instead, the Guidance provides non-binding examples of measures and practices that States may choose to consider as part of their overall strategy to issue mDLs. States continue to exercise discretion to select processes not included in the Guidance. Given the rapidly-evolving cyber threat landscape, however, TSA may periodically update the Guidance to provide additional information regarding newly published standards or other sources, or recommend mitigations of newly discovered risks to
the mDL ecosystem. TSA will publish a notice in the
Federal Register
advising that updated Guidance is available, and TSA will publish the updated Guidance on the REAL ID website at
www.tsa.gov/real-id/mDL
and provide a copy to all States that have applied for or been issued a certificate of waiver. Updates to the Guidance will not impact issued waivers or pending applications. Although the NPRM proposed that TSA would publish updated Guidance in the
Federal Register
, in addition to TSA's website, the final rule modifies this requirement to provide that the agency will publish in the
Federal Register
only a notice of availability of updated guidance, but the Guidance itself will be published on TSA's website. This change will enable TSA to more expediently provide updated guidance to the public.
(iv) Appendix A: Requirements for State mDL Issuance Systems
Appendix A sets forth fundamental requirements to ensure the security and integrity of State mDL issuance processes. More specifically, these requirements concern the creation, issuance, use, revocation, and destruction of the State's certificate systems and cryptographic keys. Appendix A consists of requirements in eight categories: (1) Certificate Authority Certificate Life Cycle Policy, (2) Certificate Authority Access Management, (3) Facility, Management, and Operational Controls, (4) Personnel Security Controls, (5) Technical Security Controls, (6) Threat Detection, (7) Logging, and (8) Incident Response and Recovery Plan. Adherence to these requirements, described below, ensures that States issue mDLs in a standardized manner with security and integrity to establish the trust necessary for Federal acceptance for official purposes.
• Certificate Authority Certificate Life Cycle Policy requirements (Appendix A, paragraph 1) ensure that a State issuing an mDL creates and manages a formal process which follows standardized management and protections of digital certificates. These requirements must be implemented in full compliance with the references cited in Appendix A: CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates; CA/Browser Forum Network and Certificate System Security Requirements; ISO/IEC 18013-5:2021(E), Annex B; NIST Framework for Improving Critical Infrastructure Cybersecurity; NIST SP 800-53 Rev. 5; and NIST SP 800-57.
42
42
See
NPRM, 88 FR at 60062-65, for a discussion of these standards.
• Certificate Authority Access Management requirements (Appendix A, paragraph 2) set forth policies and processes for States concerning, for example, restricting access to mDL issuance systems, policies for multi-factor authentication, defining the scope and role of personnel, and certificate system architecture which separates and isolates certificate system functions to defined security zones. These requirements must be implemented in full compliance with the references cited in Appendix A: CA/Browser Forum Network and Certificate System Security Requirements; NIST Framework for Improving Critical Infrastructure Cybersecurity; NIST 800-53 Rev. 5; NIST SP 800-63-3; and NIST SP 800-63B.
43
43
See
NPRM, 88 FR at 60062-65, for a discussion of these standards.
Although NPRM Appendix A, paragraph 1.1, proposed requiring States to comply with NIST SP 800-53B (among other references) as part of States' development of a policy to govern their certificate systems, the final rule does not adopt the proposal requiring compliance with NIST SP 800-53B. Document NIST SP 800-53B, “Control Baselines for Information Systems and Organizations,” defines minimum security and privacy risk controls for Federal Government agencies to protect information security systems. In addition, the publication provides guidance, but not requirements, for other entities that implement NIST SP 800-53 Rev. 5 in their own organizations. Although TSA did not receive any public comments on NIST SP 800-53B, after re-evaluating the usefulness of this document, TSA concludes that other provisions in the final rule prescribe the necessary security and privacy requirements for States issuing mDLs, and NIST SP 800-53B only serves as guidance without providing security or privacy enhancements. Accordingly, the inclusion of NIST SP 800-53B is unnecessary, and the final rule therefore declines to adopt the NPRM's proposal.
• Under the requirements concerning Facility, Management, and Operational Controls (Appendix A, paragraph 3), States must provide specified controls protecting facilities where certificate systems reside from unauthorized access, environmental damage, physical breaches, and risks from foreign ownership, control, or influence. These requirements must be implemented in full compliance with the references cited in Appendix A: NIST SP 800-53 Rev. 5.
44
44
See
NPRM, 88 FR at 60065, for a discussion of this standard.
• Personnel security controls (Appendix A, paragraph 4) require States to establish policies to control insider threat risks to certificate systems and facilities. Such policies must establish screening criteria for personnel who access certificate systems, post-employment access termination, updates to personnel security policy, training, records retention schedules, among other policies. These requirements must be implemented in full compliance with the references cited in Appendix A: NIST SP 800-53 Rev. 5 and CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly‐Trusted Certificates.
45
45
See
NPRM, 88 FR at 60062-63 & 60065, for a discussion of these standards.
• Technical security controls (Appendix A, paragraph 5) specify requirements to protect certificate system networks. In addition, States are required to protect private cryptographic keys of issuing authority root certificates using dedicated hardware security modules (HSMs) of Level 3 or higher and document signer private cryptographic keys in hardware security modules of Level 2 and higher. Dedicated HSMs are used (1) solely for IACA root private key functions and no other functions within the State's certificate system, including document signer private key functions, and (2) exclusively to support a single State. States are not permitted to share with any other State an HSM that physically supports multiple States. Other controls are specified regarding certificate system architecture and cryptographic key generation processes. These requirements must be implemented in full compliance with the references cited in Appendix A: CA/Browser Forum Network and certificate system Security Requirements; CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates; NIST Framework for Improving Critical Infrastructure Cybersecurity; NIST SP 800-53 Rev. 5; NIST SP 800-57; and NIST FIPS PUB 140-3.
46
46
See
NPRM, 88 FR at 60062-63 & 60065, for a discussion of these standards.
• Under requirements for threat detection (Appendix A, paragraph 6), States must implement controls to monitor and log evolving threats to various mDL issuance infrastructure, including digital certificate, issuance, and support systems. These requirements must be implemented in
full compliance with the references cited in Appendix A: CA/Browser Forum Network and certificate system Security Requirements; NIST Framework for Improving Critical Infrastructure Cybersecurity; and NIST SP 800-53 Rev. 5.
47
47
See
NPRM, 88 FR at 60062-63 & 60065, for a discussion of these standards.
• Logging controls (Appendix A, paragraph 7) require States to record various events concerning certificate systems, including the management of cryptographic keys, and digital certificate lifecycle events. The controls set forth detailed requirements concerning specific types of events that must be logged, as well as timeframes for maintaining such logs. These requirements must be implemented in full compliance with the references cited in Appendix A: CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly‐Trusted Certificates; NIST Framework for Improving Critical Infrastructure Cybersecurity; and NIST SP 800-53 Rev. 5.
48
48
See
NPRM, 88 FR at 60062-63 & 60065, for a discussion of these standards.
• Incident Response and Recovery Plan (Appendix A, paragraph 8) requires States to implement policies to respond to and recover from security incidents. States must act on logged events, issue alerts to relevant personnel, respond to alerts within a specified time period, perform vulnerability scans, among other things. In particular, States must report to TSA at
www.tsa.gov/real-id/mDL
within 72 hours of discovering a reportable cybersecurity incident. In response to comments to the NPRM seeking clarity on the reporting requirements (
see
Part IV.V.5.c., below), the final rule adds a provision that reportable incidents are those defined in the TSA Cybersecurity Lexicon at
www.tsa.gov
that could compromise the integrity of a certificate system. These requirements must be implemented in full compliance with the references cited in Appendix A: CA/Browser Forum Network and Certificate System Security Requirements; CISA Federal Government Cybersecurity Incident & Vulnerability Response Playbooks;
49
DHS National Cyber Incident Response Plan; NIST SP 800-53 Rev. 5; and NIST Framework for Improving Critical Infrastructure Cybersecurity.
50
Information submitted in response to this section
may
contain SSI, and if so, would be subject to requirements of 49 CFR part 1520. Although the NPRM did not propose the SSI protection provision, TSA evaluated comments to the NPRM (see Part IV.W., below) seeking clarification on SSI protection for other information (State waiver applications) and determined that SSI protection is warranted for State reports under this Appendix paragraph 8, which has been added in this final rule.
49
The NPRM inadvertently omitted “Federal Government” from the title of this publication.
50
See
NPRM, 88 FR at 60062-63 & 60065, for a discussion of these standards.
5. Decisions on Applications for Waiver
Section 37.9(b) establishes a timeline and process for TSA to issue decisions on a waiver application. Under this paragraph, TSA endeavors to provide States a decision on initial applications within 60 calendar days, but not longer than 90 calendar days. TSA will provide three types of written notice via email: approved, insufficient, or denied.
If TSA approves a State's application for a waiver, TSA will issue a certificate of waiver to that State, and include the State in a list of mDLs approved for Federal use, published by TSA on the REAL ID website at
www.tsa.gov/real-id/mDL.
51
A certificate of waiver will specify the date that the waiver becomes effective, the expiration date, and any other terms and conditions with which a State must comply, as provided under § 37.9(d). A State seeking to renew its certificate beyond the expiration date must reapply for a waiver, as provided in § 37.9(e)(6).
51
Section 37.9(b)(1).
If TSA determines that an application is insufficient, did not respond to certain information required in §§ 37.10(a) or (b), or contains other deficiencies, TSA will provide an explanation of such deficiencies and allow the State an opportunity address the deficiencies within the timeframe specified in § 37.9(b)(2). TSA will permit States to submit multiple amended applications if necessary, with the intent of working with States individually to enable their mDLs to comply with the requirements of §§ 37.10(a) and (b).
As provided in § 37.9(b)(3), if TSA denies an application, TSA will provide the specific grounds for the basis of the denial and afford the State an opportunity to submit a new application or to seek reconsideration of a denied application. Under § 37.9(c)(1), States will have 90 calendar days to file a request for reconsideration, and TSA will provide its final determination within 60 calendar days. Instructions for seeking reconsideration are provided by TSA on the REAL ID website at
www.tsa.gov/real-id/mDL.
As provided in § 37.9(c)(2), an adverse decision upon reconsideration would be considered a final agency action. However, a State whose request for reconsideration has been denied may submit a new application for a waiver.
6. Limitations, Suspension, and Termination of Certificate of Waiver
Section 37.9(e) sets forth various terms regarding a certificate of waiver. Specifically, under paragraph (e)(1) of this section, a certificate of waiver is valid for a period of three years from the date of issuance. This period was selected to align with the frequency of States' recertification under § 37.55(b).
Paragraph (e)(2) requires that a State must report to TSA if, after it receives a waiver, it makes significant modifications to its mDL issuance processes that differ in a material way from information that the State provided in its application. If the State makes such modifications, it is required to report such changes, at
www.tsa.gov/real-id/mDL,
60 calendar days before implementing the changes. This requirement is intended to apply to changes that may undermine the bases on which TSA granted a waiver. The reporting requirement is not intended to apply to routine, low-level changes, such as systems maintenance and software updates and patches. States that are uncertain about whether a change would trigger the reporting requirements should contact TSA as directed at
www.tsa.gov/real-id/mDL.
The final rule added this provision to contact TSA to provide greater certainty to States, following TSA's evaluation of public comments seeking clarification about the reporting requirements specified in the NPRM (see Part IV.S., below).
Paragraph (e)(3) requires a State that is issued a waiver to comply with all requirements specified in §§ 37.51(a) and 37.9(d)(3).
Paragraph (e)(4) sets forth processes for suspension of certificates of waiver. As provided in § 37.9(e)(4)(i)(A), TSA may suspend the validity of a certificate of waiver if TSA determines that a State:
• fails to comply with any terms and conditions (
see
§ 37.9(d)(3)) specified in the certificate of waiver;
• fails to comply with reporting requirements (
see
§ 37.9(e)(2)); or
• issues mDLs in a manner that is not consistent with the information the State provided in its application for a waiver under §§ 37.10(a) and (b).
Before suspending a waiver for these reasons, TSA will provide such State written notice via email that it intends to suspend its waiver, along with an explanation of the reasons, information on how the State may address the deficiencies, and a timeline for the State to respond and for TSA to reply to the
State, as set forth in § 37.9(e)(4)(ii). TSA may withdraw the notice of suspension, request additional information, or issue a final suspension. If TSA issues a final suspension of a State's certificate of waiver, TSA will temporarily remove the name of that State from the list, published at
www.tsa.gov/real-id/mDL,
of mDLs approved for Federal acceptance for official purposes.
52
TSA intends to work with States to resolve the conditions that result in a final suspension, and resume validity of that State's waiver. A State receiving a final suspension may apply for a new certificate of waiver by submitting a new application following the procedures in § 37.9(a).
52
Section 37.9(e)(4)(iii).
TSA additionally may suspend a State's waiver at any time upon discovery that Federal acceptance of a State's mDL is likely to cause imminent or serious threats to the security, privacy, or data integrity of any Federal agency, as set forth in § 37.9(e)(4)(i)(B). These are more exigent circumstances than those set forth in § 37.9(e)(4)(i)(A). Examples of such triggering events include cyber-attacks and other events that cause serious harm to a State's mDL issuance systems. If a State discovers a reportable cybersecurity incident, as defined in the TSA Cybersecurity Lexicon available at
www.tsa.gov,
that it believes could compromise the integrity of its mDL issuance systems, paragraph 8.6 of Appendix A requires States to provide written notice to TSA as directed at
www.tsa.gov/real-id/mDL,
of such incident within no more than 72 hours of discovery. If TSA determines such suspension is necessary, TSA will provide written notice via email to each State whose certificate of waiver is affected, as soon as practicable after discovery of the triggering event, providing an explanation for the suspension, as well as an estimated timeframe for resumption of the validity of the certificate of waiver.
Under § 37.9(e)(5)(i), TSA may terminate a certificate of waiver for serious or egregious violations. More specifically, TSA may terminate a waiver if TSA determines that a State:
• does not comply with REAL ID requirements in § 37.51(a);
• is committing an egregious violation of any terms and conditions (
see
§ 37.9(d)(3)) specified in the certificate of waiver and is unwilling to cure such violation;
• is committing an egregious violation of reporting requirements (
see
§ 37.9(e)(2)) and is unwilling to cure such violation; or
• provided false information in its waiver application.
As required in § 37.9(e)(5)(ii), before terminating a certificate of waiver, TSA will provide written notice via email of intent to terminate, including findings supporting the termination and an opportunity for the State to present information. As specified, a State would have 7 calendar days to respond to the notice, and TSA will respond via email within 30 calendar days. TSA may withdraw the notice of termination, request additional information, or issue a final termination. Under § 37.9(e)(5)(iii), if TSA issues a final termination of a State's certificate of waiver, TSA will remove the name of that State from the list of mDLs approved for Federal acceptance for official purposes. A State whose certificate of waiver has been terminated may apply for a new certificate of waiver by submitting a new application.
Section 37.9(g) provides that information provided by States in response to paragraphs (a), (b)(2), (c), (e)(2), (e)(4)(ii), and (e)(5)(ii) of this section, which concern requirements on States to apply for and maintain a waiver,
may
contain SSI and therefore must be handled and protected in accordance with 49 CFR part 1520. Although the NPRM did not propose § 37.9(g), the final rule adds this provision based on TSA's evaluation of comments to the NPRM (see Part IV.W., below) seeking clarification on SSI protection for information in State waiver applications. TSA determined that a provision concerning SSI protection is warranted not only for information in State waiver applications, but also for other information provided by States in response to §§ 37.9(b)(2), (c), (e)(2), (e)(4)(ii), and (e)(5)(ii), which has been added in this final rule.
7. Effect of Status of Waiver on REAL ID Compliance
Section 37.9(f) clarifies that the status of a State's issued certificate of waiver, including the status of a pending application for a waiver, has no bearing on TSA's determination of that State's compliance or non-compliance with any other section of this part. A certificate of waiver that TSA has issued to a State is not a determination that the State is in compliance with any other section in this part. Similarly, an application for a waiver that TSA has deemed insufficient or denied, or a certificate of waiver TSA has suspended or terminated, or that has expired, is not a determination that the State is not in compliance with any other section in this part.
8. Incorporation by Reference
Sections 37.8(b) and 37.10(a) and Appendix A of this final rule provide that States must comply with applicable sections of specified industry standards and government guidelines. The Office of Federal Register (OFR) has published regulations concerning IBR.
53
These regulations require that, for a final rule, agencies must discuss in the preamble to the rule the way in which materials that the agency IBRs are reasonably available to interested persons, and how interested parties can obtain the materials. Additionally, the preamble to the rule must summarize the material.
54
53
1 CFR part 51.
54
1 CFR 51.5(b).
The final rule amends subpart A, § 37.4, by revising the introductory paragraph and adding new IBR material specified below. TSA has worked to ensure that IBR materials are reasonably available to the class of persons affected. All materials may be obtained from their publisher, as discussed below, and certain materials as noted are available in the Federal Docket Management System at
https://www.regulations.gov,
docket number TSA-2023-0002. In addition, all but one of the IBR'd standards (ISO/IEC 18013-5:2021(E), discussed in Part II.D., below) are available to the public for free at the hyperlinks provided, and all are available for inspection on a read-only basis at TSA. Please contact TSA at Transportation Security Administration, Attn.: OS/ESVP/REAL ID Program, TSA Mail Stop 6051, 6595 Springfield Center Dr., Springfield, VA 20598-6051, (866) 289-9673, or visit
www.tsa.gov.
You may also contact the REAL ID Program Office at
REALID-mDLwaiver@tsa.dhs.gov
or visit
www.tsa.gov/REAL-ID/mDL.
55
55
The National Archives and Records Administration (NARA) maintains the official Federal copy of the IBR'd standards, but does not provide or distribute copies.
See www.archives.gov/federal-register/cfr/ibr-locations.htm
(last visited Sept. 17, 2024).
The rule revises the introductory paragraph proposed in the NPRM to clarify availability of IBR materials. Specifically, the final rule replaces DHS with TSA as a location where IBR material is available for inspection, and provides additional points of contact at TSA. TSA also notes that certain material is available in the Federal Docket Management System at
https://regulations.gov,
docket number TSA-2023-0002. The final rule makes these revisions given TSA's evaluation of public comments concerning access to IBR materials (see Part IV.K., below).
The final rule IBRs the following material:
a. American Association of Motor Vehicle Administrators
In September 2022, the American Association of Motor Vehicle Administrators (AAMVA) published
Mobile Driver's License (mDL) Implementation Guidelines Version 1.2
(Jan. 2023) (AAMVA Guidelines), American Association of Motor Vehicle Administrators, 4401 Wilson Boulevard, Suite 700, Arlington, VA 22203, available at
https://aamva.org/getmedia/b801da7b-5584-466c-8aeb-f230cef6dda5/mDL-Implementation-Guidelines-Version-1-2_final.pdf
(last visited July 17, 2024). The AAMVA Guidelines are available to the public for free at the link provided above. The AAMVA Guidelines adapt industry standard ISO/IEC 18013-5:2021(E) (discussed in Part II.D.4., below), for State driver's licensing agencies through the addition of more qualified recommendations, as the ISO/IEC standard has been developed for international purposes and may not meet all purposes and needs of States and the Federal Government. For example, Part 3.2 of the AAMVA Guidelines modify and expand the data elements specified in ISO/IEC 18013-5:2021(E), in order to enable the mDL to indicate the REAL ID compliance status of the underlying physical card, as well as to ensure interoperability necessary for Federal acceptance. AAMVA has added mDL data fields “DHS_compliance” and “DHS_temporary_lawful_status.” These data fields provide the digital version of the requirements for data fields for physical cards defined in 6 CFR 37.17(n)
56
and 6 CFR 37.21(e),
57
respectively. As discussed generally in Part III.C.4, below, §§ 37.10(a)(1) and (4) of this rule require a State to explain, as part of its application for a waiver, how the State issues mDLs that are compliant with specified requirements of the AAMVA Guidelines.
56
Section 37.17(n) provides, “The card shall bear a DHS-approved security marking on each driver's license or identification card that is issued reflecting the card's level of compliance as set forth in § 37.51 of this Rule.”
57
Section 37.21(e) provides, “Temporary or limited-term driver's licenses and identification cards must clearly indicate on the face of the license and in the machine readable zone that the license or card is a temporary or limited-term driver's license or identification card.”
b. Certification Authority Browser Forum
The Certification Authority Browser Forum (CA/Browser Forum) is an organization of vendors of hardware and software used in the production and use of publicly trusted certificates. These certificates are used by forum members, non-member vendors, and governments to establish the security and trust mechanisms for public key infrastructure-enabled systems. The CA/Browser Forum has published two sets of requirements applicable for any implementers of PKI, including States that are seeking to deploy certificate systems that must be publicly trusted and used by third parties:
•
Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates
v.
1.8.6
(December 14, 2022), available at
https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-1.8.6.pdf
(last visited July 17, 2024), establishes a set of fundamental controls for the management of publicly trusted certificate authorities, including the controls and processes required for the secure generation of digital signing keys; and
•
Network and Certificate System Security Requirements
v.
1.7
(April 5, 2021), available at
https://cabforum.org/wp-content/uploads/CA-Browser-Forum-Network-Security-Guidelines-v1.7.pdf
(last visited July 17, 2024), establishes a broad set of security controls needed to securely manage a publicly trusted certificate authority and key infrastructure management system.
CA/Browser Forum, 815 Eddy St, San Francisco, CA 94109, (415) 436-9333. To issue mDLs that can be trusted by Federal agencies, each issuing State must establish a certificate system, including a root certification authority that is under control of the issuing State. TSA believes the CA/Browser Forum requirements for publicly trusted certificates have been proven to be an effective model for securing online transactions. As discussed generally in Part III.C.4, below, Appendix A, paragraphs 1, 2, and 4-8, require compliance with specified requirements of the CA/Browser Forum Baseline Requirements and/or Network and Certificate System Security Requirements.
c. DHS and Cybersecurity and Infrastructure Security Agency
DHS protects the nation from multiple threats, including cybersecurity, aviation and border security, among others. The Cybersecurity and Infrastructure Security Agency (CISA), a component of DHS, is the operational lead for Federal cybersecurity and the national coordinator for critical infrastructure security and resilience. DHS and CISA have published two guidelines which are relevant to the operations of States' mDL issuance systems:
•
DHS, National Cyber Incident Response Plan
(Dec. 2016), available at
https://www.cisa.gov/uscert/sites/default/files/ncirp/National_Cyber_IncidentResponse_Plan.pdf
(last visited July 17, 2024), further standardizes the response process for cyber incidents including the preparation, detection and analysis, containment, eradication and recovery, and post-incident activities. Department of Homeland Security, 2707 Martin Luther King Jr. Ave. SE, Washington, DC 20528; (202) 282-8000; and
•
CISA, Federal Government Cybersecurity Incident & Vulnerability Response Playbooks
(Nov. 2021),
58
available at
https://www.cisa.gov/sites/default/files/publications/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf
(last visited July 17, 2024), was developed consistent with the direction of Presidential Policy Directive 41 (PPD-41) to establish how the U.S. responds to and recovers from significant cyber incidents which pose a risk to critical infrastructure, including the identity issuance infrastructure operated by U.S. States issuing mDLs.
58
The NPRM inadvertently omitted “Federal Government” from the title of this publication.
Cybersecurity and Infrastructure Security Agency, Mail Stop 0380, 245 Murray Lane, Washington, DC 20528-0380, (888) 282-0870. These guidelines, available for free at the links provided above and in the Federal Docket Management System at
https://www.regulations.gov,
docket number TSA-2023-0002, provide details on best practices for management of systems during a cybersecurity incident, providing recommendations on incident and vulnerability response. Management of cybersecurity incidents and vulnerabilities is critical to maintenance of a State's mDL issuance IT infrastructure. As discussed generally in Part III.C.4, below, Appendix A, paragraph 8, requires compliance with specified requirements of the DHS National Cyber Incident Response Plan and the CISA Federal Government Cybersecurity Incident & Vulnerability Response Playbooks.
d. International Organization for Standardization and International Electrotechnical Commission
International standards-setting organizations, the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC),
59
are jointly drafted
international standards specific to mDLs.
60
In September 2021, ISO and IEC published ISO/IEC 18013, Part 5, entitled, “Personal identification—ISO-compliant driving licence.” ISO/IEC 18013-5:2021(E),
Personal identification—ISO-compliant driving licence—Part 5: Mobile driving licence (mDL) application
(Sept. 2021), International Organization for Standardization, Chemin de Blandonnet 8, CP 401, 1214 Vernier, Geneva, Switzerland, +41 22 749 01 11,
www.iso.org/contact-iso.html.
This standard is available for inspection at TSA as discussed above. In addition, TSA is working with the American National Standards Institute (ANSI), a private organization not affiliated with DHS, to add this standard to the ANSI IBR Standards Portal which provides free, read-only access.
61
TSA has participated in the development of these standards as a non-voting member of the United States national body member of the Joint Technical Committee.
62
59
ISO is an independent, non-governmental international organization with a membership of 164 national standards bodies. ISO creates documents that provide requirements,
specifications, guidelines or characteristics that can be used consistently to ensure that materials, products, processes and services are fit for their purpose. The IEC publishes consensus-based international standards and manages conformity assessment systems for electric and electronic products, systems and services, collectively known as “electrotechnology.” ISO and IEC standards are voluntary and do not include contractual, legal or statutory obligations. ISO and IEC standards contain both mandatory requirements and optional recommendations, and those who choose to implement the standards must adopt the mandatory requirements.
60
ISO defines an International Standard as “provid[ing] rules, guidelines or characteristics for activities or for their results, aimed at achieving the optimum degree of order in a given context. It can take many forms. Apart from product standards, other examples include: test methods, codes of practice, guideline standards and management systems standards.”
www.iso.org/deliverables-all.html
(last visited July 17, 2024).
61
ANSI, IBR Standards Portal,
https://ibr.ansi.org/
(last visited July 17, 2024).
62
A member of TSA serves as DHS's representative to the Working Group.
Standard ISO/IEC 18013-5:2021(E) standardizes communications interfaces between an mDL holder and an entity seeking to read an individual's mDL for identify verification purposes, and between a verifying entity and a State driver's licensing agency. This standard also sets full operational and communication requirements for both mDLs and mDL readers. Standard ISO/IEC 18013-5:2021(E) applies to “attended” mode verification, in which both the mDL holder and an officer or agent of a verifying entity are physically present together during the time of identity verification.
63
TSA believes ISO/IEC 18013-5:2021(E) is critical to enabling the interoperability, security, and privacy necessary for wide acceptance of mDLs by Federal agencies for official purposes. Specifically, § 37.8 of this rule requires Federal agencies to validate an mDL as required by standard ISO/IEC 18013-5:2021(E), and § 37.10(a)(4) requires a State to explain, as part of its application for a waiver, how the State issues mDLs that are interoperable with this standard to provide the security necessary for Federal acceptance.
63
Part 7 of Series ISO/IEC 18013, entitled “mDL add-on function,” is an upcoming technical specification that will standardize interfaces for “unattended” mode verification, in which the mDL holder and officer/agent of the verifying agency are not physically present together, and the identity verification is conducted remotely. Unattended identity verification is not currently considered a REAL ID use case. ISO defines a “Technical Specification” as “address[ing] work still under technical development, or where it is believed that there will be a future, but not immediate, possibility of agreement on an International Standard. A Technical Specification is published for immediate use, but it also provides a means to obtain feedback. The aim is that it will eventually be transformed and republished as an International Standard.” ISO, Deliverables,
www.iso.org/deliverables-all.html
(last visited July 17, 2024).
e. National Institute for Standards and Technology
The National Institute of Standards and Technology (NIST), part of the U.S. Department of Commerce, promotes U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways that enhance economic security and quality of life. As part of this mission, NIST produces measurements and standards relied on by the U.S. agencies and industry.
i. Federal Information Processing Standards
NIST maintains the Federal Information Processing Standards (FIPS) which relate to the specific protocols and algorithms necessary to securely process data. This suite of standards includes:
• NIST FIPS PUB 140-3,
Security Requirements for Cryptographic Modules
(March 22, 2019), available at
https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
(last visited July 17, 2024), specifies the security requirements for cryptographic modules that are used to secure the keys which are used in digitally signing mDLs, and properly securing these keys is essential to creating a publicly trusted certificate authority for mDL issuance;
• NIST FIPS PUB 180-4,
Secure Hash Standard (SHS)
(August 4, 2015), available at
https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
(last visited July 17, 2024), specifies the secure hash standard, a cryptographic algorithm necessary to provide message and data element integrity while using the transaction modes specified in ISO/IEC 18013-5:2021(E) for mDL data transmission;
• NIST FIPS PUB 186-5,
Digital Signature Standard (DSS)
(February 3, 2023), available at
https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf
(last visited July 17, 2024), specifies digital signature standards used in ISO/IEC 18013-5:2021(E) standard to provide data integrity for mDL data elements issued by states; and
• NIST FIPS PUB 197-upd1,
Advanced Encryption Standard (AES)
(May 9, 2023) available at
https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.197-upd1.pdf
(last visited July 17, 2024), specifies the Advanced Encryption Standard, which is a cryptographic algorithm used to securely encrypt data messages used in the transmission of mDL data in ISO/IEC 18013-5:2021(E).
Although the NPRM proposed to IBR the prior (2001) version, NIST FIPS PUB 197, the final rule IBRs the current (May 2023) updated version, NIST FIPS PUB 197-upd1, which NIST confirms makes editorial improvements, but no technical changes to the version specified in the NPRM.
64
TSA has reviewed the updates and confirms they are formatting and stylistic clarifications. Although the public had an opportunity to comment, no such comments were received. Given the absence of public comments, no substantive changes to the updated standard, and to ensure continuing public access to this standard, the final rule IBRs the updated version, NIST FIPS PUB 197-upd1, which is consistent with the NPRM's proposal to IBR the previous version. TSA concludes that the compliance impact on stakeholders of both versions of this standard is identical.
64
See https://csrc.nist.gov/News/2023/nist-updates-fips-197-advanced-encryption-standard
(last visited July 17, 2024);
https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.197-upd1.pdf
(last visited July 17, 2024) at 37;
https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.197.pdf
(last visited July 17, 2024) at 1.
• NIST FIPS PUB 198-1,
The Keyed-Hash Message Authentication Code (HMAC)
(July 16, 2008) available at
https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.198-1.pdf
(last visited July 17, 2024), specifies the keyed hash message authentication code which is an essential cryptographic algorithm to create a properly interoperable mDL using ISO/IEC 18013-5:2021(E); and
• NIST FIPS PUB 202,
SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions
(August 4, 2015) available at
https://
nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
(last visited July 17, 2024), specifies the secure hash algorithm 3, a cryptographic algorithm necessary to provide message and data element integrity in ISO/IEC 18013-5:2021(E) for mDL data transmission.
National Institute of Standards and Technology, U.S. Department of Commerce, 100 Bureau Drive, Gaithersburg, MD 20899. This suite of FIPS standards, available in the Federal Docket Management System at
https://www.regulations.gov,
docket number TSA-2023-0002, are critical to the transactions required for mDLs, and any Federal systems which interact with or are used to verify an mDL for REAL ID official purposes will be required to use the algorithms and protocols defined. As discussed generally in Part III.C.4, below, § 37.10(a)(4) requires compliance with specified requirements of NIST FIPS PUB 180-4, 186-5, 197-upd1, 198-1, and 202, and Appendix A, paragraph 5, requires compliance with FIPS PUB 140-3.
ii. Security and Privacy Controls for Information Systems and Organizations; Key Management
NIST has published several guidelines to protect the security and privacy of information systems:
• NIST SP 800-53 Rev. 5,
Security and Privacy Controls for Information Systems and Organizations
(September 2020), available at
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
(last visited July 17, 2024), specifies a broad set of security and privacy controls which states must use to manage the information systems involved in the issuance and management of mDLs;
• NIST SP 800-57 Part 1, Rev. 5,
Recommendation for Key Management: Part 1—General
(May 2020), available at
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf
(last visited July 17, 2024), provides general recommendations for states managing cryptographic keys that are used to securely issue mDLs;
• NIST SP 800-57 Part 2, Rev. 1,
Recommendation for Key Management: Part 2—Best Practices for Key Management Organizations
(May 2019), available at
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt2r1.pdf
(last visited July 17, 2024), provides best practices states must follow while managing cryptographic keys; and
• NIST SP 800-57 Part 3, Rev. 1,
Recommendation for Key Management, Part 3: Application-Specific Key Management Guidance
(January 2015) available at
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf
(last visited July 17, 2024), provides for application specific controls for the management of cryptographic keys.
National Institute of Standards and Technology, U.S. Department of Commerce, 100 Bureau Drive, Gaithersburg, MD 20899. All of these documents are available in the Federal Docket Management System at
https://www.regulations.gov,
docket number TSA-2023-0002.
All four of these standards relate to the administration of a certificate system including: access management; certificate life-cycle policies; operational controls for facilities and personnel; technical security controls; and vulnerability management such as threat detection, incident response, and recovery planning. Due to the sensitive nature of State certificate system processes and the potential for significant harm to security if confidentiality, integrity, or availability of the certificate systems is compromised, the minimum risk controls specified in Appendix A require compliance with the NIST SP 800-53 Rev. 5 “high baseline” as set forth in that document, as well as compliance with the specific risk controls described in Appendix A. In addition, and as discussed generally in Part III.C.4, below: Appendix A, paragraphs 1-8, require compliance with NIST SP 800-53 Rev. 5; paragraphs 1 and 5 require compliance with NIST SP 800-57 Part 1, Rev. 5; paragraph 1 requires compliance with NIST SP 800-57 Part 2 Rev. 1; and paragraph 1 requires compliance with NIST SP 800-57 Part 3, Rev. 1.
iii. Digital Identity Guidelines
NIST has published NIST SP 800-63-3, which covers technical requirements for Federal agencies implementing digital identity: NIST Special Publication 800-63-3,
Digital Identity Guidelines
(June 2017), National Institute of Standards and Technology, U.S. Department of Commerce, 100 Bureau Drive, Gaithersburg, MD 20899, available at
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63-3.pdf
(last visited July 17, 2024)and in the Federal Docket Management System at
https://www.regulations.gov,
docket number TSA-2023-0002.
The
Digital Identity Guidelines
define technical requirements in each of the areas of identity proofing, registration, user authentication, and related issues. Because TSA is not aware of a common industry standard for mDL provisioning that is appropriate for official REAL ID purposes today, TSA views the
Digital Identity Guidelines
as critical to informing waiver application requirements for States regarding provisioning. As discussed generally in Part III.C.4, below, under § 37.10(a)(2) of the final rule, which requires compliance with Appendix A, a State must explain, as part of its application for a waiver, how the State issues mDLs that are compliant with NIST SP 800-63-3 to provide the security for mDL IT infrastructure necessary for Federal acceptance.
NIST has also published Special Publication 800-63B,
Digital Identity Guidelines: Authentication and Lifecycle Management
(June 2017), National Institute of Standards and Technology, U.S. Department of Commerce, 100 Bureau Drive, Gaithersburg, MD 20899, available at
https://nvlpubsnist.gov/nistpubs/specialpublications/nist.sp.800-63b.pdf
(last visited July 17, 2024) and in the Federal Docket Management System at
https://www.regulations.gov,
docket number TSA-2023-0002. This document, which is a part of NIST SP 800-63-3, provides technical requirements for Federal agencies implementing digital identity services. The standard focuses on the authentication of subjects interacting with government systems over open networks, establishing that a given claimant is a subscriber who has been previously authenticated and establishes three authenticator assurance levels. As discussed generally in Part III.C.4, below, § 37.10(a)(2) of this rule requires compliance with Appendix A, which requires a State to explain, as part of its application for a waiver, how the State manages its mDL issuance infrastructure using authenticators at assurance levels provided in NIST SP 800-63B.
iv. Framework for Improving Critical Infrastructure Cybersecurity
NIST has published
Framework for Improving Critical Infrastructure Cybersecurity
v.
1.1
(April 16, 2018), National Institute of Standards and Technology, U.S. Department of Commerce, 100 Bureau Drive, Gaithersburg, MD 20899, available at
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
(last visited July 17, 2024). This document, available in the Federal Docket Management System at
https://www.regulations.gov,
docket number TSA-2023-0002, provides relevant information for cybersecurity for States issuing mDLs. As discussed generally in Part III.C.4, below, certain requirements from the NIST Framework for Improving
Critical Infrastructure Cybersecurity have been adopted in Appendix A, paragraphs 1, 2, and 5-8.
D. Impacted Stakeholders
This final rule applies to State driver's licensing agencies issuing mDLs that seek a temporary waiver from TSA for its mDLs. The waiver established by this rule enables Federal agencies to accept such mDLs for official purposes, defined in the REAL ID Act as accessing Federal facilities, entering nuclear power plants, boarding Federally regulated commercial aircraft, and any other purposes that the Secretary shall determine. Any Federal agency that chooses to accept mDLs for official purposes must procure a reader in order to receive an individual's identity data.
This final rule does not apply to:
• States that do not seek a waiver for mDLs;
• Non-State issuers of other forms of digital identification; or
• Federal agencies that elect not to accept mDLs.
A State seeking a waiver for Federal acceptance of its mDLs for official purposes is required to file with TSA a complete application and supporting documents.
65
A State must demonstrate how its mDLs meet the requirements for a waiver set forth in §§ 37.10(a) and (b) when completing the application.
65
Section 37.9(a).
E. Use Cases Affected by This Rule
This final rule applies only to Federal acceptance of mDLs for official purposes, defined by the REAL ID regulations as accessing Federal facilities, entering nuclear power plants, and boarding Federally regulated commercial aircraft. Any other purpose is beyond the scope of this rulemaking. For example, a waiver issued under this rule does not apply to any of the following:
• mDL acceptance by Federal agencies for non-REAL ID official uses (
e.g.,
applying for Federal benefits);
• mDL acceptance by non-Federal agencies (
e.g.,
State agencies, businesses, private persons);
• Commercial transactions; or
• Physical driver's licenses or identification cards.
Nothing in this rule
requires
Federal agencies to accept mDLs, as each Federal agency retains the discretion to determine its identification policies. Additionally, nothing in this rule
requires
a State to seek a waiver or issue mDLs.
F. Severability
TSA notes that these changes impact multiple provisions that are not necessarily interrelated and can function independent of one another. As such, TSA believes that some of the provisions of each new part can function sensibly independent of other provisions. Therefore, in the event that any provisions in this rulemaking action as finalized are invalidated by a reviewing court, TSA intends remaining provisions to remain in effect to the fullest extent possible.
IV. Discussion of Comments
TSA published the NPRM on August 30, 2023,
66
and the deadline for public comments was October 16, 2023. TSA received 31 comments,
67
including some comments that were submitted shortly after the comment period closed. TSA carefully considered every comment received as part of the official record, including those that were submitted late. Comments and TSA's responses are as summarized by topic below.
66
See
88 FR 60056.
67
The 31 total comments include one duplicate, one correction, and one confidential submission.
A. Waiver Eligibility
Comments:
Several State driver's licensing agencies, an association, and some vendors expressed concerns that under §§ 37.7(b)(3) and 37.10(a)(1)(vii) of the NPRM, TSA would issue waivers to States that issued mDLs only to holders of REAL ID-compliant physical cards, but a State that issues mDLs to two groups of individuals—both holders of REAL ID-compliant AND non-compliant physical cards—would be ineligible for a waiver because of issuance to the latter group. Stated differently, a State's issuance of mDLs to holders of non-compliant physical cards alone would remove the State's eligibility to apply for a waiver.
Another commenter requested clarification regarding whether a State may still apply for and receive a waiver after enforcement of the REAL ID Act and regulations begins on May 7, 2025.
TSA Response:
TSA agrees with commenters and is revising the final rule to clarify that a State will not be excluded from eligibility to apply for a waiver if a State issues mDLs to both REAL ID compliant and non-compliant physical cardholders. The intended purpose of TSA's requirement is for States to ensure that an individual's mDL matches the compliance status of the underlying physical card, and for States to issue an mDL in a manner that enables a verifying Federal agency to confirm the underlying physical card's REAL ID compliance status.
Consistent with that intent, and to address commenters' concerns, the final rule makes three changes to the NPRM. First, this final rule deletes § 37.7(b)(3), as proposed by the NPRM, which provided as a criterion of waiver eligibility that a State must issue mDLs only to individuals who have been issued REAL ID-compliant physical cards.
Second, the final rule deletes a similar requirement from § 37.10(a)(1)(vii), as proposed by the NPRM, which provided that States must issue an mDL only to a resident who has been issued a valid, unexpired, and REAL ID-compliant physical card that underlies the mDL. The final rule modifies this provision to require States to populate this data field to correspond to the REAL ID compliance status of the underlying physical driver's license or identification card that a State has issued to an mDL holder. Specifically, § 37.10(a)(1)(vii)(A) requires mDL data element “DHS_compliance” to be populated with “F” if the underlying card is REAL ID-compliant, or as required by the AAMVA Guidelines,
68
Section 3.2. In addition, § 37.10(a)(1)(vii)(B) requires mDL data element “DHS_compliance” to be populated “N” if the underlying card is not REAL ID-compliant.
68
The AAMVA Guidelines require, among other things, that if the `EDL_credential' element is present, the `DHS_compliance' element shall have a value of “F.”
Third, the final rule adds new § 37.8(c), which requires Federal agencies to confirm that the physical card underlying the mDL is REAL ID-compliant, as Federal agencies will only be permitted to accept mDLs if the underlying card is REAL ID-compliant. Federal agencies would make that determination by reviewing data element “DHS_compliance” and confirming that it has been marked “F.” These changes ensure—without compromising a State's waiver eligibility—that an individual's mDL matches the compliance status of the physical card, and that Federal agency will accept only those mDLs that are based on a REAL ID-compliant underlying physical card.
Separately, in response to the commenter's question regarding waiver applications after REAL ID enforcement begins on May 7, 2025, TSA confirms that a State indeed may apply for and receive a waiver after enforcement begins.
B. Conditions on Federal Agencies Accepting mDLs
Comments:
An association requested clarification concerning requirements
on Federal agencies that choose to accept mDLs. Specifically, the commenter noted that the preamble provided that one of the “conditions for TSA acceptance” is that TSA has determined the mDL issuing State is REAL ID-compliant. The commenter sought clarification on the timing of when this compliance determination is made, specifically, whether this is a one-time determination, whether it is made at the time when TSA is reviewing a State's application, or if the State's re-certification schedule is applicable.
TSA Response:
First, TSA notes that this rule does not set conditions only for “TSA Acceptance.” Instead, the rule sets forth requirements for all Federal agencies who choose to accept mDLs for official purposes as defined in the REAL ID Act. Second, TSA clarifies that determination of a State's REAL ID compliance status is not a requirement for other Federal agencies to make. The only conditions on Federal agencies who accept mDLs are set forth in § 37.8, which requires the agency to: (1) confirm the State holds a valid waiver by reviewing the specified TSA website, (2) use an mDL reader to communicate with and validate an individual's mDL, (3) confirm that the underlying physical card is REAL ID-compliant, and (4) notify TSA within 72 hours of the discovery of specified security, privacy, or data integrity threats. A State's compliance status is an element of a State's eligibility to apply for a waiver, as set forth in § 37.7(b)(1), and TSA will make this determination when reviewing a State's application. However, TSA acknowledges that the preamble to the NPRM states that a Federal agency must make this compliance determination. TSA has revised the preamble to this final rule to reflect the intended requirements.
In response to comments, TSA also provides further clarification on the timing of its determination of a State's compliance status. TSA will make an initial determination of State compliance status at the time of application, but this is
not
a one-time determination. States have a continuing obligation, under 6 CFR 37.55(b), to maintain their compliance status by recertifying compliance every 3 years, an obligation which continues throughout the duration of the waiver. If recertification occurs after a State is issued a waiver and TSA determines the State is no longer in compliance, the waiver may be subject to review pursuant to § 37.9(e)(5).
C. Waiver Application Criteria
1. Personally Identifiable Information and Privacy
Comments:
An association remarked that § 37.10(a)(1)(i) introduces additional requirements concerning individuals' Personally Identifiable Information (PII) that are not related to mDL issuance and exceed existing requirements in the regulations. The commenter advised that the rule should not expand REAL ID requirements that are unrelated to mDLs.
The association further noted that although privacy is an important concept, it applies mostly to the agreement between an issuing State and the mDL holder, and that the only applicability to verifying Federal agencies is ensuring that the agency receives only the information necessary for identity verification. The commenter therefore recommended updating § 37.10(a)(3) so that States are only required to provision mDLs to digital wallets in a manner that will release only the data requested by the verifier. Additional privacy requirements, the commenter submitted, while important to individuals and States, may not affect verifying agencies.
TSA Response:
Sections 37.10(a)(1)(i) and (a)(3) of this rule extend to mDLs PII protections that are analogous to those in the existing regulations regarding physical cards. This rule is adding mirroring PII provisions because mDLs involve a new data set and additional elements that must be protected, which are not addressed in the current regulations. Section 37.10(a)(1)(i) requires encryption of PII, and § 37.10(a)(3) requires an explanation of the means used to protect PII during processing, storage, and destruction of mDL records and provisioning records. Nothing in this final rule modifies or imposes new requirements regarding physical cards. While TSA concurs that there is a privacy interest between individuals and States, verifying Federal agencies have an equally important privacy interest in trusted mDL transactions.
2. Provisioning
Comments:
An association contended that although the intended goal of §§ 37.10(a)(1)(iii)-(vi) is the step of “binding,” which means ensuring that an mDL is provisioned to the correct mDL holder's device, binding has no value to verifying Federal agencies, other than copy protection, at the time of identity verification. The association questions, therefore, the need for these requirements.
TSA Response:
“Binding,” a critical step in mDL provisioning, refers to the process where the issuing State binds, or pairs, the mDL data to a specific device through the generation of the device key and signing of the mobile security object. Binding is critically important to all stakeholders involved in an mDL transaction, including verifying Federal agencies, as they share a strong interest in a secure, trusted mDL ecosystem in which identity data is protected during mDL provisioning, provided only to the rightful holder of the data, bound to that holder's device, and resists cloning to other devices unless approved by the issuing State. Section 37.10(a)(1) sets forth requirements for provisioning, and the requirements specified in § 37.10(a)(1)(iii)-(vi) provide the requisite security and privacy protections to achieve secure binding. The TSA Waiver Guidance also sets forth recommendations for provisioning and binding. To clarify the relationship between provisioning and binding, the final rule adds a new definition to § 37.3 for “provisioning.”
3. AAMVA mDL Implementation Guidelines
Comments:
AAMVA noted that § 37.10(a)(4) refers to version 1.1 of the AAMVA Guidelines, conflicting with § 37.4, which incorporates by reference version 1.2 of this document.
TSA Response:
TSA agrees that § 37.10(a)(4) of the NPRM inadvertently listed version 1.1, instead of version 1.2, of the AAMVA Guidelines. TSA notes that the NPRM correctly cited version 1.2 in all other instances
69
where it referenced the AAMVA Guidelines, and only made a typographical error to version “1.1” in a single instance, in § 37.10(a)(4). TSA did not receive any comments to the contrary. Accordingly, the final rule has made a technical correction in § 37.10(a)(4) to address this typographical error and correctly refer to version 1.2.
69
See
88 FR 60056, 60062, 60068, 60071, 60085, & 60087 (Aug. 30, 2023).
4. Resident Address Data Element
Comments:
AAMVA submitted that § 37.10(a)(4)(i) of the NPRM characterizes the “resident_address” data element as “optional,” despite that the AAMVA Guidelines define this data element as mandatory.
TSA Response:
TSA clarifies that the “resident_address” data element required in § 37.10(a)(4)(i) refers to the data element as defined in the ISO/IEC 18013-5:2021(E) standard namespace “org.iso.18013.5.1,” not any data
elements defined in the AAMVA Guidelines. The use of the term “optional” in § 37.10(a)(4)(i) reflects ISO/IEC's designation of that data element as defined in ISO/IEC 18013-5:2021(E). For clarification, despite ISO/IEC's designation of “resident_address” as an “optional” data field in ISO/IEC 18013-5:2021(E), § 37.10(a)(4)(i) of this final rule mandates inclusion of that data field.
D. TSA Waiver Application Guidance
Comments:
An association recommended that the TSA Waiver Guidance should include references to the corresponding sections of the rule. The association further recommended that the documents incorporated by reference in § 37.4 should be moved to the Guidance to facilitate efficient updates as new standards are published. A State noted that the Guidance was not available at the website specified in § 37.10(c).
TSA Response:
TSA agrees that the Guidance would be more helpful if it references the applicable provisions in the final rule to which the Guidance applies. The Guidance has been revised to specifically include the corresponding regulatory provisions where possible. TSA appreciates the commenter's perspective and this opportunity to provide clarity to the public and stakeholders.
Regarding the recommendation to move the standards from § 37.4 to the Guidance to reflect updated or newly-published standards, TSA notes that the Guidance is non-binding and does not establish any legally enforceable requirements. All security measures, practices, and metrics set forth are simply illustrative, non-exclusive examples for States to consider as part of their overall strategy to address the requirements under § 37.10(a). Any legally enforceable requirements must be set forth in regulatory text. Moreover, as provided in § 37.10(c), TSA may update this Guidance as necessary to provide additional information or address evolving threats to security, privacy, or data integrity.
TSA also clarifies that the Guidance was available during the comment period at the public rulemaking docket at
www.regulations.gov,
and continues to be available. The website specified in § 37.10(c), and throughout the rule, was under development at the time of the NPRM but is now live.
E. General Concerns About mDLs
Comments:
Some public interest organizations posited that public demand for mDLs is “non-existent” and “conjectural.” However, some States disagreed. One State commented that it has issued more than 200,000 mDLs to residents following a pilot in 2017 and more recent expansion in 2022 and 2023. Another State commented that in the 3 months since it began offering its mDL app, it has been downloaded more than 7,000 times. Other commenters questioned the claimed mDL benefits concerning security, privacy, consumer protection, contact-free hygiene, among others, with one commenter opining that any such benefits would be realized only by those with the financial and technical means to purchase mobile devices that meet the specifications in the proposed rule. Some commenters further noted that mDLs would increase the vulnerability of driver's licensing agency databases to cyberattacks.
However, other commenters believe mDLs provide potential security and privacy benefits. One industry vendor commented that the rule would strengthen mDL integrity and security, which the commenter believes is critical to mDL holders and verifying entities. The commenter specifically noted that unlike physical cards, which require an agency's verifying officer to have specialized knowledge of potentially “hundreds” of different card designs of 56 issuing jurisdictions, the electronic safeguards built into mDLs obviate the need for such knowledge. The commenter further opined that mDLs provide privacy protections by empowering the mDL holder to control precisely what information is shared and with whom.
TSA Response:
TSA disagrees that public demand for mDLs is weak. As discussed in Part II.C.2., above, TSA understands that more than half of all 56 issuing jurisdictions are considering or issuing mDLs, and this number continues to increase. Indeed, TSA notes that some States submitted comments disagreeing about the purported lack of demand for mDLs.
Regarding potential benefits of mDLs, TSA continues to believe that mDLs provide potential benefits, including security, privacy, efficiency, and contact-free hygiene, as discussed further in the NPRM.
70
TSA has directly observed some of these benefits through its ongoing mDL testing at airport checkpoints (discussed in Part II.C.2, above). In addition, as discussed above, some commenters agreed with TSA's view that mDLs provide potential security and privacy benefits.
70
See
88 FR at 60062.
TSA disagrees that the rule effectively requires the purchase of smartphones that are costly or technologically complex, which commenters contend would limit potential mDL benefits only to those with financial and technical means. The potential benefits of mDLs can be realized using nearly any smartphone available today. The only technical requirements for such devices, as a result of this final rule, are a smartphone that employs Bluetooth Low Energy and has secure hardware capability to protect the device key associated with the mDL. These technologies are widely available on most smartphones.
With respect to concerns that mDLs introduce new cyber vulnerabilities, TSA continues to believe that the minimum security requirements set forth in this rule would minimize the potential for harm resulting from such threats. As discussed in Part III.C.4.iii above, cyber threats are diverse and evolving, and TSA intends to address them by updating its Waiver Application Guidance as necessary. Some commenters agreed that this rulemaking would improve mDL security and the ability to resist cyber threats. An advocacy group shared that some States and industry today are using non-standardized technological approaches with wide substantive variances in security methodologies, thereby making some mDLs susceptible to fraud and privacy intrusions. The commenter noted that the proposed rule would overcome those concerns by providing standardized approaches to protect security and privacy.
F. Scope of Rulemaking and mDL Acceptance
Comments:
An association opined that mDLs could provide benefits to Federal agencies beyond the uses discussed in the proposed rule. Specifically, the association noted that the Departments of State and Transportation could accept mDLs to improve issuance of passports and commercial driver's licenses, respectively. The commenter also sought clarification on how mDL acceptance, and REAL ID broadly, will be operationalized at TSA, both today and when enforcement of the REAL ID Act begins.
One State recommended that the definition of mDLs in the proposed rule be expanded to include Enhanced Driver's Licenses and Enhanced Identification Cards (collectively “Enhanced Driver's Licenses” or “EDLs”).
TSA Response:
TSA reiterates that the final rule applies only to Federal acceptance of mDLs for official purposes, defined by the REAL ID Act regulations as accessing Federal facilities, entering nuclear power plants,
and boarding Federally regulated commercial aircraft. Any other purpose is beyond the scope of this rulemaking.
TSA further notes that each Federal agency that chooses to accept mDLs for official purposes must build its infrastructure, train its workforce, and operationalize mDL acceptance. Each Federal agency has the discretion to determine its own policies concerning acceptable IDs for access to their facilities, and for communicating this information to the public. TSA advises that questions concerning individual Federal agency identification policies and operational details should be directed to the appropriate program offices of individual agencies.
Regarding EDLs, the definition of “mDL” does not require modification because EDLs comply with REAL ID standards (despite that they are not governed by the REAL ID Act).
71
For that reason, this rule makes clear that mDLs issued based on EDLs will be accepted by Federal agencies under the waiver process. Indeed, the AAMVA Guidelines (incorporated by reference; see § 37.4) similarly treat EDLs as synonymous with REAL ID-compliant driver's licenses, requiring that States encode EDL-based mDLs as REAL ID-compliant. To confirm that States properly encode an EDL as REAL ID-compliant, § 37.10(a)(1)(vii)(A) of this final rule requires States to populate the “DHS_compliance” data element with “F,” indicating REAL ID-compliant, as required by the AAMVA Guidelines (
see
Part IV.A., above). This ensures that a Federal officer verifying an EDL-based mDL will correctly identify the REAL ID compliance status of the underlying EDL. TSA appreciates the commenter's perspective and this opportunity to provide clarity to stakeholders.
71
EDLs are governed by the Western Hemisphere Travel Initiative. As explained in the 2008 Final Rule, DHS worked closely with States to ensure that EDLs would comply with REAL ID standards. 73 FR 5272, 5276 (Jan. 29, 2008). Some States mark EDLs as REAL ID compliant on the front of the card.
G. Privacy
Comments:
Several public interest organizations expressed concerns that this rulemaking would establish a national digital ID that Federal agencies could use in wide ranging circumstances and purposes. They suggested that this type of ID could lead to sharing of data between State driver's licensing agencies and Federal agencies, producing serious harms to privacy and security, particularly for immigrant communities. Immigrants, the commenters argue, could suffer because many States are issuing non-compliant cards to them, and this rule could influence States to share with Federal agencies information provided in immigrant applications, potentially resulting in deportation.
Other public interest organizations noted that the proposed rule would facilitate tracking and surveillance because the rule requires “installation of a government app on a mobile device of a certain type.” An organization further suggested that it be allowed to view source code for these apps in order to learn their true intent. Commenters recommended that the rule should not go forward without additional privacy safeguards, noting that standard ISO/IEC 18013-5:2021(E) is not sufficient.
TSA Response:
In the REAL ID Act, Congress established minimum standards for the issuance of State-issued driver's licenses and identification cards acceptable for official Federal purposes. Neither the Act nor implementing regulations, 6 CFR part 37, contemplate the creation of a sole national identification card or Federal database of driver's license information. Under the statute, the official purposes for Federal agency acceptance of mDLs relate to identity verification, and Congress neither created nor authorized a national identification card. Each individual licensing jurisdiction continues to issue its own unique licenses, maintain its own records, and control access to those records and the circumstances under which access may be provided. In addition, States continue to have full discretion to issue driver's licenses that are non-REAL ID compliant, or to issue dual classes of compliant and non-compliant cards, which some States are doing. States also have full discretion to choose not to issue mDLs at all. The REAL ID Act does not prevent compliant States from issuing driver's licenses and identification cards where the identity of the applicant cannot be assured or for whom lawful presence is not determined. This rule does not intend to interfere with existing State laws that are designed to protect driver's licensing agency data from being shared and used to enforce Federal immigration laws.
Nothing in this final rule requires a Federal agency to accept mDLs. Agencies that choose to do so will receive mDL user information only with the individual's consent, and individuals will control access and use of the mDL in their mobile devices. For example, in TSA mDL testing at airport security checkpoints, passengers present their mDLs to TSA, which uses an mDL reader to establish a secure communications channel with the passenger's mobile device to receive the passenger's mDL data. TSA's mDL readers are programmed to request access only to the relevant data needed for identity verification, which TSA cannot receive unless the passenger provides consent. Upon consent, the passenger's mobile device releases the mDL data to TSA, which automatically validates the authenticity of the information by confirming the digital signature of the issuing State driver's licensing agency (
see
discussion in Part II.C.1., above). TSA emphasizes that it receives passenger data
only
from the passenger's mobile device, and not from the issuing State driver's licensing agency. Although TSA does communicate with a driver's licensing agency, this is solely to receive the agency's private key for data validation purposes—not identity verification. TSA further emphasizes that it never communicates with driver's licensing agencies information regarding the locations or instances of passengers' mDL use. The passenger's PII is used in the same manner that biographic information from physical IDs is used. The PII that is collected from the mDL, along with the live photo taken by TSA, is overwritten when the next passenger scan occurs or when TSA switches off its ID scanner, whichever occurs first.
An mDL offers additional privacy and security benefits over physical IDs. An mDL transmits only the necessary information requested by TSA, rather than sharing all data elements found on a physical ID, and requires user's consent. All mDL data is encrypted at rest, during transfer, and during all transactions through secure channels. Nothing in this rule mandates that individuals must install a “government” app or any type of app at all. Nothing in this rule requires individuals to use a mobile device of any type, or to choose to receive an mDL at all. TSA appreciates the opportunity to provide a detailed explanation of the privacy protections conferred by mDLs. Additional information can be found in DHS's Privacy Impact Assessment
72
concerning privacy risks in the use of digital IDs in the identity verification process at TSA airport security checkpoints.
72
See
DHS, Privacy Impact Assessment for the Travel Document Checker Automation—Digital Identity Technology Pilots,
www.dhs.gov/sites/default/files/2022-01/privacy-pia-tsa051-digitalidentitytechnologypilots-january2022_0.pdf
(last visited July 17, 2024).
H. Waiver Validity Period and Renewals
Comments:
An industry vendor sought clarification on whether a waiver is valid until revoked or for a defined period. An association urged that the
validity period of a waiver should be long enough such that States are not frequently submitting applications for renewals and awaiting determinations, and that the period should cover both waiver applications and State re-certifications. The association further submitted that TSA should consider a grace period to allow a waiver to remain valid for some period after the Phase 2 rule is effective. A State sought clarification of requirements for renewing a waiver if the subsequent Phase 2 rulemaking does not commence within 3 years of publication of this final rule in order to assess the resources required to prepare the renewal application. A vendor sought clarification regarding whether a new audit report is required for renewal applications if a State uses the same issuance vendors for both the initial and renewal applications.
TSA Response:
Under § 37.9(e)(1), a waiver will be valid for three years from date of issuance unless suspended or terminated under §§ 37.9(e)(4) or (5). As discussed in Part III.C.6., above, this rule specifies a three-year waiver validity period because it aligns with the frequency for States to re-certify compliance with § 37.55(b). TSA believes this period is sufficient given the expedient timeframes specified in § 37.9(b) for TSA to respond to applications. As set forth therein, TSA will provide: an initial decision on applications within 60-90 calendar days, replies to States responses to notices of insufficiency within 30 calendar days, and determinations on petitions for reconsideration within 60 calendar days. These timeframes resist the commenter's concern about potentially being trapped in an enduring cycle of submitting renewal applications and waiting extensive period for TSA responses. Moreover, the three-year waiver validity period equals the three-year frequency of States to recertify compliance required by § 37.55(b), as the commenter notes.
Regarding the timing of the Phase 2 rulemaking and the need for a grace period, § 37.9(e)(6) specifies requirements for States that seek to renew waivers beyond the validity period. Renewal provides a mechanism for waivers to persist independent of the timing of future rulemakings, which obviates the need for a grace period.
With respect to audit reports for renewal applications, TSA confirms that States must submit an audit report for renewals, regardless of a State's mDL issuance vendors or system changes. Regarding the resources required for renewal applications, TSA assumes such audit costs for subsequent waiver applications will remain the same as the audit for the initial application, but TSA does estimate a 25 percent to 70 percent reduction in the renewal application cost because the State would have gained experience and collected evidence from the previously approved waiver application.
73
The processes to renew a waiver are identical to those set forth in § 37.9 for initial applications.
73
States with an established mDL program will incur a 45-hour time burden to complete an mDL waiver reapplication, down from a 60-hour time burden for the initial mDL waiver application (25 percent reduction). States without an established program may experience a 70 percent reduction in the time to complete a waiver reapplication compared to the initial mDL waiver application (from 140 hours to 45 hours).
See
§ 2.4.1 of the Regulatory Impact Analysis.
I. Vendor and Technology “Lock-in” Effects
Comments:
Some public interest organizations commented that the NPRM would promote a “lock-in” effect, in which certain technologies and vendors would gain a durable competitive advantage that would be difficult for competitors to overcome. In particular, the commenters expressed concern that markets for digital wallets and mDL readers are likely to be harmed because of the rule's reliance on standards such as ISO/IEC 18013-5:2021(E), which the commenters believe create security, privacy, and interoperability risks. According to the commenters, digital wallets and other necessary mDL technology should be based on open standards.
TSA Response:
TSA is currently testing mDLs issued by seven States who are partnering with multiple providers of digital wallets. One provider, SpruceID, is based on an open-source toolkit for developing decentralized IDs.
74
Additional digital wallet providers are expected to enter the market in the near-term, and States are expected to partner with them and seek to test their mDLs with TSA. The rule provides States broad discretion to select technology vendors of their choice, and does not prescribe any specific type of technology. This absence of prescriptive requirements is intentional, as it accommodates innovation and organic demand from consumers to facilitate technological diversity.
74
See generally
SpruceID,
https://spruceid.com/products/issuing-digital-ids
(last visited July 17, 2024).
The final rule resists technology lock-in by providing minimum standards for security, privacy, and interoperability, while remaining technology-agnostic. The ISO/IEC 18013-5:2021(E) standard enables the required interoperability for REAL ID use cases where mDL holders present their mDLs in person to an mDL reader. Adhering to this standard for interoperability does not harm the developers of digital wallets or readers because the standard does not prohibit other standards or technologies from working alongside the ISO/IEC 18013-5:2021(E) standard. Indeed, California is pursuing this approach with SpruceID. The California mDL digital wallet, built on the open-source SpruceID toolkit, supports both ISO/IEC 18013-5:2021(E) requirements and an alternative technology, known as TruAge®, which allows the mDL to be used in broader transactions, such as age-verified purchases.
75
TSA recognizes that in a broad sense, there may be a false “lock-in” effect of certain types of mDLs, namely, those that meet the waiver application criteria set forth in the rule. However, this is not a true lock-in in the traditional sense of economic path dependence, in which barriers prevent innovation and deployment of equal or potentially superior alternatives. The rule requires States to demonstrate that they issue mDLs that provide security, privacy, and interoperability necessary for Federal acceptance for official purposes, but also allows States and industry wide latitude to innovate as necessary to meet the regulatory requirements.
75
See
State of California Department of Motor Vehicles, TruAge Age-Verified Purchasing,
https://www.dmv.ca.gov/portal/ca-dmv-wallet/truage/
(last visited July 17, 2024).
As structured, this rule does not create dependencies on specific vendors, systems, or technologies. Instead, the rule facilitates development of more secure, privacy enhancing, and interoperable mDLs using technology-agnostic solutions. Accordingly, this rule resists the risk of true technology lock-in that otherwise may have occurred if market participants select technologies, developed by first-movers, that lack the protections necessary for Federal acceptance for official purposes.
J. Pseudonymous Validation and On-Device Biometric Matching
Comments:
An individual urged that it is critical to support “pseudonymous validation” under standard ETSI TR 119 476. In addition, the commenter argued that mDL transactions should support biometric matching on the mobile device itself to avoid sharing biometric data. The commenter claimed these recommendations are necessary to avoid becoming “an autocratic state.”
TSA Response:
“Pseudonymous validation” is the concept of using a pseudonym or alias to identify an
individual without revealing that person's true identity. Although this may provide valuable privacy protection in some uses, it also enables an individual to operate under a consistent—but false—identity. This is contrary to the REAL ID Act and regulations' purpose of improving the security of State-issued identity cards.
On-device biometric sharing is the subject of standards ISO/IEC 23220-5 and ISO/IEC 23220-6, which are currently in development. TSA is not aware of any currently published standards enabling the establishment of trusted on-device biometric matching in the mDL ecosystem, which makes it premature to require such functionality in the final rule.
K. Access to Standards
Comments:
A public interest organization contended that the NPRM failed to provide adequate access to the 19 standards incorporated by reference in the proposed rule. Specifically, the commenter noted that under the NPRM, “the only way” for the public to gain access was to email a request to the address specified in the rule. The commenter noted that it sent multiple emails to this address, but never received a response. The commenter also noted that the NPRM directed individuals to visit “DHS headquarters in Washington DC” but did not provide a specific address.
Other public interest organizations asserted that NPRM failed to provide reasonable access to ISO/IEC 18013-5:2021(E) without a substantial fee. A commenter noted that the ANSI link providing free access to the standard was not helpful, and that attempts “to even load the standards on a modern computer failed completely.” Further, the commenter stated that ANSI required “an unnecessarily onerous process,” which required signing up for an account and completing an online license agreement form, and that access was on a view-only basis.
TSA Response:
TSA regrets that the commenter's multiple emails seeking access were not answered. However, TSA notes that the NPRM specified multiple mechanisms for the public to access the standards, consistent with IBR requirements specified by the OFR.
76
All but one of the 19 standards incorporated by reference in § 37.4 are available to the public for free download, and the NPRM provided the website addresses to access each of these documents. In addition, the NPRM provided detailed information for the publisher of each of these standards, including most, if not all, of the following: publisher name, address, phone, email, and website. For the sole standard that is not publicly available for free, ISO/IEC 18013-5:2021(E), the NPRM facilitated free access via ANSI, a private organization with whom TSA has no affiliation. The NPRM specifically noted that ANSI's policy required individuals to complete an online license agreement form asking for only name, professional affiliation, and email address. The NPRM also stated that access would be available on a view-only basis, and provided publisher information for individuals who sought a greater level of access. TSA received many comments discussing the 19 standards, demonstrating that the NPRM provided sufficient notice regarding access to these standards.
76
See
1 CFR 51.5(a); Office of Federal Register, Incorporation by Reference Handbook (June 2023, rev'd Aug. 28, 2023),
http://www.archives.gov/federal-register/write/handbook/ibr/
(last visited July 17, 2024) [hereinafter “IBR Handbook”].
Although the NPRM provided sufficient notice to access the standards, the final rule modifies access instructions in existing § 37.4 to clarify and provide additional means for access. Specifically, the final rule replaces DHS with TSA as a location where IBR material is available for inspection and provides additional points of contact at TSA. The final rule also specifies that certain IBR material is available in the Federal Docket Management System at
https://www.regulations.gov,
docket number TSA-2023-0002.
L. Standards and Standards Development Generally
Comments:
Several commenters sought clarification on how TSA would update the final rule to reflect evolving industry standards and government guidelines. Commenters suggested that instead of incorporating by reference a specific version of a document, the rule should require compliance with the “most recent version.” Some commenters requested specificity regarding the process and timeframes given to States to conform to any updated standards.
Other commenters questioned the validity of the standards-development processes followed by ISO/IEC, AAMVA, and others. Commenters asserted that these bodies are secretive, unaccountable to the public, have onerous membership criteria, are influenced by foreign authoritarian governments, among other deficiencies.
Some commenters asserted that the documents incorporated by reference in § 37.4 of the proposed rule were insufficient because they provided only partial requirements to address security and operational issues. Commenters also criticized some of the references for their absence of protections to address: emerging threats from quantum computing, evolving risks from digital identification, outdated encryption algorithms, and digital wallet design, user experience, among other deficiencies.
TSA Response:
Under applicable legal requirements, Federal agencies must seek approval from the OFR for a specific version, edition, or date of a publication that an agency seeks to IBR in a final rule.
77
Revisions or updates to a publication already IBR'd in a final rule require re-approval from the OFR, and rules therefore do not update “dynamically” to reflect future versions.
78
Therefore, the rule cannot exclude publication version or date information, or update dynamically to reflect future versions. States will be expected to comply with the standards as published in the final rule. TSA actively monitors evolving standards and guidelines, and may consider whether to IBR those publications (pending review of the final documents) through subsequent rulemaking.
77
See
1 CFR 51.5(b) & 51.9; IBR Handbook,
http://www.archives.gov/federal-register/write/handbook/ibr/.
78
See
IBR Handbook,
http://www.archives.gov/federal-register/write/handbook/ibr/.
Regarding criticisms of standards-development bodies and their deliberations generally, the standards development process for international technology standards, particularly those intended to be interoperable globally, is developed by membership-based bodies comprised of interested parties representing participants from international governmental entities, educational organizations, research groups, non-profit organizations, commercial entities, and the public at large. Each standards-development organization sets its own criteria for membership, fees, standards development processes, and publication structure.
With respect to the criticism that the chosen standards and guidelines provide insufficient protections and lack future-proofing to address unknown threats, TSA notes that due to the nature of innovation and evolving technology, and legal constraints of Federal rulemaking, it is not possible to develop “future-proofed” regulations. TSA acknowledged in the NPRM that this is a nascent market experiencing rapid innovation, and that many key standards and guidelines are currently being developed. Although imperfect, the chosen standards reflect industry
state-of-the-art ahead of publication of emerging standards that likely will support the subsequent Phase 2 rulemaking. TSA made a risk-based determination that the 19 standards provide the key security, privacy, and interoperability requirements necessary for trusted Federal acceptance, and are commensurate with existing REAL ID standards for physical cards. The two-phased rulemaking approach is intended to address the near-term need for established security, privacy, and interoperability requirements, while accommodating the medium-term evolution of technology and standardization.
With respect to comments regarding specific deficiencies in some of the chosen standards, TSA offers the following responses. TSA acknowledges that ISO/IEC 18013-5:2021(E) was developed broadly for international consumption and does not fully address the needs for REAL ID use cases in the U.S. The waiver application criteria set forth in § 37.10(a), therefore, adapt ISO/IEC 18013-5:2021(E) for REAL ID use cases by supplementing this standard with requirements from other references as set forth in this rule. For example, §§ 37.10(a)(1) and (a)(3) address the provisioning and privacy requirements not covered by ISO/IEC 18013-5:2021(E). Other issues relevant to mDL transactions that are not addressed in ISO/IEC 18013-5:2021(E), such as device user experience and digital wallet design are beyond the scope of this rule and intentionally omitted.
M. TSA's Identity Verification Policies
Comments:
A public interest organization raised questions regarding TSA's identity verification policies at the screening checkpoint.
TSA Response:
This rulemaking is focused on allowing Federal agencies to accept mDLs for Federal official purposes as defined by the REAL ID Act. Issues regarding TSA's identify verification processes unrelated to mDLs are beyond the scope of this rulemaking.:
N. Paperwork Reduction Act
Comments:
A public interest organization argued that every mDL transaction with a Federal agency is a collection of information subject to the Paperwork Reduction Act (PRA), and that no exemptions apply. The organization further contended that because neither TSA nor any other Federal agency has sought approval from the Office of Management and Budget (OMB) for these collections, any use of mDLs violates the PRA. Without an approved information collection, the commenter noted that it is not able to determine the costs or purposes of this information collection.
TSA Response:
TSA disagrees with the commenter's assertion that every mDL transaction with a Federal agency is a collection of information subject to the PRA because a request for identify verification is not the “soliciting . . . of facts or opinions . . . calling for . . . answers to identical questions.” 44 U.S.C. 3502(3) (defining “collection of information”);
cf.
5 CFR 1320.3(h)(1) (excepting from the definition information affirmations or certifications that “entail no burden other than that necessary to identify the respondent”). This final rule establishes a process for States to apply to TSA for a temporary waiver that enables Federal agencies to accept mDLs issued by those States when REAL ID enforcement begins on May 7, 2025. This rule does not, however, require any mDL transactions with a Federal agency or set requirements for the use of mDL information. Therefore, this comment is beyond the scope of this rulemaking.
O. Legal Authority
Comments:
A public interest organization questioned the legality of DHS's delegation of authority to TSA to administer the REAL ID program because the public was deprived of an opportunity to comment on it. The commenter further argued that it is improper for TSA, a transportation-focused agency, to regulate use of mDLs by other Federal agencies for non-transportation uses.
Other public interest organizations posited that neither the REAL ID Act, nor subsequent amendments in the REAL ID Modernization Act, authorize issuance of the waiver as set forth in the NPRM. The commenters argued that DHS is statutorily authorized only to prescribe standards, certify State compliance, and extend time to facilitate compliance, and the implementing regulations prevent DHS from waiving any mandatory minimum standards.
TSA Response:
Generally, Federal agencies' delegations of duties and authority are exempt from notice-and-comment requirements of the Administrative Procedure Act because they are matters of “agency management” and “rules of agency organization, procedure or practice.”
79
Matters involving internal agency organization, procedure, practice, and delegations of duties and authority are directed primarily towards improving the efficiency and effectiveness of agency operations, and therefore are not required to be posted for public comment. DHS's delegation of authority to TSA to administer the REAL ID program falls within this exemption, obviating the need for public comment.
79
5 U.S.C. 553(a)(2), (b)(A).
TSA further clarifies that the REAL ID Act, as amended, authorizes the Secretary to promulgate regulations to implement the requirements under the REAL ID Act.
80
And the REAL ID Modernization Act amended the definitions of “driver's license” and “identification card” to specifically include mDLs that have been issued in accordance with regulations prescribed by the Secretary of Homeland Security.
81
TSA is adopting the waiver process established in this final rule pursuant to its authority to implement the requirements of the REAL ID Act as amended, and the final rule is consistent with all statutory requirements.” The waiver application criteria specify issuance-related security and privacy requirements that are commensurate with requirements for physical cards. The final rule further provides that these are temporary requirements that will be superseded by a subsequent rulemaking setting forth more comprehensive requirements after emerging industry standards are published over the next few years.
80
Sec. 205 of the REAL ID Act.
81
Sec. 1001 of the REAL ID Modernization Act, 134 Stat. 2304.
P. Economic Impact Analysis
1. Alternatives
Comments:
Several commenters, including a State, associations, and an individual, commented on various aspects of the assessment regarding the costs and benefits of available regulatory alternatives.
82
Some commenters recommended that TSA should accept Alternatives 1, 3, or 4 compared to the proposed rule. The commenter recommending acceptance of Alternative 1 stated the proposed rule does not address the market failures associated with a lack of common standards, such as increased complexity of mDL use across States, and may result in larger costs
This text is long and has been trimmed here. Open the source document for the complete record.
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.