Look for Appendix <i>B. Syncable Authenticators</i>: <a href="https://pages.nist.gov/800-63-4/sp800-63b.html#appB" rel="nofollow">https://pages.nist.gov/800-63-4/sp800-63b.html#appB</a><p>Interesting they feel comfortable using WebAuthn for Authenticator Assurance Level 2. It does seem like the right middle-ground for an exportable private key.<p>They referenced WebAuthn quite a bit in Appendix B. I'm surprised the FIDO Alliance's Credential Exchange Format/Protocol was not mentioned: <a href="https://fidoalliance.org/specifications-credential-exchange-specifications/" rel="nofollow">https://fidoalliance.org/specifications-credential-exchange-...</a><p>I haven't taken a deep dive on it, but I wonder if those FIDO Alliance specifications would meet/support NIST's AAL2 criteria for WebAuthn.