Annex F: TSA mDL Final Rule Mapping

This annex maps the technical and organizational security requirements of the TSA mDL Final Rule (6 CFR Part 37, 89 FR 85340, effective November 25, 2024) to SEDI Implementation Guide requirements. This mapping is informative and supports alignment between the SEDI program and federal mDL acceptance standards.

The TSA rule establishes waiver-based requirements for states seeking federal acceptance of mobile driver's licenses. While SEDI is broader than mDL, the rule's organizational security framework, NIST references, and auditor requirements are directly applicable to SEDI infrastructure.

Scope of This Mapping

Included: Technical requirements, organizational security (Appendix A), NIST standards, auditor requirements, incident response.

Excluded: AAMVA-specific namespace requirements, ISO 18013-5 format specifics (those belong in conformance profiles), budget/fiscal estimates, REAL ID Act specific provisions.

NIST Standards Referenced by TSA Rule

The TSA rule incorporates these NIST standards, all of which are relevant to SEDI:

Standard

Description

SEDI Application

SP 800-53 Rev. 5

Security and Privacy Controls

Primary control catalog for organizational security requirements

SP 800-57 Parts 1-3

Key Management

Key lifecycle management for SEDI credential infrastructure

SP 800-63-4

Digital Identity Guidelines

Identity proofing assurance levels (already normative in Ch. 6)

NIST CSF v1.1

Cybersecurity Framework

Organizational cybersecurity posture assessment

FIPS 140-3

Cryptographic Module Validation

Key storage hardware requirements

FIPS 186-5

Digital Signature Standard

Approved signing algorithms

Provisioning Security Requirements

TSA Requirement

CFR Cite

SEDI Requirement

Notes

Encrypt data in transit and at rest during provisioning

37.10(a)(1)(i)

SEDI-SDI-14, SEDI-WAL-02

Applies to both Department and wallet provider

Review repeated failed provisioning attempts

37.10(a)(1)(ii)

SEDI-SDI-01

Compromise detection

Confirm applicant controls the device

37.10(a)(1)(iii)

SEDI-SDI-04

Device/holder binding

Confirm applicant possesses device private key

37.10(a)(1)(iv)

SEDI-CRY-02

Key binding assurance

Prevent false matching with other individuals

37.10(a)(1)(v)

SEDI-IDP-04

Identity proofing integrity

Presentation attack detection (liveness)

37.10(a)(1)(vi)

SEDI-IDP-04

Anti-spoofing

Data matches authoritative source

37.10(a)(1)(viii)

SEDI-SDI-16

Endorsed attribute verification

Organizational Security Requirements (Appendix A)

The TSA rule's Appendix A defines 8 categories of organizational security requirements for mDL issuance infrastructure. These map to SEDI as follows:

#

Category

What It Covers

SEDI Domain

1

Certificate Lifecycle

Governance, change mgmt, patching

KMS, ORG-07

2

Access Management

Least privilege, MFA, account review

ORG-01

3

Facility Controls

Physical access, supply chain

SDI-13, SDI-14

4

Personnel Security

Screening, training, termination

ORG-02

5

Technical Controls

Network segmentation, HSMs, key ceremonies

KMS-02, KMS-03

6

Threat Detection

Continuous monitoring, log integrity

ORG-04

7

Logging

Event logging, 36-month retention

ORG-04

8

Incident Response

Alerting, vuln scanning, pen testing, 72-hr reporting

ORG-03, ORG-05

Auditor Requirements

The TSA rule specifies auditor qualifications that can inform SEDI's Expert (EXPT) verification method:

TSA Requirement

SEDI Adaptation

CPA license in issuing state

Licensed professional in relevant jurisdiction

CISA or CITP certification

Information systems security audit certification

Independent of the issuing agency

Independent of the Department and wallet providers being assessed

Experienced with information systems security audits

Demonstrated experience with digital identity / credential systems

Conflict of interest disclosure and mitigation

Same

Key Differences from SEDI

Area

TSA mDL Rule

SEDI

Credential format

ISO 18013-5 (mDoc) only

Technology-neutral; format determined by profiles

Anti-surveillance

Not addressed

Statutory mandate (63A-20-301(3))

Selective disclosure

Not addressed

Statutory mandate (63A-20-301(1)(e))

Holder control

Limited (state-issued credential)

Extensive (bill of rights, holder sovereignty)

Scope

Federal acceptance of state mDLs

State-endorsed digital identity (broader)

Phase

Phase 1 waiver; Phase 2 pending

Comprehensive from inception

Reference

Full rule text: 89 FR 85340 (October 25, 2024).