2024-23881. Minimum Standards for Driver's Licenses and Identification Cards Acceptable by Federal Agencies for Official Purposes; Waiver for Mobile Driver's Licenses
Table 1—Summary of Changes Between the NPRM and the Final Rule
Section Final rule Reason for the change 37.3 Adds definition for “Provisioning.” Technical change to add definition of a key term to improve clarity. 37.4 Revises points of contact for the public to contact TSA; provides additional means to access certain standards that are IBR'd in this rule Technical changes to improve access to IBR materials. 37.4(c)(1) Corrects title of “Cybersecurity Incident & Vulnerability Response Playbooks” to “Federal Government Cybersecurity Incident & Vulnerability Response Playbooks.” Technical correction. 37.4(g)(4) Updates standard NIST FIPS PUB 197 to NIST FIPS PUB 197-upd1 to reflect revised version of standard Technical change to reflect revisions to standard to improve public access. Revisions include editorial improvements, but no technical changes to the algorithm specified in the earlier version. 37.4(g)(7) Corrects website address to the cited standard Technical change to correct a typo. 37.7(a) Clarifies conditions under which TSA will issue a waiver Clarification regarding impact of the waiver. 37.7(b)(3) Deleted Deleted proposed language that would have made a State ineligible to apply for a waiver if the State issues mDLs to individuals with non-REAL ID compliant physical cards (in addition to issuing mDLs to other individuals that have compliant physical cards). 37.8(c) Adds paragraph (c) to require Federal agencies accepting mDLs to confirm, consistent with the deadlines set forth in § 37.5, that the mDL data element “DHS_compliance” is encoded “F,” as required by §§ 37.10(a)(4)(ii) & (a)(1)(vii) Clarifies that when REAL ID enforcement begins, Federal agencies may accept mDLs from States only if the underlying physical card is REAL ID compliant. 37.8(d) Renumbers § 37.8(c), as proposed in the NPRM, to § 37.8(d) in light of addition of new § 37.8(c) Corrects website address from dhs.gov to tsa.gov Adds requirement regarding protection of SSI Technical changes renumber provision from 37.8(c) to 37.8(d), update agency name and website address, and clarify the mechanics of reporting. Provides that reports may contain sensitive security information (SSI) 34 and if so, would be subject to requirements of 49 CFR part 1520. ( print page 85345) 37.9(a) Corrects agency name from DHS to TSA Corrects website address from dhs.gov to tsa.gov Technical changes update agency name and website address. 37.9(b) Revises “days” to “calendar days.” Corrects website address from dhs.gov to tsa.gov Clarifies that “days” means calendar days, not business days. Technical change updates agency website address. 37.9(c) Revises “days” to “calendar days.” Corrects website address from dhs.gov to tsa.gov Clarifies that “days” means calendar days, not business days. Technical change updates agency website address. 37.9(e)(2) Revises “days” to “calendar days.” Corrects website address from dhs.gov to tsa.gov Provides a means for States to contact TSA if the State is unclear whether certain modifications to its mDL issuance processes require reporting Clarifies that “days” means calendar days, not business days. Technical change updates agency website address. Provides a means for States to resolve potential questions regarding reporting requirements. 37.9(e)(4)(ii) Revises “days” to “calendar days.” Clarifies that “days” means calendar days, not business days. 37.9(e)(5)(i) Corrects agency name from DHS to TSA Technical change updates agency name. 37.9(e)(5)(ii) Revises “days” to “calendar days.” Clarifies that “days” means calendar days, not business days. 37.9(g) Adds new paragraph (g), which provides that information submitted in response to requirements to apply for and maintain a waiver may contain SSI, and if so, would be subject to requirements of 49 CFR part 1520 SSI protection. 37.10(a)(1)(vii) Replaces NPRM requirement that States must issue mDLs only to residents who have been issued physical cards that are valid, unexpired, and REAL ID-compliant with requirement that States must populate the “DHS_compliance” data field to correspond to the REAL ID-compliance status of the underlying physical driver's license or identification card, or as required by the AAMVA Guidelines Proposed language would have required States to issue mDLs only to individuals to whom that State previously issued a physical card that is valid, unexpired, and REAL ID-compliant. This would have denied States the discretion to issue mDLs to holders of non-compliant physical cards. Revisions require States to issue mDLs in a manner that reflects the REAL ID compliance status of the underlying physical card. This is consistent with the intent of the NPRM, which was to enable Federal agencies to determine the REAL ID-compliance status of the underlying physical card, and accept only compliant cards when enforcement begins. 37.10(a)(4) Corrects version number of AAMVA Mobile Driver's License (mDL) Implementation Guidelines (Jan. 2023) Updates NIST FIPS PUB 197 to NIST FIPS PUB 197-upd1 to reflect revised version of standard Technical change corrects version number of AAMVA Guidelines. Changes reflect current version of NIST FIPS PUB 197 to ensure continuing public access. Revisions to the standard include editorial improvements, but no technical changes to the algorithm specified in the earlier version. 37.10(b)(1) Clarifies that “independent entity” includes State employees or contractors that are independent of the State's driver's licensing agency Provides States additional options to select auditors. Reduces burdens without impact on security or privacy. 37.10(c) Corrects website address from dhs.gov to tsa.gov Clarifies that TSA will publish in the Federal Register a notice advising of the availability of updated TSA mDL Waiver Application Guidance, which itself will be published at www.tsa.gov/mDL/ Technical changes update agency website address, and clarify means of notifying and publishing updates to TSA mDL Waiver Application Guidance. Appendix A, Throughout Corrections to titles of: CISA Federal Government Cybersecurity Incident & Vulnerability Response Playbooks DHS National Cyber Incident Response Plan NIST FIPS PUB 140-3 NIST Framework for Improving Critical Infrastructure Cybersecurity Technical corrections. Appendix A, paragraph 1.1 Adds section numbers to certain references Deletes requirement to comply with NIST SP 800-53B Technical changes clarify which parts of cited reference require compliance, and remove an unnecessary requirement. Appendix A, paragraph 2.2 Revises “privileged account or service” in NPRM to “trusted role.” Technical change corrects terminology. Appendix A, paragraph 2.13 Adds section numbers to a certain reference Technical change clarifies which parts of cited reference require compliance. Appendix A, paragraph 5.13 Reduces requirements for minimum number of personnel to generate issuing authority certificate authority (IACA) root certificate keys from a minimum of three to two persons, consisting of at least one ceremony administrator and one qualified witness Provides States greater freedom to select products. Does not impact security, privacy, or interoperability. ( print page 85346) Appendix A, paragraph 5.14 Modifies requirements for minimum number of personnel to generate document signer keys. Final rule requires either at least one administrator and one qualified witness (other than a person involved in key generation), or at least 2 administrators using split knowledge processes Provides States greater freedom to select products. Does not impact security, privacy, or interoperability. Appendix A, paragraph 6.3 Revises “days” to “calendar days Clarifies that “days” means calendar days, not business days. Appendix A, paragraph 8.6 Modifies cyber incident reporting requirements to incidents as defined in the TSA Cybersecurity Lexicon available at www.tsa.gov that may harm state certificate systems Corrects website address from dhs.gov to tsa.gov Adds SSI protection requirements Clarifies types of incidents that must be reported, updates agency website address, and adds SSI protection.