Practical platform view: because notaries usually do not personally know the signer, does the normal remote proofing flow require credential analysis + KBA, explicitly allow a biometric / identity-proofing alternative, or leave any non-KBA route approval-dependent?
For reference only — always verify independently
This information is based on statutory research current as of June 2026 and is being actively updated. Laws change frequently. Do not rely on this as legal confirmation before operating in any state. You must verify current requirements directly with the relevant state authority, a licensed notary attorney, or the state Secretary of State office before conducting RON services.
NAC 240.670 — 3 methods: (1) personal knowledge; (2) credible witness; (3) remote ID + credential analysis + [KBA OR SOS-approved identity proofing]. Under method 3, KBA and identity proofing (e.g. biometric) are alternatives. Biometric must be SOS-registered (NAC 240.720) and meet/exceed KBA accuracy (NAC 240.700). NAC 240.695: notary must visually compare ID photo vs. signer on screen.
R2-12-1305 mandates all three together: credential analysis + dynamic KBA (5-question quiz, 80% pass) + real-time visual photo comparison. The rule uses mandatory 'must' language; no alternative to KBA is listed.
Remote-ID path: statute requires remote ID + credential analysis + SOS-approved identity proofing. KBA is not named in the statute, but neither is biometric substitution guaranteed; Stripe-style biometrics would depend on SOS approval.
Remote-ID path: Illinois requires credential analysis + dynamic KBA in the default rule path, but the broader identity-proofing framework also allows Secretary-of-State-approved alternatives. Not a pure KBA-only state.
75 IAC 7-8-1: identity proofing 'must be performed through dynamic knowledge based authentication or through another process or service approved by the secretary of state.' KBA is default; a non-KBA route requires explicit SOS approval — not automatic.
721 IAC 43.9(2): (a) KBA quiz, (b) credential analysis definition, (c) credential analysis requirements — all three are conjunctive requirements a provider must satisfy, not a menu. No OR, no biometric alternative. Rule references NIST SP 800-63-3; KBA is the only named identity proofing mechanism.
K.A.R. 7-43-18: credential analysis (a)(1) AND KBA quiz (a)(2) are conjunctive — regulation uses 'and' between them. KBA: 5 questions, 5 choices, 80% pass, 2-minute limit, 1 retake. Biometric not mentioned anywhere. No 'or' alternative to KBA exists in the rule.
30 KAR 8:005 §5(4) requires credential analysis that 'binds the individual's identity to the individual following a successful dynamic knowledge-based authentication assessment.' KBA is embedded as the binding mechanism — not listed as one of several options.
§ 358.645 Subd. 5(1) defines identity proofing to 'include knowledge-based authentication' with specific minimums (5 questions, 5 choices, 80% pass, 2-minute limit). KBA is built into the statutory definition — no biometric alternative found.
12.9.4.11 NMAC: procedure 'shall analyze the individual's identity credential against trusted third-person data sources, bind the individual's identity to the individual following successful knowledge-based authentication.' KBA is the named binding mechanism. No biometric substitute in the rule text.
OAC 655:25-11-5(a): procedure 'shall analyze the principal's identification credential... bind the principal's identity to the individual following successful dynamic knowledge-based authentication assessment.' KBA is the only named binding mechanism. No biometric substitute.
OAR 160-100-0805(2)(a): 'signer's identity must be linked to the signer following successful knowledge-based authentication.' KBA is the required binding step. Biometrics are explicitly optional: 'If biometric sensing technologies are used... may include facial, voice, and fingerprint recognition' (§4(c)).
Gov. Code § 406.110(b)(2) uses 'each of the following': credential analysis AND identity proofing, both conjunctive. 1 TAC § 87.70(b): 'identity proofing IS dynamic knowledge-based authentication.' No 'or', no 'may include' — KBA is mandatory and irreplaceable in the credential pathway.
WAC 308-30-300(1): 'two different types of identity proofing consisting of a credential analysis procedure and a dynamic knowledge-based authentication assessment.' Both are named explicitly. No alternative to KBA is provided; no biometric substitute authorized.
Remote-ID path: Wisconsin requires 2 different types of identity proofing through an approved provider or approved alternative process. Primary-source text does not cleanly hard-code either a KBA pair or a biometric pair.
§ 36-20-73.1(e): 'either of the following' — personal knowledge OR (two govt IDs AND a 'review of public or private data sources'). KBA never named; broad data-source review qualifies. AL RON is narrow wet-ink-over-video, not full electronic RON.
§ 8231.8: credential analysis AND identity proofing required; identity proofing = 'review of data sources' per SOS rules. KBA never named. RON NOT yet operative — SOS must build system + adopt regs (deadline Jan 1, 2030). No binding method rule exists yet.
§ (6)(b)(II): credential analysis 'and at least one of the following' — (A) KBA OR (B) public key certificate OR (C) third-party identity verification OR (III) any other SOS-approved method. Rule confirms KBA applies 'if selected'. Replaceable.
§ 3-95b(b)(2): 'one or more of the following methods' — personal knowledge / govt ID / 'not less than 2 types of identity proofing' / credible witness. Technology-neutral, KBA never named. ID presentation alone can suffice. No RON regs adopted.
§ 4320(c)(1)(c): 'at least 2 different types of identity proofing' — types not specified, KBA never named. Biometric + credential analysis satisfies it. § 4323 lets SOS later impose specific standards; confirm provider config.
§ 117.265(4)(b)3: identity proofing 'in the form of knowledge-based authentication OR another method of identity proofing.' § 117.201 names biometric verification as a qualifying alternative. Category required; KBA replaceable.
§ XLVI-144(C): 'Identity proofing shall be performed through either of the following' — (1) 5-question KBA quiz OR (2) biometric data analysis (facial/voiceprint/fingerprint). Explicit either/or; biometric replaces KBA.
'At least 2 different types of identity proofing' — menu of 4 (credential, biometric, public key cert, question-based), pick any 2. KBA never named; biometric is co-equal. SOS must approve the method/provider.
§ 18-201 defines identity proofing as 'review of personal information from public or private data sources' — broad category, KBA never named. No quiz mandated. The '5-question/80%' boilerplate is NOT in Maryland code.
§ 1: identity proofing is a 'review of data sources, which MAY INCLUDE credential analysis, dynamic KBA, analysis of biometric data... or other means permitted by the secretary.' Permissive 'may include' — KBA is one option, biometric explicit. Need 2 of the menu.
Mar 2026 SOS Standards §B(2): 'identity proofing by means of knowledge-based authentication OR biometric verification.' Disjunctive 'or' — two co-equal sub-paths. Biometric (a) standalone alternative to KBA. Credential analysis stays separately required.
15 CSR 30-110.040: software must allow 'at least two of the following' — (1) credential analysis, (2) dynamic KBA, (3) biometrics. Any 2 of 3. Provider can do credential analysis + biometrics, omit KBA entirely.
§ 1-5-603(12)(c): 'two or more different types... SUCH AS dynamic KBA, public key certificate, identity proofing, credential analysis, or any other means.' Illustrative 'such as' list joined by 'or'. KBA is one menu option. Pick any 2.
§ 64-411(2)(b): credential analysis AND identity proofing (conjunctive). 433 NAC 8 §010.04 defines identity proofing as a quiz: min 5 questions, 5 choices, 80% pass, 2-min limit. No biometric alternative for slot 2. KBA irreplaceable.
'At least 2 different types of identity proofing' (generic, KBA never named). Defaults to MISMO RON v1 standard unless SOS rules otherwise. IAL2-compliant biometric not foreclosed. Method set by standard, not locked by statute.
N.J.A.C. 17:50-1.14(g)3: 'personal knowledge, OR one of the following methods' — (1) dynamic KBA, (2) biometric (NIST-compliant), (3) digital public key certificate. KBA is 1 of 3, pick one. Biometric replaces KBA.
§ 182.7: identity proofing 'must meet, at minimum, the IAL2 standard... or any industry accepted standard at least as secure.' Performance standard, not a named quiz. KBA never appears in Part 182. Any IAL2-equivalent method (incl. biometric) qualifies.
§ 10B-134.11(a)(2): credential analysis AND 'identity proofing by a third-party vendor.' § 10B-134.1 defines identity proofing as 'review of personal information from public or proprietary data sources' — KBA/quiz never named. Any approved vendor process qualifies.
OAC 111:6-1-05(B)(5): 'Identity proofing shall be performed by means of dynamic KBA OR through another process approved by the secretary of state.' KBA named (5Q/80%/2min) but disjunctive 'or' — SOS-approved alternative permitted.
§ 167.86(4): 'two types... identity proofing methods MAY INCLUDE credential analysis, dynamic KBA, biometrics OR other means.' Dept expressly declined to mandate any method ('technology agnostic'). KBA replaceable; pick any 2.
Statute is generic ('2 different types of identity proofing'). But SOS RON Performance Guide names KBA explicitly, joined to govt-ID by 'and', with NO biometric alternative offered. KBA is the expected method per state guidance — confirm before relying on a non-KBA stack.
§ 18-1-11.2: 'two different methods of identity proofing.' § 18-1-2(3) defines it as 'review of personal information from public or proprietary data sources' — KBA never named. SOS has not adopted method rules. Any 2 qualifying methods work.
Part 8-6(a): notary 'shall verify... through BOTH a credential analysis procedure AND a dynamic knowledge-based authentication assessment.' KBA named, joined by 'both...and'. No biometric alternative. KBA irreplaceable.
§ 47.1-2: 'identified by at least two of the following' — (1) credential analysis, (2) antecedent in-person proofing, (3) other authorized method, (4) digital cert via biometric/PIV, OR (5) KBA. HB 1372 added KBA as the 5th option. Any 2 of 5; KBA fully replaceable.
§ 32-3-102(a)(xxxi)(B): 'two or more types... SUCH AS dynamic KBA, public key certificate, identity proofing, credential analysis or other means.' Open OR-menu. 'Identity proofing' definition itself includes biometric. KBA replaceable.
No enabling legislation.
Expired 2022; HB 289/334/SB 8 pending 2026.
§ 51-120
In-person electronic notarization only.
No RON provisions in Century Code Ch. 44.
Title 26 requires in-person; IPEN only.
No RON provisions; no 2024–2026 legislative action.
HAR § 5-11-69(b): 'The analysis of the identity credential AND the knowledge-based authentication shall conform...' KBA named (5Q, 5 choices, 80%, 2min). No biometric alternative. KBA irreplaceable.
No live RON authority. EO 1467 (COVID-era) expired Dec 2021; HB1154 (2025) and all prior RON bills died. Only TWIN + IPEN authorized — both require in-person appearance.
§ 46-1-2(26): secondary authentication 'by means of: (a) dynamic KBA... OR (b) analysis of biometric data (facial/voiceprint/fingerprint).' Disjunctive 'or' — biometric co-equal. SB 139 kept this structure. KBA replaceable.
§ 39-4-38(a)(2)(C): 'at least two different types of processes... through a review of public or private data sources.' KBA never named — broad technology-neutral standard. Any 2 qualifying methods satisfy it.
2024–2026 updates. No state dropped KBA requirements.
| State | Date | Change |
|---|---|---|
| Michigan | Apr 2026 | Biometric now primary alternative; KBA demoted |
| Pennsylvania | Mar 2026 | RULONA final regs; biometric + cred analysis aligned |
| Utah | May 2026 | S.B. 139 enacted; auth methods still under review |
| Oregon | Jan 2025 | RON notaries must renew notice with commission renewal |
| Ohio | Apr 2025 | Fee increase (HB 315); KBA requirement unchanged |
| Virginia | 2024 | HB 1372: KBA added as 5th option (still optional) |
| South Dakota | Jul 2024 | First-time RON authorization; KBA optional |
Statutory citations link directly to official state legislature sources where available. Laws are updated continuously — always confirm with the state authority before entering a new market. NotaryPerfect currently serves Nevada under NRS 240.1997. This is not legal advice.