Join our Newsletter — 33% off our NHI Course
Home› Guides› CIAM Buyer’s Guide
Buyer's Guide Identity & Access Management (IAM)

CIAM Buyer’s Guide

← All guides
By Lalit Choda, NHI Mgmt Group Updated 27 September 2026 4 min read
On this page

A customer identity (CIAM) platform shapes both your customers' first impression and your exposure to account takeover and fraud. CIAM products handle registration, sign-in, passkeys, social login, consent, profile management and increasingly fraud signals, business customer administration and access by AI agents acting for customers. Options range from developer-focused identity APIs to full platforms from large identity vendors and CIAM specialists, and some organisations build on open-source components. This vendor-neutral buyer's guide helps you define requirements, compare platforms and plan a proof of concept.

Key takeaways

  • Judge CIAM on security and conversion together: passkeys, risk-based step-up and bot defence with low friction.
  • Test scale and availability against your peak events, not average traffic.
  • Check B2B needs early: delegated administration, organisations and federation with business customers.
  • Consent, privacy and data residency requirements often decide the shortlist.
  • Look ahead to AI agents acting for customers and digital identity wallets.

Define requirements

  • Which audiences: consumers, business customers and their users, partners, patients, citizens?
  • Expected user numbers, peak sign-in rates and growth.
  • Channels: web, mobile apps, call centre, in-store, devices.
  • Identity proofing and age assurance needs. See the Identity Proofing and KYC Guide and the Age Assurance Guide.
  • Regulatory needs: PSD2 strong customer authentication, privacy law, data residency, accessibility.
  • Existing systems: customer data platform, CRM, fraud tools, marketing consent.

Capability areas

AreaWhat to look for
AuthenticationPasskeys, social login, passwordless email and SMS as fallbacks, MFA and risk-based step-up. See the Passwordless and Passkeys Guide
Account protectionBreached-password screening, credential stuffing and bot defence, device intelligence, account takeover detection. See the Identity Fraud Prevention Guide
Registration and recoveryProgressive profiling, verified contact details, secure recovery with re-verification options. See the Account Recovery Guide
Consent and privacyGranular consent capture and history, preference centre, data subject request support, residency options. See the Identity Data Privacy and Consent Guide
B2B and delegated administrationOrganisations, invitations, customer-managed admins, federation with customer IdPs, SCIM
Developer experienceSDKs, hosted and embedded login, customisation, APIs, test environments
StandardsOpenID Connect, OAuth 2.0 and 2.1 practices, SAML, FAPI for financial APIs, wallet and verifiable credential support. See the OAuth and OIDC Guide
Scale and resilienceProven peak throughput, regional deployment, availability commitments, degradation modes
Agent accessDelegated, scoped tokens for AI agents acting for customers; consent screens that show the agent; revocation. See the Agentic Commerce Identity Guide
Logging and integrationComplete event logs, streaming to SIEM and fraud tools, webhooks

Evaluating the vendor's own security

  • How are tenant signing keys protected and rotated, and how is support staff access to your tenant controlled?
  • What independent certifications and penetration test results can you see?
  • How are tenants isolated from each other?
  • How quickly can you revoke all sessions and tokens, and rotate keys, in an incident?

Questions to ask vendors

  • Show us passkey enrolment and sign-in across our main browsers and mobile apps, and the fallback when a passkey is not available.
  • How do you detect and stop credential stuffing without blocking genuine customers? What does a false positive cost the customer?
  • How does account recovery work, and can we require re-verification for high-value accounts?
  • What throughput have you sustained for a single tenant at peak, and what happens when limits are reached?
  • How do business customers manage their own users and connect their identity providers?
  • How would an AI agent get delegated access to a customer's account, and how would the customer see and revoke it?
  • Where is customer data stored and processed, and can we choose?

Red flags

  • No passkey support, or passkeys treated only as a second factor.
  • Bot and fraud defence that is an unintegrated add-on with its own data silo.
  • Recovery limited to email or SMS links with no stronger option.
  • Consent records that cannot be exported or evidenced.
  • Pricing that punishes growth in monthly active users with no predictability.
  • Vague answers on tenant isolation, support access or key management.

Proof of concept

  1. Build the main journeys: registration, sign-in with passkeys, step-up for a sensitive action, recovery and profile update.
  2. Integrate one web and one mobile app, plus your fraud or analytics tool.
  3. Run a load test at your expected peak and a simulated credential stuffing attack.
  4. Test a B2B scenario with delegated administration and federation, if relevant.
  5. Export logs and consent records and check they meet audit needs.
  6. Estimate migration: password hash import, user communications and passkey enrolment campaigns.

How NHI Mgmt Group can help

We provide independent requirements, RFP and evaluation support across customer identity, IAM, IGA, PAM and NHI. Browse vendors in our products directory or contact us.

Related NHI Mgmt Group resources: Customer IAM (CIAM) Guide · Identity Verification Buyer's Guide · IAM and IdP Buyer's Guide · Identity Fraud Prevention Guide

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 27 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org