FAL 3 requires the presentation of an additional Cryptographic Key bound to the assertion (e.g., the use of a cryptographic authenticator) along with all requirements of FAL 2. Note that the additional Cryptographic Key presented at FAL 3 need not be the same key used by the subscriber to authenticate to the Identity Provider (IDP)