FB pixel

US draft policy would expand Login.gov across federal digital services

Draft policy would move the platform closer to becoming the backbone of US digital identity infrastructure
US draft policy would expand Login.gov across federal digital services
 

The U.S. government is preparing to make Login.gov the primary authentication service for most federal digital services, significantly expanding its role in the country’s digital identity infrastructure. A draft White House Office of Management and Budget (OMB) memorandum would require federal agencies to make Login.gov available across most public-facing websites and digital services requiring user authentication.

The proposed policy comes as Login.gov is undergoing a significant expansion. GSA is exploring persistent device fingerprinting and behavioral risk analysis, preparing to use mobile driver’s licenses for identity verification, strengthening defenses against AI-enabled fraud and redesigning the service with the White House National Design Studio.

FedScoop reported Wednesday that OMB circulated a draft memorandum to agencies Monday that would require the use of Login.gov “for most public facing services,” including government websites and other digital platforms requiring authentication.

Agencies would have 60 days after issuance of the final policy to inventory their existing authenticated public services and six months to conduct a broader digital identity risk management review.

According to FedScoop’s review of the document, agencies would not necessarily have to abandon commercial identity providers such as ID.me or CLEAR. Instead, the policy would require them to incorporate Login.gov while leaving room for other authentication options.

GSA would also be directed to establish implementation guidance, convene quarterly meetings with agencies, conduct industry engagements with commercial digital identity providers and report to OMB on opportunities to improve the service.

The proposal would make considerably more concrete a requirement that has technically existed for more than a decade.

Congress directed agency heads in 2015 to implement a “single sign-on trusted identity platform” developed by GSA for individuals accessing public agency websites that require authentication.

GSA launched Login.gov in 2017 in response. But adoption has remained uneven, leaving federal agencies with a mixture of Login.gov, internally developed credentials and commercial identity services.

The OMB draft memo therefore appears less to create a new federal identity policy than to establish a governmentwide mechanism for enforcing and measuring adoption of one that Congress previously ordered.

OMB Director Russell Vought reportedly argues in the draft that the government’s fragmented approach increases costs and creates unnecessary complexity for people interacting with federal agencies.

Greater use of Login.gov, the memo says, would allow the government to spread identity verification costs across a larger user base while deploying security improvements centrally rather than requiring agencies to build overlapping systems.

Requiring an agency to use Login.gov does not necessarily mean every person accessing a federal website would have to submit identity documents or biometric information.

A basic Login.gov account provides authentication using a password and a second factor. Agencies decide whether the service being accessed also requires the user to prove a real-world identity.

When stronger identity proofing is required, Login.gov can ask users for a government-issued ID, Social Security number and other identifying information. In some cases, users are asked to provide a selfie that is compared with the photograph on an identity document.

Login.gov also offers in-person verification through participating U.S. Postal Service locations.

The same day the OMB draft was circulated, GSA issued a Request for Information seeking a new device fingerprinting capability for Login.gov.

The contemplated technology would attempt to recognize computers and mobile devices across repeated visits even after IP addresses change, cookies are deleted or users employ private browsing, virtual private networks or technologies intended to obscure their devices.

GSA is also changing how Login.gov looks and operates. The agency announced August 3 that it had begun working with the National Design Studio to overhaul the service’s user experience, particularly the identity-verification process.

GSA said the effort is intended to reduce friction without weakening privacy or security requirements. A redesigned interface is already being tested and gradually rolled out to users.

The expansion comes against a more complicated security record.

In July, the Government Accountability Office told Congress Login.gov’s anti-fraud team had discovered fraudulent accounts that successfully passed its Identity Assurance Level 2, or IAL2, identity-proofing workflow.

GSA concluded in 2025 that the sophistication of such attempts was likely to increase and that an additional verification layer would be needed to reduce the platform’s exposure to fraud.

Login.gov has more than 100 million accounts and is processing more than 300 million sign-ins annually. GSA’s fiscal 2026-2030 strategic plan explicitly calls for increasing the number of active Login.gov users as part of an effort to expand governmentwide shared services.

The OMB draft, if finalized substantially as reported, would accelerate that transition from a widely used shared service into something much closer to governmentwide identity infrastructure.

It would also raise the stakes for the changes now taking place inside Login.gov.

A platform capable of authenticating users, verifying identity documents, conducting facial comparisons where required, accepting cryptographically verified mobile IDs and evaluating the devices from which people connect would sit in front of an expanding portion of the federal government’s online services.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Meta sued over alleged facial recognition training for smart glasses

Meta Platforms is facing a proposed nationwide class action lawsuit accusing the company of using photographs from Facebook and Instagram…

 

IATA urges EU to extend biometric border flexibility amid EES delays

The International Air Transport Association (IATA) is urging the European Union to extend temporary flexibility measures for its biometric Entry/Exit…

 

Thailand puts verifiable credentials at center of 2027 digital ID strategy

Thailand’s digital development agency is planning big moves for 2027 as it focuses on digital ID and digital transformation. The…

 

Albania gives ALBTrace broader role in digital identity infrastructure

Albania has expanded the mandate of state-owned identity services provider ALBTrace, giving it responsibility for the country’s digital identity infrastructure…

 

BEAC lays foundation for interoperable payments across Central Africa

The Bank of Central African States (BEAC) has rolled out some initiatives lately which suggest a coordinated push aimed at…

 

Procivis expands EUDI footprint as Europe’s wallet deadline approaches

Procivis has added France to a growing list of European digital identity environments where its technology can issue and verify…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events