FB pixel

White House makes Login.gov mandate final with two-year governmentwide rollout

White House makes Login.gov mandate final with two-year governmentwide rollout
 

The White House has finalized its plan to make Login.gov the universal sign-on for most public-facing federal services, converting a draft policy disclosed last week into a governmentwide mandate with firm deployment deadlines and new requirements governing competing identity providers.

On Monday, the Office of Management and Budget (OMB) issued Memorandum M-26-18, Scaling Use of Login.gov to Deliver a Universal Sign-on for Public Services, requiring agencies to deploy Login.gov across covered federal websites over the next two years. A separate White House fact sheet says the policy puts the government on a path toward “a universal sign-on across services.”

The OMB’s draft that was circulated last week required agencies to make Login.gov available for most public-facing services requiring authentication. The final policy largely preserves that approach but provides considerably more detail about how and when agencies must carry it out.

Agencies now have one year to deploy Login.gov on covered websites supporting services designated by OMB as High Impact Service Providers. Within two years, they must deploy it on all existing public-facing websites covered by the policy or submit a notice to OMB explaining why they cannot.

The final memorandum also puts tighter limits on agencies’ continued use of other identity providers.

The draft made clear that commercial services such as ID.me or CLEAR would not necessarily be displaced. The final policy confirms that agencies may retain alternatives when Login.gov cannot meet the needs of a particular population or operational requirement, or when eliminating an existing sign-on would place a significant burden on users.

But it goes further by directing agencies to phase out identity solutions that no longer meet those conditions, regularly reconsider whether alternatives remain necessary and promote Login.gov as the default option for new accounts among populations it can serve.

That makes the final policy more than an instruction to add Login.gov alongside existing systems. It establishes an explicit presumption in favor of consolidating federal authentication and identity verification around the government-operated platform while preserving exceptions for services and users Login.gov cannot adequately accommodate.

The implementation timetable also changed from the version described last week.

The 60-day deadline for agency chief information officers to inventory public-facing websites requiring authentication remains.

Agencies now have 240 days to conduct Digital Identity Risk Management assessments under National Institute of Standards and Technology’s (NIST) SP 800-63-4, rather than the six-month period described in reporting on the draft. NIST has 120 days to publish a resource to help agencies conduct those reviews.

The final memorandum also gives considerably more definition to Login.gov’s longer-term evolution.

Within six months, the General Services Administration (GSA) must assess opportunities to create and use verifiable digital credentials, with veteran status cited as an example, and identify ways to reduce repeated collection of the same information from users.

GSA must also hold an industry day examining commercial digital identity technologies that Login.gov could potentially use.

Within a year, GSA and NIST are directed to explore additional capabilities, including accepting credentials issued by commercial credential service providers and allowing identity verification to become progressively stronger according to the risk posed by a particular transaction.

“Login.gov unlocks the potential for users to re-use their information as they interact across services,” the White House said, arguing that government currently pays in some cases to verify the same person repeatedly or pays commercial vendors to verify identity attributes against information government agencies themselves maintain.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Meta sued over alleged facial recognition training for smart glasses

Meta Platforms is facing a proposed nationwide class action lawsuit accusing the company of using photographs from Facebook and Instagram…

 

IATA urges EU to extend biometric border flexibility amid EES delays

The International Air Transport Association (IATA) is urging the European Union to extend temporary flexibility measures for its biometric Entry/Exit…

 

Thailand puts verifiable credentials at center of 2027 digital ID strategy

Thailand’s digital development agency is planning big moves for 2027 as it focuses on digital ID and digital transformation. The…

 

Albania gives ALBTrace broader role in digital identity infrastructure

Albania has expanded the mandate of state-owned identity services provider ALBTrace, giving it responsibility for the country’s digital identity infrastructure…

 

BEAC lays foundation for interoperable payments across Central Africa

The Bank of Central African States (BEAC) has rolled out some initiatives lately which suggest a coordinated push aimed at…

 

Procivis expands EUDI footprint as Europe’s wallet deadline approaches

Procivis has added France to a growing list of European digital identity environments where its technology can issue and verify…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events