Federal agencies must make Login.gov a sign-in and identity verification option for a wide array of public-facing websites within two years, according to a Monday memo from the Office of Management and Budget.
“Agencies must offer Login.gov, the single sign-on identity platform developed by the Administrator of General Services, as a sign-on option for all in-scope public-facing websites,” the memo states.
It gives agencies 60 days to provide OMB with a list of public-facing websites with user authentication, 240 days to conduct a digital identity risk assessment and one year to adopt the General Services Administration’s Login.gov best practices.
Agencies are required to adopt Login.gov on “in-scope public-facing websites” within two years. The Defense Department, “elements of the intelligence community” and national security systems are not required to deploy Login.gov, according to the memo. But OMB does encourage the Defense Department to offer Login.gov for public-facing websites that need user authentication “to the extent practicable.”
The memo gives GSA 180 days to publish a best practices guide for Login.gov, host an industry day to learn from commercial digital identity technologies and provide OMB with a report on assessing further digital identity opportunities.
GSA also has a year to work with the National Institute of Standards and Technology on exploring opportunities to expand Login.gov’s capabilities such as “the inheritance of credentials from commercial CSPs and ability to progressively increase [identity] verification based on the relative risk of specific transactions.”
NIST has 120 days to publish a resource that would help agencies develop a digital identity risk assessment.
The memo does not bar agencies from using other credential service providers such as ID.me and CLEAR, a notable stipulation as websites such as Medicare.gov let users pick between Login.gov and commercial digital identity verification options.
“Agencies may also offer other authentication or identity verification solutions in order to: 1) meet specific use cases that Login.gov is unable to fully meet (e.g., a particular user population or operational requirement), or 2) avoid imposing additional burden on a significant population of users (e.g., users that rely on an existing sign-on option),” the memo states.
But at the same time, “agencies must phase out identity solutions that do not meet this description and should routinely reevaluate the need for continued use of solutions other than Login.gov, including by assessing each solution’s volume of active users. When offering other solutions, agencies must promote Login.gov as the default option for new account creation for any user population that Login.gov is able to serve,” it adds.
OMB encourages agencies to track user-focused metrics, analyze fraud and security data and make privacy considerations when reviewing the performance of digital identity services.
The government’s in-house digital identity service has not been without its share of controversy. A March 2023 GSA Inspector General report found that agency officials had misled customer agencies by claiming Login.gov met identity assurance level two standards set by NIST when it actually did not. GSA promised later that year to add facial recognition capabilities in order to meet that standard.
GSA has also accepted many Government Accountability Office recommendations to improve Login.gov but still needs to address fraud threats and technical issues, the watchdog wrote in a July report.
The OMB memo comes as the identity service is experiencing broader changes. GSA implemented a new, lower-cost Login.gov pricing model for agencies in July and will be “continuously strengthening” anti-fraud safeguards, Nextgov/FCW previously reported.
GSA is also working with the National Design Studio on a redesign of Login.gov.

