executive-ordertrade-pressNewsThe Broadside2 min read

OMB mandates Login.gov for public-facing federal services

After decades of fragmented identity systems, the memo gives agencies two years to consolidate onto a single platform, but the escape hatch is generous and the enforcement teeth are absent.


TL;DR

OMB issued a memo Monday directing agencies to deploy Login.gov as the default authentication platform for public-facing federal websites within two years, with a one-year deadline for High Impact Service Provider (HISP) services. Agencies that cannot meet either deadline may submit a notice to OMB explaining why. The mandate exempts DoD systems, national security systems, and B2B/B2G use cases. GSA must convene customer agencies within 90 days, host an industry day within six months, and explore expanded service offerings including verifiable digital credentials. From fiscal 2020 through 2023, agencies spent $209 million on commercial identity solutions against $32.5 million on Login.gov.

OMB mandates Login.gov for public-facing federal services
Editorial illustration · drawn by The Broadside

The memo, signed by OMB Director Russ Vought, is the most forceful push yet to resolve what Vought described as "a range of different solutions and taken inconsistent approaches for managing digital identity, creating unnecessary burden and inefficiencies for the public and government alike."

The fragmentation is real and expensive. GAO found in a July 2025 report that between fiscal 2020 and 2023, 15 of 24 CFO Act agencies used Login.gov for public-facing applications, six used it alongside a commercial solution, and three relied solely on commercial products. On the usage side, Login.gov handled roughly 190 million users versus 60 million across the four commercial alternatives combined, yet agencies spent 6.4 times more on the commercial solutions.

The mandate has two tiers. Within one year, agencies must deploy Login.gov on all existing in-scope HISP websites or submit a notice to OMB stating why they cannot. Within two years, the same applies to all in-scope public-facing websites. Both deadlines come with that notice option, it's not a hard cutoff, and the memo doesn't specify what happens to agencies that file a notice or miss the timeline outright.

The exemptions are explicit. DoD systems and national security systems are out of scope. So are websites where users act on behalf of organizations (businesses, state and local governments) and those where individuals act on behalf of another individual. OMB also carved out cases where Login.gov would impose additional burden on a significant user population, or where user populations with limited official records (young people, Americans living abroad) make identity verification through Login.gov impractical.

GSA has its own deadlines: convene customer agencies within 90 days and quarterly thereafter, publish an implementation best-practices guide with OMB within six months, host an industry day to solicit commercial technology that Login.gov could integrate, and report to OMB on opportunities like verifiable digital credentials. Within one year, GSA and NIST must explore expanding Login.gov's offerings based on agency DIRM results.

The memo also requires agencies to phase out non-conforming identity solutions and "routinely reevaluate the need for continued use of solutions other than Login.gov." Where other solutions remain, Login.gov must be promoted as the default for new account creation, and agencies must seek "maximum parity in assurance level selection" between Login.gov and any alternative.

The road to this point has been long. GSA launched Login.gov in 2017, and the 2023 GSA inspector general finding that TTS misled agencies about Login.gov's compliance with NIST SP 800-63-3 identity proofing requirements didn't help, agencies kept investing in multiple providers. The memo is OMB's answer to the habit.

What's missing is equally clear. There's no penalty structure for non-compliance, no explicit requirement to terminate existing commercial contracts, and no funding mechanism for agencies that need to absorb integration costs. For contractors managing public-facing authentication services, the notice provision means the two-year clock could run differently agency by agency, and the renegotiation of commercial IAM contracts will unfold on that same uneven timeline.


Published ·Deep Fathom