nisttrade-pressNewsThe Broadside2 min read

OMB Memo Mandates Login.gov as Universal Federal Sign-On

The binding memo closes the enforcement gap that let agencies maintain custom authentication stacks for decades, setting hard deadlines through 2027.


TL;DR

OMB Director Russell Vought issued a binding memo Monday making Login.gov the mandatory sign-on for federal public-facing websites that require authentication. Agencies have 60 days to inventory those sites, one year to adopt GSA's Login best practices, and two years to complete migration. The memo does not bar agencies from using other identity verification services alongside Login where Login can't meet specific needs, but the voluntary-adoption era is over. GSA must convene agency customers quarterly, publish implementation guidance within 180 days, and host an industry day for commercial identity providers. NIST gets 120 days to deliver a Digital Identity Risk Management resource.

OMB Memo Mandates Login.gov as Universal Federal Sign-On
Editorial illustration · drawn by The Broadside

The Office of Management and Budget released the binding memo Monday that federal IT leaders have anticipated (and in some cases resisted) since Login.gov's launch in 2017. The six-page document from Director Russell Vought mandates Login.gov as the universal sign-on for public-facing federal websites requiring authentication, with compliance deadlines stretching into 2027.

The memo addresses a structural problem that has persisted across three administrations. Congress required agencies to establish a single sign-on platform for government website logins. Login.gov was created to fill that role. But OMB never enforced its use, and agencies built or maintained their own authentication stacks. The result, per Vought: users juggle multiple sign-ons and the government pays more for duplicate identity verification. "This policy enforces Login.gov as the universal sign-on for accessing public services online," the memo states, "enabling more seamless and efficient service delivery while safeguarding user privacy and supporting resilience against fraud and security threats."

The compliance timeline is aggressive by federal standards. Agency CIOs have 60 days to inventory every public-facing website with authentication. Within one year, agencies must adopt GSA's Login best practices. Within two years, all covered sites must be migrated. GSA faces its own obligations: quarterly agency feedback sessions starting in 90 days, best-practice guidance in 180 days, and an industry day for commercial identity providers on the same 180-day clock.

The memo doesn't ban other identity services outright. Agencies can use additional solutions when Login can't meet specific needs or when populations would be burdened by a forced switch. The carve-out is pragmatic, but the default has flipped. Login is now the baseline, and any deviation requires justification.

NIST is directed to deliver a new Digital Identity Risk Management resource within 120 days to help agencies implement existing guidance. That piece matters because the GAO flagged in October 2024 that Login.gov had not yet achieved full compliance with NIST SP 800-63 identity assurance standards, and 12 CFO Act agencies reported challenges with that gap. The GAO subsequently confirmed IAL2 certification was issued, but the tension between mandated adoption and outstanding technical maturity will shape how the next two years play out.

The memo landed on Greg Barbaccia's last day as federal CIO, a former GSA official whose departure timing was noted by a source who told FedScoop the plan was to push the memo out before he left. Treasury CIO Sam Corcos was named acting assistant commissioner of Login.gov concurrently, adding the role to existing GSA titles while keeping his Treasury post. The leadership shuffle at the moment of enforcement is unlikely to be coincidence.


Published ·Deep Fathom