One front door: What OMB’s new Login.gov mandate means for agencies
The Office of Management and Budget recently made Login.gov the front door for federal public services. OMB M-26-18 gives agencies two years to deploy it, and if you miss the deadline, your agency head signs a personal letter to Congress explaining why.
Having run identity for one of the biggest benefit-delivering agencies in government, I think this is the right move. I also think the next two years are going to be harder than the memo makes them sound. Here’s my take on what it means for agencies, and for the vendors who serve them.
I’ve lived this problem
When I was the chief information security officer at a federal agency, digital identity wasn’t an abstract policy topic. It was the front door to benefits that millions of Americans depend on. When someone couldn’t get through identity verification online, they didn’t give up — they picked up the phone or drove to a field office. Every failed sign-on became a more expensive, slower interaction somewhere else in the system.
So when M-26-18 says the government’s patchwork of sign-ons creates “unnecessary burden and inefficiencies for the public and Government alike,” I’m not reading a talking point; I’m reading real user experience. The public juggles multiple credentials, sometimes for services inside the same agency, and the government pays over and over to verify the same person against data it often already owns. Consolidating on one front door is the right direction.
What the memo actually says
Strip away the footnotes and it comes down to four things:
- Every in-scope public-facing website has to offer Login.gov, and the big customer-facing services, within one year, and everything else within two.
- Login.gov becomes the default for identity verification too, unless an agency documents why it can’t serve a specific population or mission.
- Everything else gets phased out over time. Other sign-on options survive only where Login.gov genuinely can’t do the job or where forcing millions of existing users to re-enroll would do more harm than good.
- Agencies have 240 days to do real risk work, assurance levels selected and documented under the National Institute of Standards and Technology digital identity guidelines, not assumed.
And the accountability piece is what makes this different from the stack of memos agencies have slow-rolled over the years: miss the deadline, and the head of your agency personally certifies to OMB and Congress why. I’ve watched plenty of IT mandates die quietly. Secretaries signing letters to Congress is not quiet.
What this means for agencies
First, the 60-day website inventory is going to be humbling. Ask any federal CISO whether they can name every public-facing site with a login box and watch their face. Shadow portals and legacy program-office apps are about to surface, and the chief information officer owns the reporting.
Second, and this is the part I’d put on every agency leadership team’s whiteboard, the memo doesn’t just ask you to deploy something — it asks you to watch whether it works. Pass rates. Abandonment rates. How long verification takes. That’s the same shift I’ve been talking about all year across federal cyber policy: We’re moving from proving a control exists to proving it works. If the only identity metric you can produce is your authority to operate date, you’re measuring the wrong thing.
Third, verification becomes a shared service you trust rather than a process you own. The memo tells agencies to accept previously verified Login.gov credentials instead of re-verifying, and to put any extra fraud controls inside their own boundaries rather than turning people away at the door. That’s a real culture change for agencies used to controlling identity end to end, and it moves the interesting security work to what happens after sign-on.
What this means for vendors
If your business is selling sign-on directly to agencies, the map was just redrawn. Commercial identity providers with direct agency contracts now live under a phase-out presumption, re-tested regularly against how many active users they still have, with Login.gov promoted as the default for every new account. Big existing user bases buy time, but the trajectory is clear.
Here’s the part I’d encourage vendors not to miss: The back door opens as the front door closes. Login.gov integrates commercial tools, and the General Services Administration has 180 days to hold an industry day on technologies it could bring into the platform. Document verification, biometrics, device intelligence, identity data — the opportunity shifts from selling to 20 agencies to becoming part of the platform that serves all of them. And because agencies now put fraud controls inside their own boundaries, there’s a growing market for the analytics that sit behind the sign-on and feed the Security Operations Center.
Where I’m skeptical
I’ll be honest about the gaps, because that’s the job. Login.gov’s track record on identity-proofing assurance hasn’t been spotless, GSA’s own inspector general called the program out in 2023, and taking on the whole federal public-facing estate is a different order of magnitude. The memo doesn’t address funding, and the integration invoices will arrive before the economies of scale do. And the populations left out of scope, caregivers, representatives, organizations, aren’t edge cases at a benefits agency. They’re a core service channel, and their identity problem is still unsolved.
Five things I’d do now
- Start the website inventory today. The sites you can’t find in 60 days are your compliance problem at year two.
- Treat the risk assessment as a decision, not paperwork. Assurance levels are where you either right-size friction or lock in years of frustrated users.
- Instrument outcomes from day one. Pass rates and abandonment rates belong in the deployment plan, not bolted on at month 18.
- Map your current identity vendor exposure and the migration path for those user bases.
- If you’re a vendor: Reposition toward the platform and the agency boundary. That’s where the next decade of this market lives.
The bottom line
I’ve said for years that cybersecurity is the art and science of maintaining operations. For public-facing services, identity is where operations begin — it’s the first thing a citizen touches and the first thing an adversary probes.
Agencies that treat M-26-18 as a deployment checkbox will meet the deadline and miss the point. Agencies that use it to finally measure whether their identity controls work for the people they serve will come out of the two-year window with something better than compliance: evidence.
Want to go deeper? Read the memo itself and NIST’s digital identity guidelines.
Timothy Amerson is the federal CISO at GuidePoint Security and president of the board of directors for The KEY (Keep Elevating Yourself) Community. He previously served as CISO at the Social Security Administration, where he was recognized as a 2024 FedScoop Top 50 Federal Leader Nominee and a 2025 CyberScoop Government Leader.