GAO: Login.gov needs partner timeframes for reported technical fixes
A new Government Accountability Office report says GSA has not set mutually agreed time frames with the agencies that rely on Login.gov to fix technical challenges those agencies reported. GAO says that accountability gap can leave technical and anti-fraud weaknesses in place longer than partners and users should have to tolerate.
Quick context: what Login.gov is
Login.gov is a government-wide identity verification service built to help ensure that people accessing online federal benefits and services are who they say they are. GAO says Login.gov uses a non-biometric, three-step process to verify identity and adds protections like encryption, access restrictions, and monitoring.
On the user side, Login.gov’s help page describes a typical verification flow:
- Photos of your ID online (and sometimes a selfie)
- Enter your Social Security number to verify personal information
- Verify your phone number and get a one-time code (or, in some cases, verify by mail)
- Re-enter your password to store verified information and connect it to the partner agency you’re trying to access
What GAO found: progress, but one key accountability gap remains
GAO says it previously identified multiple challenges in GSA’s implementation of Login.gov (including alignment with federal digital identity guidance and resolving technical challenges reported by agencies). GAO also says GSA has taken steps to implement most of GAO’s earlier recommendations.
But GAO highlights one remaining issue: GSA has not established time frames with its partners for addressing agency-reported technical challenges. GAO warns that without proposed actions and time frames, agencies will continue to experience technical issues with the system.
GAO notes that in December 2024, GSA developed a public Login.gov roadmap and created a Partner Advisory Group for structured discussions. GAO says those steps do not fully show that the specific technical challenges were addressed or that mutually agreed time frames were established for fixing them.
Why it matters: stolen PII and the real fraud-risk backdrop
GAO’s report places the accountability problem in a broader fraud-threat context. GAO says increased cyberattacks have raised the risk that stolen personally identifiable information (PII) could be used to commit fraud—such as fraudulently obtaining government benefits or conducting tax fraud, and financial fraud involving account openings and similar schemes.
GAO is not claiming this report proves Login.gov was breached. Instead, GAO is warning that when identity verification systems keep experiencing unresolved technical problems without clear partner timelines, it can extend the period in which fraud attempts can exploit weak spots and in which agencies may lack the visibility or controls they need.
Standards connection: what “good” identity proofing requires
GAO’s concerns also connect to federal identity-proofing standards. NIST guidance emphasizes that identity proofing should follow documented procedures (including the steps and evidence needed for the targeted assurance level) and include operational controls such as timely completion and fraud-related checks.
In GAO’s view, unclear partner commitments and missing time frames make it harder to demonstrate that the system consistently meets those assurance expectations in practice.
What to watch next
The next real benchmark is whether GSA and participating agencies agree on concrete time frames for addressing the specific technical challenges GAO says are still unresolved—and whether progress gets tracked in a way GAO can validate over time.
For everyday users, the practical question is simpler: will Login.gov’s identity verification become more reliable and more consistently aligned with anti-fraud expectations as those partner timelines finally get set?
Sources
- GAO report (summary): GAO-26-109261
- GAO-26-109261 full report
- Login.gov: “Verify your identity” (user steps)
- NIST SP 800-63A (IAL general)
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.