BlackLeafwatch the watchmen
Federal identity verification (GSA's Login.gov)

GSA Left Login.gov's Most Urgent Fix Without a Deadline

Summary

The General Services Administration got $187 million in 2021 partly to make Login.gov -- the federal government's single sign-on identity-verification service -- harder to defraud. A [July 2026 GAO testimony](https://www.gao.gov/products/gao-26-109261) finds GSA has since closed three of the four recommendations GAO made to fix it, including certifying it against federal identity-proofing standards. The recommendation still open: GSA has never set a deadline, or even proposed a plan, for fixing the technical problems nine federal agencies flagged years ago -- even as GAO documents stolen identity data being used to redirect Social Security beneficiaries' direct-deposit payments.

By Locusta · July 15, 2026

The General Services Administration () has fixed nearly everything the Government Accountability Office () told it to fix about Login.gov, the federal government's single sign-on identity-verification service. A testimony GAO delivered July 15, 2026 to a House Oversight subcommittee says implemented three of the four recommendations issued since 2024 -- all but the one requiring to set a deadline for fixing technical problems that agencies using Login.gov have been reporting for years.

A single login for the whole government

launched Login.gov in 2017 to give federal agencies a shared way to verify that the person accessing a benefits account, a tax record, or a government website is who they claim to be. By the time reviewed it, Login.gov had been adopted by more than 40 federal and state agencies and signed up over 100 million users. In 2021, the Technology Modernization Fund Board steered about $187 million to expand the service, specifically to strengthen its security and anti-fraud protections and make it easier for agencies to adopt.

What the fraud risk actually looks like

's testimony isn't abstract about the stakes. It states that the Social Security Administration has reported that stolen personal information belonging to beneficiaries has been used to fraudulently redirect their direct-deposit benefit payments -- money meant for retirees and people with disabilities rerouted to someone else's account. The same stolen data says gets used to file fraudulent tax returns and open fraudulent credit accounts using Social Security and driver's license numbers, without the victim's knowledge until the damage is done.

2021 Login.gov modernization funding
$187M
Awarded to strengthen Login.gov's security, anti-fraud protections, and agency adoption -- the same goals the one still-open recommendation targets
Commercial ID-check spend vs. Login.gov
$209.1M
vs. $32.5M agencies spent on Login.gov, FY2020-FY2023 -- about 6.4x more, despite Login.gov serving roughly 3x the users
GAO Login.gov recommendations still open
1 of 4
No timeframe set for fixing the technical issues 9 of 21 agencies flagged, as of the July 2026 testimony
Nine agencies' technical complaints are the one still open
Login.gov challenges reported by the 21 CFO Act agencies using it, as of GAO's October 2024 report
NIST IAL2 noncompliance
12
Technical issues
9
Cost uncertainty
8
Source: GAO, GAO-25-106640, Findings
View data as table
Of the 21 CFO Act agencies using Login.gov as of GAO's October 2024 report, 12 cited NIST IAL2 noncompliance (resolved via GSA's October 2024 certification), 9 cited unresolved technical issues, and 8 cited cost uncertainty (addressed via a new pricing model that took effect July 2024). The technical-issues complaint is the one category GAO's July 2026 testimony says still has no GSA-proposed fix or timeline.
NIST IAL2 noncompliance12
Technical issues9
Cost uncertainty8

Three fixes closed, one never scheduled

's October 2024 report made three recommendations: bring Login.gov into compliance with NIST's digital-identity guidelines, set a completion date for its remote identity-proofing pilot, and document lessons learned from that pilot. closed the second one fast -- it obtained third-party certification that Login.gov met the NIST IAL2 standard on October 9, 2024, just before the report even published. A June 2025 follow-up report added a fourth recommendation, on testing the integrity of Login.gov's backup data -- had left that policy unfinished because its security engineering team wasn't fully staffed until January 2024. By the July 2026 testimony, that one was closed too.

What's left is the recommendation that 's Technology Transformation Services division "propose actions to address the technical challenges that the agencies identified... and develop mutually agreed-upon time frames for taking those actions" -- 's own standard for what counts as actually fixing agency complaints, not just acknowledging them. has done neither.

's record on this specific category isn't new. In the same 2024 report, found that Login.gov billed partner agencies more than $10 million for IAL2-level service through May 2022 -- after 's own Technology Transformation Service had been told in 2020 that those IAL2 services weren't actually available, and even after notifying agencies in February 2022 that the service didn't meet NIST's standard. The Small Business Administration told GAO the noncompliance finding was enough to pause its own plans to adopt Login.gov entirely, forcing it into extra reviews of the system's costs and security.

Agencies paid 6.4x more for commercial ID checks
Public-facing identity-proofing spending by CFO Act agencies, FY2020-FY2023 ($ millions)
Commercial vendors (ID.me, LexisNexis, Okta, Experian)
209.1
Login.gov
32.5
Source: GAO, GAO-25-107000, Table 7
View data as table
Between FY2020 and FY2023, CFO Act agencies spent about $209.1 million on commercial identity-proofing vendors versus $32.5 million on Login.gov -- even though about 190 million users relied on Login.gov in that span, compared with about 60 million across the four commercial vendors combined.
Commercial vendors (ID.me, LexisNexis, Okta, Experian)209.1
Login.gov32.5

Paying more for less certainty

That unresolved friction shows up in the money. Between fiscal 2020 and 2023, the 24 Act agencies spent about $209.1 million on commercial identity-proofing vendors like ID.me, LexisNexis, Okta, and Experian, versus $32.5 million on Login.gov -- despite Login.gov handling roughly 190 million users to the commercial vendors' combined 60 million over the same span. Agencies aren't choosing commercial vendors because Login.gov can't handle the volume; six agencies run Login.gov alongside a commercial system specifically to cover the gaps Login.gov hasn't closed, and three -- including, per , agencies deterred by the compliance and technical problems documented here -- skip it altogether.

The takeaway

  • fixed the fixes with clear finish lines and left the open-ended one. Certifying against a technical standard and setting a pilot completion date are checkable, one-time actions; did both. Committing to timeframes for an ongoing category of agency complaints requires an operational plan -- and as of July 2026, says that plan still doesn't exist.
  • The harm cites isn't hypothetical. The Social Security Administration has already reported stolen identity data being used to redirect beneficiaries' direct-deposit payments -- a live consequence of the identity-verification gaps this recommendation is meant to close, not a risk model.
  • has billed for compliance it didn't have before. The 2020-2022 episode, where Login.gov kept charging agencies for IAL2-level service after being told internally it wasn't available, shows the technical-issue recommendation isn't 's first unresolved gap in this exact system -- it's a pattern is now trying to close with a deadline requirement specifically because acknowledgment alone hasn't worked.

's July 2026 testimony states has implemented all but one of the recommendations issued in its October 2024 and June 2025 Login.gov reports; this piece counts those as three closed of four total (three from the 2024 report, one from the 2025 report). The 12-NIST/9-technical/8-cost-uncertainty challenge counts and the 21-of-24-agency usage figure are from 's October 2024 fieldwork and may not reflect current adoption. The NIST-noncompliance and cost-uncertainty categories are described by as resolved through the October 2024 IAL2 certification and a new pricing model effective July 2024, respectively; only the technical-issues category is identified in the July 2026 testimony as still lacking a -proposed fix or timeframe.

The $10 million IAL2 improper-billing figure covers billing through May 2022 and is disclosed in the 2024 report as background on 's Office of Inspector General findings -- it is not itself one of 's four open-or-closed Login.gov recommendations. No document reviewed here puts a dollar figure on losses from the identity fraud it describes; the benefit-redirection and tax/credit-fraud examples are cited as documented harm mechanisms, not quantified totals.

Sources(3) ▾
  • U.S. Government Accountability Office, Identity Verification: GSA Needs to Address Fraud Threats and Technical Issues (GAO-26-109261) (2026-07-15)Testimony delivered before the House Oversight Subcommittee on Government Operations summarizing 's Oct. 2024 and June 2025 Login.gov reports plus updated information from on recommendation status; source of the $187M 2021 funding figure, the fraud-harm example, and the current one-recommendation-still-open status as of the testimony date. gao.gov · original document
  • U.S. Government Accountability Office, Identity Verification: GSA Needs to Address NIST Guidance, Technical Issues, and Lessons Learned (GAO-25-106640) (2024-10-16)Full report text (Dec. 2022-Oct. 2024 audit) on Login.gov's adoption, agency-reported benefits/challenges, NIST alignment, and pilot practices. Source of the three 2024 recommendations, the 21-of-24-agency usage split, the technical/NIST/cost challenge counts, and the IAL2 improper-billing finding. files.gao.gov · original document
  • U.S. Government Accountability Office, Identity Verification: GSA Should Demonstrate Its Implementation of Policies for Testing Data Backups on Login.gov (GAO-25-107000) (2025-06-03)Full report text comparing Login.gov and commercial identity-proofing vendors' NIST data-protection practices and FY2020-2023 agency spending/usage. Source of the $209.1M-vs-$32.5M spending comparison, the 190M-vs-60M user comparison, the backup-testing gap, and the one 2025 recommendation. files.gao.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account