Why It Matters

GAO told Congress that the federal government’s identity verification service has resolved most previously identified weaknesses, but one key technical recommendation remains open as agencies confront growing fraud and identity-theft risks. A GAO testimony delivered July 15 before the House Oversight and Government Reform Subcommittee on Government Operations found that the General Services Administration has implemented most prior recommendations concerning Login.gov, but one recommendation remains open.

The outstanding recommendation focuses on the fact that GSA has not established mutually agreed-upon time frames with partner agencies for resolving technical challenges those agencies have reported with Login.gov. Without proposed actions and deadlines, GAO warned that agencies will continue experiencing technical issues with the system.

The fraud context makes this more than a procedural matter. The Social Security Administration has reported that beneficiaries' personal information has been used to fraudulently redirect direct deposit benefits. Stolen personally identifiable information can also enable fraudulent credit card applications using Social Security and driver's license numbers. Login.gov is designed to help agencies verify that people accessing government services and benefits are who they claim to be, and GAO said fully implementing its remaining recommendation would help better protect personal information and reduce identity-theft risks.

GSA has made measurable progress. The agency completed its remote identity-proofing pilot and began offering services that comply with federal digital identity guidelines. It also demonstrated that it had begun testing Login.gov data backups as required by policy. Three of GAO's four recommendations from the two underlying reports have been implemented, leaving one open.

Broader Context

The testimony draws primarily from two earlier GAO reports: GAO-25-106640 (Identity Verification: GSA Needs to Address NIST Guidance, Technical Issues, and Lessons Learned, October 2024) and GAO-25-107000 (Identity Verification: GSA Should Demonstrate Its Implementation of Policies for Testing Data Backups on Login.gov, June 2025). The testimony updates Congress on GSA's progress implementing recommendations from those reviews.

GSA launched Login.gov in 2017 as a government-wide system for verifying the identities of people accessing federal websites. In 2021, GSA allocated about $187 million in Technology Modernization Fund money to enhance Login.gov, including strengthening security and anti-fraud protections and making the service easier for agencies to adopt. The system uses a nonbiometric, three-step identity verification process and security measures including encryption, access restrictions, and monitoring capabilities.

The prior reports identified four principal implementation challenges: regularly backing up Login.gov data, aligning the service with National Institute of Standards and Technology digital identity guidelines, resolving technical challenges reported by agencies, and documenting and applying lessons learned from pilot programs.

GAO's October 2024 review found that 21 of the 24 Chief Financial Officers Act agencies used Login.gov for identity-proofing services. Nine agencies reported technical issues, while 12 cited the platform's lack of alignment with NIST guidelines. GSA subsequently addressed the NIST and pilot-program recommendations, but GAO continues to classify the technical-issues recommendation as open and partially addressed.

The Bottom Line

GSA has closed most of the gaps GAO identified in 2024 and 2025, but the remaining recommendation has a direct operational consequence. GSA has developed a public roadmap and created a Partner Advisory Group, but GAO says those steps do not demonstrate that the specific technical challenges agencies identified have been resolved or that mutually agreed-upon time frames have been established.

GAO will continue monitoring GSA's progress. Until those time frames are established, the federal government's government-wide identity verification service retains an unresolved implementation gap as fraud and identity-theft threats continue to evolve.

Spot something wrong? Report an issue with this article