New ID type: Mobile Driver’s Licenses coming soon
We are excited to announce that users will soon have the option to use a mobile driver’s license (mDL) as evidence in our remote identity flow. We are excited about this capability because it provides another option to simply and securely verify your identity. Using an mDL eliminates document photo capture and manual address entry and allows greater privacy control as users can preview the specific attributes shared. We are finalizing some of the remaining details and will be sharing a roll-out plan in follow-up communications. You can also reach out to us at partners@login.gov with any questions.
New ID type: Passport cards for remote identity verification
Beginning at the end of July, we will accept U.S. passport cards (in addition to U.S. passport books) as part of the remote identity verification flow on a percentage-based gradual roll out. This update gives users another option for verifying their identity online and may help reduce barriers for individuals who have a passport card but not a passport book. No action is required from partners at this time, but partners may wish to update user-facing guidance or support materials to reflect this expanded document option.
Pricing Reminder: Invoices coming in August
As a reminder, our new pricing model took effect on July 1, 2026. Your July invoice, which is scheduled to be sent during the third week of August, will reflect these updated rates. If you have any questions regarding these changes, please reach out directly to your Account Manager.
Rev 4 Update: Alignment Status
Effective July 31, 2026, Login.gov is now fully aligned with the guidelines outlined in NIST Special Publication 800-63 Revision 4 based on our own self-assessment. The new guidelines were published a year ago and there has been tremendous effort to conform to the new guidance, as you heard about in our last partner webinar, including assessing our platform relative to the new guidance, maturing our risk management practices, implementing new technical controls, and documenting evidence of alignment.
Rev. 4 Update: Third-Party Assessment Status
We have a third party assessment of our services underway against the Rev 4 guidelines. Our independent assessor has recently provided Login.gov with its readiness and scheduling for Rev 4 assessments, which will begin in the next few weeks. We are working closely with the assessor to complete certification as efficiently as possible and will notify partners promptly of any schedule changes.
In the meantime, Login.gov’s identity services, security, privacy, and fraud controls remain fully operational and unchanged. This is a certification-timeline update, not a change to the service or its protections. We will continue to operate under our current compliance certification under NIST 800-63 Revision 3, and are concurrently seeking renewal against that version.
Rev 4 Update: Documentation available upon request
In aligning with Rev 4, we are providing partners with the Digital Identity Acceptance Statements (DIAS) and supporting documentation upon request to support your Digital Identity Risk Management. Items dependent on the final assessment are identified as provisional and will be confirmed upon certification. These documents include:
- Digital Identity Acceptance Statement (DIAS)
- Practice Statement
- AI/ML usage details including test results
You can request copies of any of these by emailing partners@login.gov.
Rev 4 Update: Update on new IdV policy - No identity proofing of minors
As noted in our last newsletter, we updated our Rules of Use to allow only users 18 and older to create new identity verification accounts. As part of this change, all users will be asked to review and re-accept our Rules of Use.
In FY27, we will explore how to support users under 18 in a manner that meets NIST requirements.
Rev 4 Update: Expiration timeline for verify-by-mail
We updated the expiration timeline for verify-by-mail expiration codes sent to a validated address within the contiguous U.S. to 21 days, where codes sent to non-contiguous will continue to expire after 30 days. (Non-contiguous are: Alaska, Hawaii, U.S. territories, and military bases). This change went into effect on July 30, 2026.
Rev 4 Update: Providing information on the latest authentication event
We updated our OIDC and SAML protocols to include the relevant timestamp for user authentication in the attribute bundle sent to the relying party.
Launch of reCAPTCHA for enhanced sign in protection
We are excited to announce that we have now fully implemented Google reCAPTCHA, a tool for detecting and blocking bot traffic, for users at sign in. This will help safeguard accounts by preventing credential stuffing attacks, where fraudsters attempt to gain unauthorized access using large numbers of stolen email and password combinations. We’re committed to staying ahead of emerging threats and making sure your users have a secure, seamless experience every time they sign in. If a legitimate user has any trouble passing the security check, they can find step-by-step guidance on our Help Center page.