Government organisations hold identity data on entire populations, run services every citizen depends on, and are persistent targets for nation-state attackers. Public sector identity covers two very different problems: securing the workforce, contractors and systems that run government, and providing digital identity to citizens and businesses who use public services. Both are shaped by mandates such as the US federal zero trust strategy and phishing-resistant MFA requirements, and by national digital identity programmes. This guide maps identity controls to the main public sector requirements in the US, UK and EU. It is a practitioner summary, not legal advice.
Key takeaways
- US federal agencies have a mandate for phishing-resistant MFA and zero trust under OMB M-22-09.
- PIV and derived credentials remain the backbone of federal workforce authentication, alongside FIDO2.
- Cloud services for government are assessed through FedRAMP in the US and equivalent schemes elsewhere.
- Citizen identity services must balance assurance, inclusion and privacy.
- Nation-state campaigns target identity infrastructure itself: federation, signing keys and cloud tenants.
Requirements and frameworks at a glance
| Requirement / framework | Applies to | Identity-relevant themes |
|---|---|---|
| OMB M-22-09 (US) | Federal civilian agencies | Enterprise identity, phishing-resistant MFA for staff, contractors and partners, device inventory, zero trust architecture |
| FIPS 201-3 and PIV (US) | Federal employees and contractors | Personal identity verification credentials, derived PIV credentials |
| NIST SP 800-63-4 (US) | Federal digital identity services | Identity proofing, authentication and federation assurance levels |
| FedRAMP (US) | Cloud services used by federal agencies | Security authorisation based on NIST SP 800-53 controls, including identification and authentication |
| CISA Zero Trust Maturity Model | Federal agencies; widely used elsewhere | Identity pillar maturity from traditional to optimal |
| EU NIS2 Directive | Public administration entities in scope under national law | Access control, MFA, supply chain security |
| UK Government Cyber Security Strategy and Cyber Assessment Framework | UK government organisations | Identity and access control outcomes, resilience |
| eIDAS 2.0 (EU) | Member states and public sector relying parties | European Digital Identity Wallets and acceptance by public services |
Workforce identity in government
- Phishing-resistant MFA for all users, using PIV, FIDO2 security keys or device-bound passkeys. See the MFA Guide.
- Consolidated identity providers for the agency, so policy is enforced once.
- Privileged access with dedicated admin identities, just-in-time elevation and session recording. See the Privileged Access Management Guide.
- Contractor identity with sponsorship, background checks and time limits. See the Third-Party Access Guide.
- Zero trust roadmap aligned to the CISA maturity model. See the Zero Trust Identity Guide.
Protecting identity infrastructure
Government networks have been hit by campaigns that targeted identity systems directly:
- The SolarWinds campaign forged SAML tokens and hijacked cloud application identities.
- The Midnight Blizzard breach abused OAuth applications to read mailboxes, prompting a CISA emergency directive for affected agencies.
- Ivanti Connect Secure exploitation exposed credentials on VPN appliances, including at CISA.
Protect federation signing keys in hardware, monitor for changes to federation trust and application credentials, and treat identity providers and remote access appliances as tier-zero assets. See the Identity Provider and SSO Security Guide and the Cryptographic Key Management Guide.
Citizen and business identity
- National services such as Login.gov in the US and GOV.UK One Login in the UK provide shared sign-in and identity verification for public services.
- Assurance must fit the service: proofing to a higher level for benefits and tax, lower for information services. See the Identity Proofing and KYC Guide.
- Inclusion matters: offer in-person and assisted routes for people who cannot complete digital proofing.
- Benefits and tax services face large-scale identity fraud and need fraud controls alongside proofing. See the Identity Fraud Prevention Guide.
- In the EU, public services will need to accept European Digital Identity Wallets. See the Digital Identity Wallets Guide.
Non-human identities and AI in government
- Inventory service accounts, API keys and cloud workload identities across agencies and suppliers. See the NHI Governance Maturity Model.
- Use workload identity federation instead of static cloud keys. See the Cloud Workload Identity Guide.
- Register AI agents and apply the same authorisation and oversight rules as to other systems handling citizen data. See the Agentic AI Security Policy Template.
Practitioner checklist
- Enforce phishing-resistant MFA for staff, contractors and partners.
- Consolidate identity providers and enforce policy centrally.
- Protect federation signing keys and monitor federation and application credential changes.
- Treat identity providers and remote access appliances as tier-zero assets.
- Apply sponsorship and time limits to contractor identities.
- Match citizen proofing assurance to service risk, with inclusive alternatives.
- Govern NHIs and AI agents with the same rigour as human identities.
- Track zero trust maturity against the CISA model.
Standards and references
- OMB M-22-09: Moving the U.S. Government Toward Zero Trust (2022)
- FIPS 201-3: Personal Identity Verification (2022)
- NIST SP 800-63-4: Digital Identity Guidelines (2025)
- FedRAMP
- CISA Zero Trust Maturity Model
- NCSC Cyber Assessment Framework
This guide summarises identity themes for security practitioners and is not legal advice. Related NHI Mgmt Group resources: Zero Trust Identity Guide · Identity Security Regulatory Map · Digital Identity Wallets Guide · Identity Provider and SSO Security Guide