Join our Newsletter — 33% off our NHI Course
Home› Guides› Public Sector Identity Security Guide
Guide Governance, Risk & Compliance

Public Sector Identity Security Guide

← All guides
By Lalit Choda, NHI Mgmt Group Updated 27 September 2026 5 min read
On this page

Government organisations hold identity data on entire populations, run services every citizen depends on, and are persistent targets for nation-state attackers. Public sector identity covers two very different problems: securing the workforce, contractors and systems that run government, and providing digital identity to citizens and businesses who use public services. Both are shaped by mandates such as the US federal zero trust strategy and phishing-resistant MFA requirements, and by national digital identity programmes. This guide maps identity controls to the main public sector requirements in the US, UK and EU. It is a practitioner summary, not legal advice.

Key takeaways

  • US federal agencies have a mandate for phishing-resistant MFA and zero trust under OMB M-22-09.
  • PIV and derived credentials remain the backbone of federal workforce authentication, alongside FIDO2.
  • Cloud services for government are assessed through FedRAMP in the US and equivalent schemes elsewhere.
  • Citizen identity services must balance assurance, inclusion and privacy.
  • Nation-state campaigns target identity infrastructure itself: federation, signing keys and cloud tenants.

Requirements and frameworks at a glance

Requirement / frameworkApplies toIdentity-relevant themes
OMB M-22-09 (US)Federal civilian agenciesEnterprise identity, phishing-resistant MFA for staff, contractors and partners, device inventory, zero trust architecture
FIPS 201-3 and PIV (US)Federal employees and contractorsPersonal identity verification credentials, derived PIV credentials
NIST SP 800-63-4 (US)Federal digital identity servicesIdentity proofing, authentication and federation assurance levels
FedRAMP (US)Cloud services used by federal agenciesSecurity authorisation based on NIST SP 800-53 controls, including identification and authentication
CISA Zero Trust Maturity ModelFederal agencies; widely used elsewhereIdentity pillar maturity from traditional to optimal
EU NIS2 DirectivePublic administration entities in scope under national lawAccess control, MFA, supply chain security
UK Government Cyber Security Strategy and Cyber Assessment FrameworkUK government organisationsIdentity and access control outcomes, resilience
eIDAS 2.0 (EU)Member states and public sector relying partiesEuropean Digital Identity Wallets and acceptance by public services

Workforce identity in government

  • Phishing-resistant MFA for all users, using PIV, FIDO2 security keys or device-bound passkeys. See the MFA Guide.
  • Consolidated identity providers for the agency, so policy is enforced once.
  • Privileged access with dedicated admin identities, just-in-time elevation and session recording. See the Privileged Access Management Guide.
  • Contractor identity with sponsorship, background checks and time limits. See the Third-Party Access Guide.
  • Zero trust roadmap aligned to the CISA maturity model. See the Zero Trust Identity Guide.

Protecting identity infrastructure

Government networks have been hit by campaigns that targeted identity systems directly:

Protect federation signing keys in hardware, monitor for changes to federation trust and application credentials, and treat identity providers and remote access appliances as tier-zero assets. See the Identity Provider and SSO Security Guide and the Cryptographic Key Management Guide.

Citizen and business identity

  • National services such as Login.gov in the US and GOV.UK One Login in the UK provide shared sign-in and identity verification for public services.
  • Assurance must fit the service: proofing to a higher level for benefits and tax, lower for information services. See the Identity Proofing and KYC Guide.
  • Inclusion matters: offer in-person and assisted routes for people who cannot complete digital proofing.
  • Benefits and tax services face large-scale identity fraud and need fraud controls alongside proofing. See the Identity Fraud Prevention Guide.
  • In the EU, public services will need to accept European Digital Identity Wallets. See the Digital Identity Wallets Guide.

Non-human identities and AI in government

Practitioner checklist

  • Enforce phishing-resistant MFA for staff, contractors and partners.
  • Consolidate identity providers and enforce policy centrally.
  • Protect federation signing keys and monitor federation and application credential changes.
  • Treat identity providers and remote access appliances as tier-zero assets.
  • Apply sponsorship and time limits to contractor identities.
  • Match citizen proofing assurance to service risk, with inclusive alternatives.
  • Govern NHIs and AI agents with the same rigour as human identities.
  • Track zero trust maturity against the CISA model.

Standards and references

This guide summarises identity themes for security practitioners and is not legal advice. Related NHI Mgmt Group resources: Zero Trust Identity Guide · Identity Security Regulatory Map · Digital Identity Wallets Guide · Identity Provider and SSO Security Guide

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 27 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org