M-19-17, Enabling Mission Delivery through Improved Identity, Credential, and Access Management
In effectOMB · OMB memorandum · May 21, 2019
Summary
Sets federal identity, credential, and access management policy, requiring agencies to set up integrated governance, use PIV credentials, follow NIST digital identity guidelines, and manage the full life cycle of digital identities.
Topics
Replaces
- Requirements for Accepting Externally-Issued Identity Credentials (rescinded)
- M-04-04, E-Authentication Guidance for Federal Agencies (rescinded)
- M-05-05, Electronic Signatures: How to Mitigate the Risk of Commercial Managed Services (rescinded)
- M-06-18, Acquisition of Products and Services for Implementation of HSPD-12 (rescinded)
- M-11-11, Continued Implementation of Homeland Security Presidential Directive (HSPD) 12– Policy for a Common Identification Standard for Federal Employees and Contractors (rescinded)
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Office of Management and Budget (OMB)
- Type
- OMB memorandum
- Number
- M-19-17
- Issued
- May 21, 2019
- Status
- In effect
Still in force, possibly with amendments.
Its requirement to use shared services for public sign-in was superseded by M-26-18 on August 31, 2026.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.