Identity management

Federal IT Modernization: Why Workforce Identity Is the Missing Piece

Christine Owen

Field CTO

Federal IT modernization is how U.S. government agencies are catching up to a world their legacy systems were never built for. It means moving to cloud infrastructure, adopting zero trust security, and rethinking identity and access management from the ground up. Agencies that don't modernize are left managing growing security gaps while trying to deliver services on infrastructure that was never designed for today's threats or workforce.

IT modernization efforts are ramping up across the federal government. As the tech landscape evolves, along with the federal workforce that relies on that technology, every agency is starting to update its infrastructure.

Those updates take different forms, but they align around several common priorities. The entire government has a mandate to adopt zero trust principles for enhanced security. Agencies must also bring technology in alignment with FedRAMP and other standards to improve quality and consistency. They are making changes in response to a workforce and workplace that are changing quickly, replacing aging systems with alternatives that better align with the opportunities and threats of the AI era.

Sweeping changes are coming to government technology, and in many cases are already underway. Establishing trusted digital identities will play a major role in that effort, especially in places where the legacy IAM infrastructure doesn’t reach. A growing segment of users are not eligible for PIV smart cards yet still require secure and efficient access to government systems.

This raises new questions around identity assurance, authentication, and trust that modernization efforts must answer.

Why federal IT modernization matters

Federal IT modernization matters because the systems agencies built for a simpler era were never designed to handle today's threats, workforces, or the growing web of external partners who now depend on them.

As the federal government has modernized in other areas, it has begun to rely on a large number of “partners” who are neither employees nor contractors. This includes state and local officials, financial institutions, maritime operators, legal representatives, and other entities who collaborate closely with federal officials and agencies. Partners operate outside the high-assurance frameworks built for federal employees and contractors at a time when the federal government is coming under fire across the digital domain.

Cyber attacks on the government, both from nation-state actors and criminal gangs, are becoming more frequent, successful, and damaging. The 2020 Solar Winds hack from 2020 is the most infamous example, but the public sector has experienced years of increasing attacks; over 555 million were observed in October 2025 alone.

Attacks on the public sector are growing at the same time that digital identities are evolving. This convergence creates new risks that modernization must address:

  • A workforce that onboards and operates remotely

  • Contractors and partners working in greater numbers with wider access

  • Credential recovery that must be efficient yet secure

  • Establishing trusted digital identities in an era of AI-driven impostorship

These risks arose long after legacy IAM systems were established, and in many cases they fall outside what existing infrastructure can address. Modernizing identity trust is therefore one of the most important and urgent responsibilities facing government CISOs and CIOs. The challenge is modernizing on top of existing infrastructure rather than replacing it entirely.

The changing state of federal workforce identity

Federal agencies manage vast amounts of sensitive information and provide access to systems that support critical government functions. Deciding who has access to what and authenticating every access request remains a foundational responsibility that has only become more complex as the federal workforce evolves.

Federal workforce identity governance

Workforce identity verification is governed by FICAM together with OMB memos and NIST guidelines. Much of that infrastructure was built for an earlier era where employees worked exclusively in offices, contractors and partners were limited, agencies operated in silos, cyber attacks were insignificant, and technology was located on-premises. Then the COVID-19 pandemic happened, reversing all those trends.

Legacy identity infrastructure no longer covers every scenario

These changes mean that sensitive scenarios around identity trust are now typical. For example, a contractor needs secure access to multiple systems across agencies. Or a remote employee has to verify his identity after losing a smart card but can’t complete an in-person verification process. Once rare, this now happens on a daily basis across the government.

The rapidly evolving federal workforce complicates the notion of identity trust. It increasingly means authenticating people who are not on-site, can’t provide physical documents or use smart cards, and need access to sensitive systems. Legacy infrastructure can still work in many cases. Modernization efforts will need to carefully understand where and why it can’t.

Why non-PIV users create a new identity challenge

To get a sense of where legacy IAM is at odds with today’s federal workforce and tomorrow’s modernization goals, consider a risk that has been quietly rising.

PIV smart cards are effective at establishing trusted digital identities for established employees and contractors. For non-PIV users like federal partners, digital identities do not rise to the same level of trust.

These partners are required to use phishing-resistant methods (FIDO2) to authenticate themselves. Unlike employees and contractors, however, they don’t need to show official documents in-person to obtain smart cards in accordance with IAL3 standards. Often, they don’t even need to scan documents or provide biometric markers as required by IAL2. Instead, they can self assert their identity with little more than a name and email address.

What this means in practice is that Federal partners are held to stronger standards for authentication strength than identity assurance.

As a result, legacy IAM systems may confidently authenticate someone who was never adequately verified in the first place. This disconnect between authentication and assurance introduces a significant risk that bad actors could easily exploit to commit fraud or legitimize impostors. It’s also a violation of the zero trust principles now required at all agencies.

This example highlights one reason federal identity trust needs to be modernized, but it’s not the only example. Even though smart cards remain effective and will continue to be the foundation of identity trust, they cannot be the entire infrastructure. At a time when technology, teams, and threats are all progressing quickly, the federal government needs to rethink how it establishes trust in workforce identities.

Key elements for secure, scalable identity modernization

Legacy IAM provides a valuable starting point on which to build a modernized approach to identity trust. That approach includes:

  • Identity assurance: Verifying the person behind the device, not just the device itself.

  • Standards-based verification: Using standards like Kantara Full Services CSP (which validates NIST 800-63), W3C, and ISO 30107-3 as the basis for identity trust.

  • Workforce identity verification: Establishing trust in employees, contractors, and partners throughout the workforce lifecycle by verifying user identities before proceeding to authentication and access management.

  • Interoperability: Picking solutions that integrate with vendors like Microsoft, Okta, and Ping as well as they integrate with cloud and mobile solutions coming online.

  • Privacy & security: Making identity trust secure against sophisticated nation-state attacks and AI-driven impostorship while keeping user data private and under their control.

  • Future readiness: Choosing solutions that support legacy IAM and meet the immediate needs of modernization but can also expand, evolve, and adapt at the same pace as federal IT.

Identifying solutions that check all these boxes is most effective through the lens of standards. What is considered the highest standards today will be table stakes tomorrow.

The most effective way to maximize identity trust while engineering long-term viability is to select solutions that regulators have already identified as superlative. That makes what could be a subjective decision as objective as possible.

Extending trust beyond traditional workforce boundaries

Federal identity modernization is increasingly becoming a question of identity trust. While existing PIV-based frameworks remain effective for federal employees and contractors, agencies must also address the growing population of external users who require access to federal systems but fall outside traditional identity models.

As workforce ecosystems expand and Zero Trust initiatives mature, establishing trusted digital identities across employees, contractors, partners, and non-PIV users is becoming a foundational requirement for secure, modern government operations.

To learn more about how standards-based identity verification can support your workforce modernization and Zero Trust initiatives, download the guide or reach out to our team for a walkthrough.


FAQs

What is federal IT modernization?

Federal IT modernization is the effort by U.S. government agencies to replace legacy technology with secure, cloud-based systems built for today's threats and workforce demands. It spans cloud migration, zero trust architecture, and modern identity frameworks, all aimed at closing the security and operational gaps that outdated infrastructure leaves behind.

What is an example of federal IT modernization?

One clear example of federal IT modernization is the shift toward standards-based identity verification for non-PIV users like federal partners and contractors. Where legacy systems relied on self-asserted credentials with minimal verification, modern approaches require document scanning, biometric checks, and compliance with NIST 800-63 identity assurance standards before access is granted.

How does workforce identity play into federal IT modernization?

Workforce identity is key for federal IT modernization because as agencies expand access to contractors, partners, remote employees, and now AI agents, establishing trusted digital identities for every user will be a foundational requirement. Without it, even the most modern infrastructure remains vulnerable to impostors, credential abuse, and access that was never properly verified in the first place.

About the author

Christine Owen

Field CTO

Christine is a former attorney who transitioned to Identity and Access Management (IAM) over a decade ago. As the Field CTO at 1Kosmos, Christine works on strategy and supports clients through identity verification and digital identity wallets. Prior to 1Kosmos, she spent 10 years as a consultant for IAM and Zero Trust in the public sector.

The latest in identity security.

Enter our orbit.

The latest in identity security.

Enter our orbit.

The latest in identity security.

Enter our orbit.

Transform how you verify and authenticate

Secure onboarding, eliminate passwords, and stop fraud on one platform. Schedule a demo and see it in action.

Transform how you verify and authenticate

Secure onboarding, eliminate passwords, and stop fraud on one platform. Schedule a demo and see it in action.

Transform how you verify and authenticate

Secure onboarding, eliminate passwords, and stop fraud on one platform. Schedule a demo and see it in action.