Centralization is an emerging digital identity trend for states, leaders say

NASCIO President JR Sloan addresses the audience during the organization's annual conference Monday, Sept. 28, 2026, in San Diego. Sloan and other state CIOs hosted a discussion on digital identity policies, practices and trends across the U.S. Kaitlyn Levinson/Route Fifty
While an enterprise approach to digital identity is gaining traction across the U.S., some experts also tout a hybrid or phased model.
As everyday services increasingly go digital, states are working to add driver’s licenses and other forms of identification to the list. An enterprise approach to digital identities is also arising as a trend as agencies look to centralize services and capabilities, state chief information officers said at a recent conference.
Credit cards, proof of insurance, boarding passes and now driver’s licenses or other forms of identification in 22 states and Puerto Rico can be accessed with a mobile device.
States are increasingly developing digital identity programs “to create a more seamless ‘digital front door’ for residents while strengthening identity assurance, fraud prevention and cybersecurity,” reads an August report from the National Association of State Chief Information Officers.
At the federal level, the Office of Management and Budget announced a new policy the same month to enforce Login.gov as “the universal sign-on for accessing public services online” as a digital identity solution.
“Identity is so core to everything we do [in government], and if we don’t get it right, we’re going to have a lot of problems,” Bill Kehoe, chief information officer for Washington state, said during a mainstage program at NASCIO’s annual conference in San Diego this week.
Nearly a decade after states began efforts to develop mobile and digital IDs, “research shows a clear movement toward centralized or hybrid identity [management] models," said JR Sloan, NASCIO president and CIO for Arizona.
Indeed, the NASCIO report found that 51% of state tech leaders operate their digital identity programs under a centralized model. That figure is based on responses from 47 state and territorial CIOs, chief information security officers and chief technology officers who were able to select multiple options.
Without an enterprise or centralized management approach, individual agencies are left to build their own digital solutions, driving up costs and spending across organizations, said Ohio CIO Katrina Flory.
As an example, she pointed to a 2019 executive order that has helped pave the way for Ohio to develop an enterprise digital identity service by establishing the common InnovateOhio Platform.
The order stipulates that the platform provides a “definitive digital identity across programs promoting security, privacy and compliance with applicable standards” in a bid to “improve customer service and save tax dollars.”
Washington has similar plans in store, Kehoe said. Gov. Bob Ferguson signed an executive order last September to improve residents’ customer experience with government services. The order established the Your Washington hub and agency, which aims to expand the centralization of the state’s WA.gov resident portal over four years.
One of the state’s priorities under the order is to develop an enterprise “customer identity” for residents, Kehoe explained.
“The outcome should make state government feel seamless to the customer, not like a patchwork of agencies that the customer must navigate,” the order reads.
However, New York is taking a different approach with a hybrid strategy, said Jenson Jacob, the state’s acting CIO. According to the NASCIO report, 38% of respondents reported that they have implemented a hybrid or federated management style for digital identity.
New York state employees are required to have a digital identity because of the state’s consolidated IT infrastructure, but centralization “is not a stick for agencies to conform to,” Jacob said.
Under New York’s hybrid digital identity management, “agencies know the compliance requirements,” such as security and usability standards,” but the Office of Information Technology Services “provides them with the plug-in to build in to,” he explained.
While many states have been eager to stand up their digital identity systems, adoption can be slow among state organizations and residents.
The NASCIO report found that 70% of state tech leaders see inadequate funding or budget as a barrier to implementing enterprise identity solutions, and 68% cited “organizational and cultural resistance.”
“When we realize we're serving our residents and not our agencies, then we're going to be okay. But we still get a lot of, ‘No, we want to do it this way,’” Kehoe said. “We’re trying to change that mindset. That's a real cultural change for our state.”
Indeed, implementing enterprise digital identity across state government “needs to be a bite-sized approach,” Vitaliy Panych, senior advisor at World Wide Technology and former chief information security officer for California, told Route Fifty in a separate interview between conference sessions.
“In California, we started to centralize identities for specific business use cases, like the California Protection Agency’s centralized identity validation for its data request opt-out process,” he said.
The CPPA is required by law to allow residents to request their personal data collection from businesses be limited or restricted, “so we apply identity validation using some of our partners’ tools … that we integrated for a specific use case,” Panych explained. The tools “are built to support other use cases for the future, so breaking [the work] for particularly bite-sized approaches, generally, is a good way to go.”




