The UK is rolling its digital identity plans into 2026 around GOV.UK One Login. Millions already use the service, and the programme—funded to the tune of several hundred million pounds—aims to make One Login the default way to prove identity for public services and to hold digital government documents in a mobile wallet. But the project has hit security and compliance headwinds. I'll walk you through what One Login is doing in 2026, show how to use it, compare it to private alternatives, and spell out the key things organisations and people need to know about privacy, cost and regulation.

Quick reference: the essentials

At a glance — main points for 2026:

  • GOV.UK One Login: free for citizens; intended as the primary government digital ID.
  • Users: more than 6 million people are registered (public figure).
  • Services: One Login already connects to 50+ government services, and now supports a digital Veteran Card launched 17 October 2024.
  • Security and assurance: the programme reported meeting 21 of 39 NCSC CAF outcomes in recent assessments; the project spent c.£330m in its business case.
  • Alternatives: private ID providers and bank-based schemes remain in use — typical per‑check costs for businesses run roughly £0.50–£5 depending on volume and check type.

Overview: what GOV.UK One Login is (and isn't)

Sure, GOV.UK One Login is the government's digital identity and sign‑in platform. It's meant to let people sign in to public services with one account and to store verified government documents in a government digital wallet on a smartphone. It's free for individual users. For public services, it promises simpler sign‑in flows, fewer forms and fewer in‑person checks.

But One Login is different from a bank's digital ID or a commercial verification API; it's a government-run service with different rules and oversight. It's a government service with distinct rules on data handling, oversight by the Information Commissioner's Office (ICO) and technical assurance requirements from the National Cyber Security Centre (NCSC) and the Government Security Group (GovAssure).

Top picks / analysis for different users

Who should use One Login — and when?

  • Everyday citizens using government services: One Login is the simplest option. It's free, integrates with many services and now supports the digital Veteran Card for faster in‑person checks.
  • If you run a public service, you should link to One Login where you can. It will cut user friction, but be ready for integration work and required security assurance checks.
  • For commercial tasks like age checks or customer onboarding, many firms still prefer private ID vendors with flexible APIs and fraud tools. They usually charge per verification. Typical market rates range from about £0.50 per simple document check to £3–£5 for biometric checks and liveness tests depending on volume.

Comparison table: GOV.UK One Login vs common alternatives

Feature GOV.UK One Login Commercial ID providers (typical) BankID / Open Banking ID
Cost to user Free Usually free to download; businesses pay per check Free to users; costs for businesses depend on provider
Typical business cost Integration costs only (no per‑check fee for citizen sign‑in) ~£0.50–£5 per verification depending on type/volume Variable; often mid‑range per transaction
Assurance & audit Subject to NCSC/GovAssure; recent CAF progress reported (21/39 outcomes) Commercial assurance, ISO27001 common; varies by vendor Banks have strong assurance and fraud monitoring
Use cases Signing in to government services; digital government documents Onboarding, high‑risk transactions, age checks Payments, financial onboarding, bank‑grade identity

Prerequisites: what you'll need before you start

Before you sign up for GOV.UK One Login, you'll want to have a few things to hand:

  • A UK phone number and email address.
  • A smartphone able to run the One Login app (iOS or Android).
  • One form of government‑issued ID recommended for verification — passport or driving licence — and a recent selfie for biometric checks.
  • Time: the initial sign‑up and identity verification typically takes under 10 minutes, but complex checks may take longer.

Step‑by‑step: set up GOV.UK One Login (citizen)

  1. Go to https://www.gov.uk/one-login and tap the link to download the One Login app for iOS or Android.
  2. Open the app and create an account with your email address. Choose a strong password and note your recovery options.
  3. Enter your mobile number and confirm via SMS code. This is used for 2‑factor authentication (2FA).
  4. Follow the in‑app prompts to verify your identity. You'll be asked to scan a passport or driving licence and to take a live selfie for biometric checks.
  5. Grant permissions for the app to store verified credentials in the government digital wallet if you want to use the Veteran Card or other documents.
  6. Use One Login to sign in to a supported government service. Look for the 'Sign in with GOV.UK One Login' button on service pages on gov.uk.

Step‑by‑step: integrate One Login (organisations)

  1. Read GOV.UK One Login guidance at https://www.gov.uk/guidance/one-login-for-services. Register as a service provider.
  2. Decide your assurance level and data you need to request. Higher assurance needs stronger checks and more evidence.
  3. Complete the integration steps in the developer documentation and test in the sandbox environment.
  4. Undergo technical and security assurance checks required by NCSC/GovAssure before going live.
  5. Notify users about data handling and keep an accessible privacy notice meeting ICO standards.

Practical tips and costs

Keep these points in mind to avoid surprises.

  • Link to gov.uk URLs in communications. Use https://www.gov.uk/one-login for sign‑in help and https://www.gov.uk for service listings.
  • Expect integration time. Even simple sign‑in setups can take several weeks when assurance and testing are included.
  • Budget for staff time and possible consultancy. While the citizen service is free, organisational integration and security testing will incur costs.
  • For businesses needing identity checks beyond government sign‑in, compare commercial vendors. Ask for volume pricing and SLAs — per‑check tariffs vary widely.
  • Keep a fallback. Not every citizen will verify immediately — keep alternative authentication routes for those without suitable documents or smartphones.

Privacy and safety — what to watch

Data protection is central. GOV.UK One Login is governed by the Data Protection Act 2018 and UK GDPR; the ICO expects transparency and minimal data retention. The NCSC sets technical standards via the Cyber Assessment Framework (CAF) and GovAssure oversees security reviews.

Still, One Login has faced criticism and security testing in recent years. The programme reported progress against CAF, but independent tests and regulatory attention have highlighted areas where controls must be strengthened. Organisations should assume regular security updates and periodic re‑assurance requirements when they integrate.

Common mistakes to avoid

  • Rushing integration without security testing. The NCSC/GovAssure process is mandatory for many services — skipping it delays go‑live.
  • Relying on One Login for high‑risk commercial checks. Use specialist vendors for financial onboarding or fraud‑sensitive transactions.
  • Poor privacy notices. The ICO expects clear, plain‑English explanations of what's collected and why.
  • Ignoring accessibility. Offer alternatives for those who can't use a smartphone or need assistive technologies.
  • Assuming assurance is fixed. Regular reviews and patching are a fact of life — plan for ongoing compliance work.

Related Articles

GOV.UK One Login is central to UK digital ID plans in 2026. It's free to citizens, already used by millions, and is expanding to host government documents in a digital wallet. But the service remains a work in progress from a security and assurance point of view, and many organisations will still need commercial identity checks for high‑risk use cases. For most people, One Login will simplify access to public services. For organisations, the sensible path is to plan integration carefully: follow NCSC and ICO guidance, budget for testing and support, and keep commercial vendor options for anything beyond government authentication.

This article was created with AI assistance.