SSA's Public Credentialing and Authentication Process
No material or nonsubstantive change to a currently approved collection
No
Regular
Approved without change
08/12/2024
08/08/2024
In accordance with 5 CFR 1320, this information collection is approved
table that charts list comparision
Inventory as of this Action
Requested
Previously Approved
02/28/2027
02/28/2027
02/28/2027
193,030,126
0
136,832,911
3,280,597
0
3,684,290
0
0
0
The Social Security Administration's citizen authentication process enables a new user experience and access to more electronic services. Authentication is the foundation for secure, online transactions. Identity authentication is the process of determining, with confidence, that someone is who he or she claims to be during a remote, automated session. It comprises three distinct factors: something you know, something you have, and something you are. Single-factor authentication uses one of the factors, and multi-factor authentication uses two or more of the factors. Social Security's process features credential issuance, account management, and single- and multi-factor authentication. We allow our users to maintain one User ID, which consists of a self-selected Username and Password, to access multiple Social Security electronic services. This process provides the means for authenticating users of Social Security's sensitive electronic services and streamlines access to those services. The respondents are individuals who choose to use the Internet or Automated Telephone Response System to conduct business with SSA.
This is an IT Mod Change Request to move another application currently accessible through IRES (0960-626) to the agency's Public Credentialing and Authentication Process (OMB Clearance No. 0960-0789). We are removing the application from IRES to move it to behind the more secure authentication process (under 0960-0789).
We show an overall decrease as we no longer accept new registrations through eAccess, and require new users to register using either ID.me or Login.gov (we do not account for the burden for registering through ID.me or Login.gov here to avoid double counting the burden). In addition, we have also noted an overall decrease in burden for accessing mySocial Security accounts though ID.me and Login.gov sign-ins; however, we also accept eAccess sign-ins for users who formerly registered through eAccess. Finally, we are also recording a burden increase of 5,825 new registrations/sign-ins as we have moved the Internet Representative Payee Accounting (iRPA) application behind the mySocial Security portal for access through eAccess sign-ins. For ease of noting the new users, we included them in a new IC; however, when we next resubmit this ICR for approval, we will include those new registrations under either ID.me or Login.gov where they belong.
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.