Skip to main content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it’s official.
Federal Government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a Federal Government site.

Https

The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

FICAM Program

Introduction

Managed by the GSA Office of Government-wide Policy as an initiative of the Federal CIO Council, the GSA Federal ICAM (FICAM) program assists federal agencies in planning and managing enterprise identity, credentialing, and access management (ICAM). It delivers this support by offering guidance on IT policy, architecture, standards, and implementation, along with opportunities for interagency collaboration. The majority of the best practices and guidance featured on this website originate from collaborative interagency efforts.

The GSA OGP FICAM program distinctively concentrates on government-wide initiatives promoting organizational interoperability, unlike individual agency ICAM programs (such as GSA’s internal enterprise ICAM program) that focus on agency alone.

Federal Workforce Identity Framework

The FICAM Program administers identity federations using a four-component structure:

  • Governance - Establishes guidance to support federal policy, executes legal agreements, evaluates and approves members and applicants, and provides oversight for compliance efforts.
  • Technical and Security Requirements - Delivers implementation guides and playbooks to assist agencies with seamless standards adoption.
  • Recognition - Keeps official list of enrolled members across the federal government inclusive of agency ICAM leads, co-leads, and active contractors.
  • Compliance - Ensures trust by requiring participants and services to undergo second-party (e.g., OIG) or third-party compliance reviews.

Through this four-part framework, the GSA FICAM Program leads and coordinates the following governmentwide functions.

  1. Governance
    • ICAM Governance - Manage and refresh idmanagement.gov, hosting the FICAM Architecture along with supporting playbooks and implementation instructions. Provide executive secretarial and co-chair leadership for the Federal CISO Council ICAM Subcommittee, and spearhead cross-government efforts such as M-26-15 FICAM Modernization Working Group and FIDO2 Community of Action.
    • Federal PKI Governance - Co-chair and support the Federal PKI Policy Authority while evaluating third-party Federal PKI audits.
  2. Technical and Security Requirements
    • FIPS 201 and accompanying Special Publications
    • NIST Special Publication 800-63 series
    • GSA FIPS 201 Functional Requirements and Test Cases
  3. Recognition
  4. Compliance

ICAM Governance Bodies

The GSA FICAM Program coordinates and oversees governmentwide ICAM initiatives as directed by the Federal CISO Council and the Office of Management and Budget. It accomplishes this mission through various governance bodies outlined below.

An organization chart of the FICAM Governance Bodies and Working Groups.

Identity, Credential, and Access Management Subcommittee

The Identity, Credential, and Access Management Subcommittee (ICAMSC) is the principal interagency forum for identity management, secure access, authentication, authorization, credentials, privileges, and access lifecycle management. It’s a sub-committee of the Federal CIO Council’s Chief Information Security Officer (CISO) Council.

The ICAMSC is co-chaired by the GSA Office of Government-wide Policy and the National Science Foundation (NSF). Two other co-chair positions are currently vacant, dedicated to the DHS Cybersecurity and Infrastructure Agency (CISA), and the Small Business Administration (SBA) representative. The ICAMSC aligns the identity management activities of the federal government and supports collaborative government-wide efforts to increase agency flexibility in addressing ICAM challenges, coordinate interagency efforts to meet agency mission needs, identify gaps in policies, procedures, standards, guidance, and services and align ICAM policies and compliance with other cybersecurity initiatives.

Activities

  • Address Agency Challenges - provides opportunities for agencies to troubleshoot issues and challenges associated with the planning, implementation, and operations of ICAM programs and solutions.
  • Develop Policy Recommendations - recommends new ICAM policies and updates existing ones to policy organizations.
  • Provide Flexible Tools for ICAM Programs - develops specific tools to assist agencies’ abilities to meet ICAM policy objectives and overcome ICAM implementation challenges.
  • Facilitate Communications and Information Sharing - acts as a vehicle for cross-government collaboration by sharing information, lessons learned, and best practices related to ICAM.

Membership and Meetings

Membership is open to federal agency employees with a .gov or .mil email address. Contractors are permitted to join on a case-by-case basis. See the ICAMSC Meeting Page on Connect.gov for more information. Access to the page requires a multifactor authentication using a PIV/CAC.

M-26-15 FICAM Architecture Modernization Working Group

On August 12, 2026, an interagency working group was established to update the Federal Identity, Credential, and Access Management (FICAM) architecture pursuant to OMB M-26-15, Execution of the Migration to Post-Quantum Cryptography. The meeting included technical discussions on the primary draft of the modernized FICAM architecture to support Post-Quantum Cryptography (PQC), Non human identities, automation, and other modern identity features. Moving forward, the working group will meet bi-weekly to advance FICAM modernization efforts. The team will publish all group activities within connect gov after each meeting.

FIDO CoA - The Office of Management and Budget’s Office of the Federal CIO, in partnership with the Identity, Credential, and Access Management Subcommittee and Cybersecurity and Infrastructure Security Agency, have launched a Phishing-Resistant Authentication (FIDO2) Community of Action. This group works with Agencies that plan to rapidly deploy a pilot of FIDO2-based phishing-resistant authenticators within their enterprise, Provide agencies with access to expertise and guidance in achieving this goal, and Documents results to help accelerate the modernization of phishing-resistant MFA throughout the Federal Government.

Certificate Policy (CPWG) - The Federal Bridge and Common policies advisory group facilitates proposed Certificate Policy changes, facilitate the FPKI cross-certification process, and address and resolve issues through policy analysis and modification. Members must be Federal employees, designated contractors, and PKI providers involved in the FPKI.

The ICAMSC charters working groups based on a defined-purpose and timeline. See the complete list of active and inactive working groups at the ICAMSC’s Connect.gov page. Send an email to icam@gsa.gov for more information and join a working group.

ICAM Community Listserv

The Federal ICAM Community Technical Listserv (ICAM-COMMUNITY-TECH List) aims to provide a communications platform to share and discuss technical issues impacting the Federal ICAM Community. We hope to leverage the knowledge of ICAM Subject Matter Experts to identify, share, and hopefully resolve technical issues that exist in Agencies and Departments. Federal employees and active contractors with a .gov or .mil email are eligible to join the listserv.

Federal Public Key Infrastructure Policy Authority

The Federal Public Key Infrastructure Policy Authority (FPKIPA) serves the interest of U.S. federal government organizations as relying parties and promotes interoperability between federal and non-federal entities by setting policy governing the Federal Public Key Infrastructure (FPKI) Trust Infrastructure, approving applicants for cross certification with the Federal Bridge Certification Authority (FBCA), and providing oversight to the Certified PKI Shared Service Provider (SSP) Program.

It is co-chaired by the GSA Office of Government-wide Policy and the Department of War (DoW). Working group members include current federal employees and active contractors.

Activities

  • Approve Policies and Practices – Approve Federal Bridge Certification Authority (FBCA) and Federal Common Policy Certification Authority Certificate Policies (CPs), including revisions; approve FPKI Trust Infrastructure Certification Practice Statements.
  • Approve Entity Cross-Certification – Establish and administer criteria and methodology for cross-certification with the FBCA; approve cross-certifications and execute Memoranda of Agreement (MOAs); maintain the FPKI Certification Applicant Requirements and the Common Policy CPS Evaluation Matrix.
  • Maintain Compliance – Ensure cross-certified entities are compatible with the FBCA Certificate Policy (CP) (or the Federal Common Policy Certification Authority (FCPCA) CP for Federal Legacy CAs).
  • Agreement with FPKI Management Authority – Oversee the FPKI Management Authority (FPKIMA) to issue and revoke cross-certificates, ensure adherence to the FPKI CPs, and provide documentation to be archived.
  • Interoperability Practices – Coordinate legal, policy, technical, and business practices and issues related to FPKI Trust Infrastructure.

Membership and Meetings

Members are appointed by each federal agency’s CIO, and the group operates under the authority of the Federal CIO Council through the Information Security and Identity Management Committee (ISIMC) and the Identity, Credential, and Access Management Subcommittee (ICAMSC). See the FPKIPA Charter (PDF, August 2021) for information on membership requirements, voting rights, etc.

The FPKIPA meets in the morning on the second Tuesday of each month. Contact fpki@gsa.gov to participate in the FPKIPA or its working groups.

Federal Public Key Infrastructure Management Authority

The Federal Public Key Infrastructure Management Authority (FPKIMA) enables government-wide trust by providing trust infrastructure services to federal agencies. The FPKIMA is governed under the FPKI Policy Authority (FPKIPA) and managed by the GSA Federal Acquisition Service.

Activities

  • Manage digital certificate policies and standards to ensure secure physical and logical access, document sharing, and communications across federal agencies and between external business partners.
  • Operate the FPKI Trust Infrastructure, which consists of two main certification authorities (CA):
    • Federal Common Policy CA (FCPCA) is the trust anchor for the federal government. Authorized CAs issue certificates for exclusive use by the federal government for federal employees and contractors, to include the PKI certificates on the Personal Identity Verification (PIV) credential.
    • Federal Bridge CA (FBCA) is the PKI Bridge that enables interoperability between and among federally operated and business partner PKIs.

If your agency is experiencing issues related to the FBCA or FCPCA, contact fpki-help@gsa.gov

IDManagement.gov

An official website of the U.S. General Services Administration

Looking for U.S. government information and services?
Visit USA.gov Edit this page