Twenty-Three Million Accounts, One Login
GOV.UK One Login is now the single sign-in layer for more than 23 million users across UK government services, a milestone that is easy to undersell because consolidation projects rarely generate headlines the way new features do. Before One Login, citizens accessing government services faced a patchwork of roughly 190 separate account systems built by different departments over different decades, using 44 different sign-in methods between them. First trialed in 2020, the platform has spent six years absorbing that fragmentation into one identity layer, with HM Revenue and Customs among the largest and most complex departments to migrate onto it.
That consolidation work is the unglamorous prerequisite for everything the platform can now do at population scale, including this month's passkey rollout. You cannot ship a unified authentication upgrade to 23 million people across dozens of services if those services are still running their own separate login stacks with their own separate security assumptions. The passkey announcement is a feature release. The six-year consolidation underneath it is the actual infrastructure achievement, and it is the part of this story most directly relevant to any enterprise still managing identity across a sprawl of acquired systems and departmental logins.
What Actually Changed This Week
The specific change is straightforward: One Login users can now sign in using a passkey, a PIN code, fingerprint, or facial biometric tied to their own device, instead of a password paired with a text message verification code. The Department for Digital, Culture, Media and Sport, now home to the Government Digital Service that built the platform, says adopting a passkey lets users sign in up to eight times faster than the password-and-SMS flow it replaces. More than 100,000 users tested the feature in a trial before the wider launch, and one in ten of all daily One Login sign-ins now use a passkey following that initial rollout wave.
Digital government minister Stephanie Peacock framed the change in plainly practical terms: nobody enjoys hunting for a forgotten password or waiting for a text message code just to check a tax return or renew a document, and passkeys mean people can access the services they rely on in seconds using the same fingerprint or face scan they already use to unlock their phone. That framing matters because it targets adoption friction directly rather than leading with a security pitch citizens tend to tune out. The security case is real, but the speed argument is what will actually move usage past the current one-in-ten share.
The Security Case, Not Just the Convenience Case
The National Cyber Security Centre has been explicit that passkeys are not just a faster login, they are a materially different security posture. Passkeys are tied to a specific device and website, cannot be guessed or reused, and leave no password for scammers to steal in the first place. NCSC director for national resilience Jonathon Ellison put it directly: cybercriminals often look for the easiest route into important accounts, which means login credentials remain a common target, and passkeys offer a highly phishing-resistant alternative that frustrates attackers while saving users time. Passkey data itself never leaves the user's device and is not collected by One Login or any other part of government.
That device-bound design is what makes passkeys resistant to the credential-stuffing and phishing techniques that compromise passwords at scale, including SMS-based two-factor codes, which remain vulnerable to SIM-swap attacks and interception. Eliminating the SMS step entirely also produces a smaller but concrete operational benefit: the shift is already saving roughly 800 pounds a day in text message verification costs, a savings figure that will compound as passkey adoption climbs beyond its current one-in-ten share of daily sign-ins across a user base this large.
A Program That Was Not Always This Smooth
This milestone lands after a genuinely rocky period for One Login that is worth remembering before treating the platform as a straightforward success story. The system lost its formal digital identity trustmark, the accreditation confirming it meets government identity assurance standards, for nine months, only regaining it in February. Reporting last year revealed that senior officials working on the program had internally warned it was carrying a high level of risk, and the Government Digital Service has since engaged an outside security consultancy to run the platform through a formal cyber-resilience audit aligned with the latest NCSC service assessment regime.
None of that history should be read as a reason to discount the passkey milestone. It should be read as context for how much sustained investment and correction it took to get a population-scale identity platform to the point where a feature like this can ship with confidence. Programs of this size rarely move in a straight line from pilot to full accreditation to feature velocity, and One Login's timeline, six years from first trial to this rollout, with a real accreditation lapse in the middle, is a more honest picture of large-scale identity consolidation than most vendor case studies present.
The Consolidation Lesson Behind the Headline
Most enterprises carry their own version of the pre-One Login problem: identity systems accumulated through acquisitions, departmental autonomy, and legacy applications nobody wanted to touch, each with its own authentication logic and its own security assumptions. The lesson from One Login is not that passkeys are the answer, plenty of enterprise identity providers already support them. The lesson is that the passkey rollout was only possible because the harder, less visible consolidation work happened first, and that work took years, survived a lost accreditation, and required sustained executive sponsorship through a period when the program was reportedly carrying real risk internally.
For CIOs running identity consolidation initiatives of their own, the sequencing matters more than the end-state architecture. Trying to layer modern authentication, passkeys, adaptive risk scoring, unified session management, onto a fragmented identity estate tends to produce exactly the kind of high-risk, trustmark-losing period One Login went through internally before it stabilized. Consolidating the underlying identity layer first, even when it produces no visible feature for years, is what made this month's genuinely impressive rollout number, eight times faster sign-in for 23 million people, possible at all.
What Enterprise IAM Teams Should Take From This
If your organization is still running separate login systems across business units, acquired companies, or legacy applications, One Login's six-year timeline is a useful benchmark to set expectations internally before your own consolidation project starts. Passkey adoption, or any modern authentication upgrade, is the easy, visible part once the identity layer underneath is unified. The consolidation itself is where the multi-year budget, the accreditation risk, and the executive sponsorship actually need to go, and it is the part of the roadmap most likely to get deprioritized in favor of a faster, more demoable feature.
The concrete numbers here are also worth borrowing directly for your own business case: eight times faster sign-in, phishing resistance that removes an entire attack category rather than mitigating it, and a measurable cost reduction from eliminating SMS verification at scale. Those are the same arguments that will justify passkey investment inside your own organization, provided the underlying identity consolidation has already happened. If it has not, the more urgent project is the unglamorous one nobody will write a headline about, unifying the login systems you already have before adding a faster way to sign into any of them.



