All bills
HR9152 Referred to committee

VETRA Act

Bill Text

Version IH
This Act may be cited as the Veterans Electronic Trust and Records Authentication Act or the VETRA Act.
The Secretary of Veterans Affairs shall, in accordance with chapter 57 of title 38, United States Code, carry out a pilot program to modernize digital identity proofing and authentication systems of the Department of Veterans Affairs. Under such pilot program, the Secretary shall be responsible for—
replacing legacy knowledge-based or single-factor identity verification mechanisms with multi-layered, high-assurance digital identity solutions;
reducing fraud and improper payments;
improving secure access to digital service platforms of the Department for veterans and other individuals eligible for benefits under laws administered by the Secretary; and
assessing cost savings and operational efficiencies before carrying out a full-scale deployment of any digital identity solution developed pursuant to the pilot program.
The Secretary shall select, for participation in the pilot program, not more than three high-volume digital service platforms of the Department, each of which may consist of one or more underlying systems, applications, or services, including—
disability compensation claims system;
veterans health care enrollment portal;
the system to administer educational benefits; or
the system to administer home loan benefits.
As part of the pilot, the Secretary shall—
map categories of digital transactions within participating platforms to graduated levels of identity assurance based on—
transaction sensitivity;
fraud risk; and
potential harm;
implement adaptive authentication mechanisms capable of adjusting authentication requirements based on contextual and behavioral risk signals; and
ensure, to the extent practicable under applicable Federal standards, more rigorous authentication requirements are applied only where warranted by risk.
Any digital identity solution implemented pursuant to the pilot program shall—
be commercially available and may not be developed exclusively for use by the Department;
be independently certified to meet or exceed Identity Assurance Level 2 (IAL2), as defined in National Institute of Standards and Technology Special Publication 800–63 (or any successor document);
incorporate multi-factor authentication consistent with Authentication Assurance Level 2 (AAL2), as defined in NIST SP 800–63 (or any successor document), or higher; and
comply with applicable Federal cybersecurity and privacy requirements, including—
chapter 57 of title 38, United States Code;
the Privacy Act of 1974 (5 U.S.C. 522a); and
the Federal Information Security Modernization Act of 2014 (Public Law 113–283).
Of amounts authorized to be appropriated for Information Technology Systems under chapter 57 of title 38, United States Code, the Secretary may obligate or expend not more than $25,000,000, in the aggregate, may be obligated to carry out the pilot program.
No additional funds are authorized to be appropriated to carry out this section.
Not later than 120 days after the date of the enactment of this Act, the Secretary shall submit to the Committees on Veterans’ Affairs of the House of Representatives and the Senate a plan for implementing the pilot program under this section.
Not later than one year after the date on which the Secretary commences the pilot program, the Secretary shall submit to such committees an interim performance report that includes—
a summary of—
identity proofing completion rates;
successful authentication rates;
successful account recovery rates; and
abandonment rates during proofing, authentication, and recovery workflows, for each participating digital service platform, compared to the baseline rates in effect before commencement of the pilot program;
fraud reduction metrics applicable to the digital service platforms of the Department selected for participation in the pilot program;
an assessment of the extent to which the pilot program has resulted in decreased overall costs to the Department; and
cybersecurity performance indicators.
Not later than 90 days before the date specified in subsection (i)(1), the Secretary shall submit to such committees a final report that includes—
a comprehensive evaluation of the pilot program; and
legislative recommendations with respect to modernizing digital identity and authentication systems of the Department.
Not later than 18 months after the date of the enactment of this Act, the Comptroller General of the United States shall carry out an independent evaluation of the pilot program under this section and submit to the Committees on Veterans’ Affairs of the House of Representatives and the Senate a report that includes the findings of such evaluation. Such report shall include the following:
An assessment of—
the extent to which the pilot program successfully implemented identity proofing and authentication mechanisms that meet or exceed Identity Assurance Level 2 (IAL2) and Authentication Assurance Level 2 (AAL2) standards under National Institute of Standards and Technology Special Publication 800–63 (or any successor document);
the degree to which the pilot program reduced identity-related fraud, improper payments, or unauthorized account access across participating digital service platforms;
the effect of the pilot program on veteran access to such digital service platforms, including effects on—
authentication success rates;
account recovery and support requests; and
barriers to access for veterans—
residing in rural areas;
with disabilities; or
with limited digital literacy;
costs associated with implementation of the pilot program compared with the financial benefits to the Department derived from fraud reduction, administrative efficiencies, and avoided improper payments;
the extent to which the digital identity solutions used in the pilot program complied with applicable Federal cybersecurity and privacy requirements;
the extent to which the Department successfully implemented risk-tiered authentication approaches that adjust identity verification requirements based on transaction sensitivity and fraud risk; and
the feasibility of scaling the pilot program across additional digital service platforms of the Department, including compatibility with existing Department identity infrastructure and potential integration with Government-wide identity verification services.
Recommendations of the Comptroller General with respect to whether the pilot program should be—
expanded to additional digital service platforms of the Department;
modified to address operational or cybersecurity risks; or
discontinued.
The authority of the Secretary to carry out the pilot program under this section shall terminate on the date that is two years after the date of the enactment of this Act.
The Secretary may not be expand the scope or funding cap beyond the levels described in this section unless expressly authorized by a subsequent Act of Congress.

Legislative Timeline

3 actions
  1. Jun 4, 2026
    Introduced in House
  2. Jun 4, 2026
    Introduced in House
  3. Jun 4, 2026 House
    Referred to the House Committee on Veterans' Affairs.
About this civic dataset

About this legislation view

Track federal and state bills and legislation — browse by chamber, status, and day, with summaries and sponsor details, updated daily on Civic Stream.

Use the scope, chamber, status, and search controls to move from the national legislation picture down to an exact state or legislative stage.