Social Security Identity Verification: CBSV and eCBSV Compared

The Social Security Administration offers two identity verification services that let qualifying financial institutions confirm whether a person’s name, Social Security number, and date of birth match SSA records: the older Consent Based SSN Verification (CBSV) program and the newer Electronic Consent Based SSN Verification (eCBSV) program. Both return a simple match/no-match answer with a death indicator, both require the individual’s written consent, and both are limited to a defined set of financial-sector users. Congress created the electronic version through Section 215 of the Economic Growth, Regulatory Relief, and Consumer Protection Act to help lenders detect synthetic identity fraud, particularly against children and recent immigrants whose SSNs are common targets.1United States Congress. Economic Growth, Regulatory Relief, and Consumer Protection Act (PL 115-174)

CBSV and eCBSV Compared

CBSV is the legacy service. Users submit single requests or batch files through the SSA’s Business Services Online portal, and every consent form must carry an ink signature. Batch responses come back within 24 hours.2Social Security Administration. Consent Based Social Security Number Verification (CBSV) Service

eCBSV was built for real-time, automated checks during a live customer interaction. It uses an API that plugs into the institution’s own software, and it accepts electronic signatures on the consent form. Acceptable e-signatures include a typed name in a signature block, clicking an “I Consent” button, a digitized handwritten signature, or a voice recording expressing consent, provided the method complies with the federal E-SIGN Act.3Social Security Administration. eCBSV User Agreement – Electronic Signature Requirements Responses typically arrive within seconds.4Social Security Administration. eCBSV Frequently Asked Questions

Both programs draw their authority from 42 U.S.C. § 1306, which allows the SSA to recover the full cost of running the service from participating entities.5Office of the Law Revision Counsel. 42 USC 1306 – Disclosure of Information in Possession of Social Security Administration or Department of Health and Human Services

Who Can Enroll

These are not public tools. The statute limits eCBSV to “permitted entities,” defined as financial institutions under the Gramm-Leach-Bliley Act along with their service providers, subsidiaries, affiliates, agents, subcontractors, and assignees. In practice that means banks, credit unions, mortgage lenders, and the vendors that handle verification for them.1United States Congress. Economic Growth, Regulatory Relief, and Consumer Protection Act (PL 115-174)

Verification requests may only be made in connection with a credit transaction or another circumstance described in Section 604 of the Fair Credit Reporting Act. Using eCBSV for tenant screening or employment checks without a qualifying basis would violate the terms. Organizations that don’t qualify as permitted entities, or that need verification for purposes outside the Act, must use CBSV instead.4Social Security Administration. eCBSV Frequently Asked Questions Each entity certifies its own eligibility to the SSA at least every two years.

What It Costs

CBSV

CBSV charges a nonrefundable enrollment fee of $5,000 plus $2.25 per verification request. The per-request fee can change at the SSA’s discretion.2Social Security Administration. Consent Based Social Security Number Verification (CBSV) Service

eCBSV

eCBSV uses annual subscription tiers rather than per-request billing. You estimate your annual volume, choose the tier that covers it, and pay a flat fee for a 365-day agreement. The current schedule took effect on April 7, 2025:6Federal Register. Notice of Tier Fee Decrease for Our Electronic Consent Based Social Security Number Verification Service

  • Tier 1, up to 10,000 transactions: $5,100 per year
  • Tier 2, 10,001 to 75,000 transactions: $37,125 per year
  • Tier 3, 75,001 to 200,000 transactions: $98,000 per year
  • Tier 4, 200,001 to 500,000 transactions: $240,000 per year
  • Tier 5, 500,001 to 1 million transactions: $470,000 per year
  • Tier 6, 1,000,001 to 2.5 million transactions: $907,500 per year

Tiers continue up to 200 million transactions at $5,878,125 per year.7Social Security Administration. Social Security Identity Verification Services If you exhaust your tier’s volume before the agreement year ends, you must move up to the next tier to keep processing. Renewal fees follow whatever schedule is in effect at renewal time.

How to Enroll

Both programs run through the SSA’s Business Services Online (BSO) portal, which requires a Login.gov or ID.me credential with identity verification and multi-factor authentication.8Social Security Administration. Business Services Online

For CBSV, enrollment is handled through Form SSA-200 submitted by email, and the full process takes up to six weeks. For eCBSV, onboarding runs on a separate track and requires executing a legally binding User Agreement with the SSA that sets out data-use rules, privacy protections, and audit obligations.9Social Security Administration. eCBSV Onboarding The entity takes full responsibility for keeping any information it receives confidential, and a violation of the agreement can bring immediate suspension.

The Consent Form: SSA-89

No verification happens without the individual’s written permission on Form SSA-89, the “Authorization for the Social Security Administration to Release Social Security Number Verification.” The form captures the person’s full legal name, nine-digit SSN, and date of birth, and it must be signed and dated by the individual.10Social Security Administration. Form SSA-89 – Authorization for the Social Security Administration to Release Social Security Number Verification

Each authorization is valid for 90 days from the signature date, unless the individual specifies a shorter window. Entities must use the current version of the form or risk rejection, and even a small typo in a name or birth date can produce a failed match. Providing false information on the form can trigger federal criminal prosecution.

Reading the Response

The SSA does not return personal data. It returns codes. eCBSV sends back a verification code of “Y” or “N,” and when the answer is “Y,” a death indicator of “Y” or “N.” The death indicator only populates on a verified match, because the system confirms identity before checking the death records.11Social Security Administration. Electronic Consent Based SSN Verification (eCBSV) Service – Technical Information Document CBSV returns a comparable result set with a death indicator when records show the SSN holder as deceased.2Social Security Administration. Consent Based Social Security Number Verification (CBSV) Service

A “not verified” result is not proof of fraud. A name change after marriage that was never reported to the SSA, or a data-entry mistake in the original application, can produce the same output. Treat it as a signal to look closer, not an automatic disqualification.

Recordkeeping and Audits

Every request is logged, and the SSA can review those logs at any time. Entities must keep the signed SSA-89 (or its electronic equivalent) and supporting documentation for five years from the date of the request. Electronic storage is allowed, but the entity has to maintain file integrity, password-protect the records, restrict access, and keep disaster-recovery procedures in place. If a wet-signature form is stored electronically, the paper original must be destroyed.12Social Security Administration. eCBSV User Agreement

eCBSV also carries a mandatory independent audit schedule:

  • An initial audit during the entity’s first year in the program.
  • After that, every five years for entities subject to Gramm-Leach-Bliley oversight that had no violations in their most recent audit.
  • Every year for entities not subject to that oversight, and for any entity with violations on its record.

The SSA also reserves the right to audit any permitted entity or the financial institutions it serves at any time.13Social Security Administration. eCBSV User Agreement – Audit Requirements Audits examine consent documentation, data handling, and whether the entity has stayed inside its authorized use of the system.

Suspension and Criminal Exposure

The SSA can suspend an entity’s access immediately, without advance warning, by sending an email stating the reason. Grounds include non-payment, violations of the User Agreement, and failure to keep the permitted entity certification current. A financial institution cannot dodge a suspension by routing requests through another permitted entity.14Social Security Administration. eCBSV User Agreement – Suspension of Services

An entity has 30 calendar days from the notice date to dispute a suspension by email. After review, the SSA may lift it, keep it in place, or terminate the User Agreement.14Social Security Administration. eCBSV User Agreement – Suspension of Services

Under 42 U.S.C. § 408, false statements or misrepresentations involving Social Security information are a felony punishable by up to five years in prison, a fine, or both. For professionals who receive fees in connection with Social Security benefit determinations, the maximum rises to ten years.15Office of the Law Revision Counsel. 42 USC 408 – Penalties for False Statements

If You’re the Consumer Being Asked to Consent

When a lender or other financial institution asks you to authorize an SSN verification during a mortgage application, account opening, or similar transaction, you’re signing Form SSA-89. You can set a consent window shorter than the default 90 days, and you can decline the check, though the institution may then decline the transaction.10Social Security Administration. Form SSA-89 – Authorization for the Social Security Administration to Release Social Security Number Verification

If your check fails, the most common cause is unreported information. A marriage, divorce, or legal name change that never made it to the SSA will throw off the match. The remedy is to visit your local Social Security office with documentation of the change, get your record updated, and ask the institution to resubmit.16Social Security Administration. What Should I Do If My Employee’s Name and Social Security Number Don’t Match

If the institution then takes adverse action against you based on the verification results, the Fair Credit Reporting Act requires it to tell you and to give you the name, address, and phone number of the agency that supplied the information.17Consumer Financial Protection Bureau. A Summary of Your Rights Under the Fair Credit Reporting Act