What changed
The National Cyber Security Centre now recommends choosing passkeys wherever a service supports them, with traditional two-step verification retained where they are not available. A passkey is a FIDO2 credential held by a device or credential manager. Instead of sending a password or one-time code, the device proves possession of a private key that is bound to the legitimate service.
That distinction matters because ordinary passwords and traditional MFA prompts can be copied, observed or relayed through a convincing fake login. The NCSC assesses FIDO2 credentials, including passkeys, as resistant to credential harvesting, adversary-in-the-middle phishing and notification-fatigue attacks. This is a control improvement, not evidence of a new incident or a reason to claim that every account using a passkey is unbreakable.
[1][2]What the evidence does and does not say
The NCSC's detailed comparison finds that FIDO2 credentials are as secure as or more secure than traditional MFA against the common credential attacks it examined. When the service requires user verification, such as a device PIN or biometric, it also assesses FIDO2 authentication as multi-factor. The private key is not disclosed to the website during login, and the credential is scoped to the correct service origin, removing the reusable secret that a phishing page wants to collect.
The technical paper focuses on credentials used by individuals for personal services. It says many findings are likely to apply to organisations but does not present itself as a formal enterprise assessment. Businesses therefore need to consider managed devices, shared workstations, legacy applications, joiner and leaver processes, support arrangements and recovery before treating a consumer passkey pattern as a complete workforce design.
[1][2]What businesses should do
Begin with accounts whose compromise would cause the greatest harm: primary email, cloud administration, finance, domain registration and password or credential management. Check which providers support passkeys, whether the credential can be managed through the organisation's chosen device platform, and how an administrator can revoke it when a device is lost or a person leaves.
Pilot the full lifecycle rather than only the happy-path login. Test enrolment on an approved device, use from a replacement device, loss of one authenticator, recovery without the normal phone or laptop, revocation and access by an emergency administrator. Protect the account that synchronises passkeys, keep devices updated and require a strong screen lock. A weak recovery route can undermine a strong daily login.
Where passkeys are unavailable, keep unique password-manager-generated passwords and enable the strongest practical 2SV. Do not remove a working second factor merely because a preferred option is missing. Record unsupported critical services and revisit them during supplier reviews or contract renewal.
- Prioritise email, cloud, finance, domain and credential-management accounts.
- Confirm how passkeys are stored, synchronised, recovered and revoked.
- Pilot lost-device and leaver scenarios before a wider rollout.
- Protect synchronisation accounts and keep enrolled devices updated.
- Retain strong passwords and 2SV where passkeys are not supported.
The Beekeeper view
Passkeys are useful because they change the economics of phishing: a copied page can still mislead a person, but it cannot simply collect a reusable FIDO2 secret and replay it elsewhere. That makes adoption worthwhile for the accounts that control a business's communications, money and infrastructure.
The durable outcome is not a badge saying passwordless. It is an identity process that remains safe when somebody changes phone, loses a laptop or leaves the company. Roll out the stronger credential, but test the recovery and revocation paths with equal care.
[1][2]Primary sources
- Passkeys are more secure than traditional ways to log in — National Cyber Security Centre, 23 April 2026
- Comparing the security properties of traditional user credentials and FIDO2 credentials for personal use — National Cyber Security Centre, 23 April 2026
Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.