The UK’s National Cyber Security Centre (NCSC) is beginning to endorse passkeys over passwords wherever a service supports them.
In instances where passkeys are not supported two-step verification is advised, the NCSC announced.
The NCSC’s ongoing guidance will reflect this new endorsement as passkeys become a lauded defence tool.
The NCSC says that their recommendation of passkeys was “not a decision taken lightly.” The organisation consulted websites, app developers, tech vendors, as well as the FIDO Alliance, and carried out technical and sociotechnical research.
Research from the NCSC found that all traditional multifactor authentication methods, from passwords with one-time codes to push approvals, are “inherently phishable”.
However, FIDO2 credentials, which include passkeys, were found to be either as secure or more secure than traditional MFA when faced with common credential attacks.
FIDO2 authentication constitutes as multi-factor authentication when user verification is required as part of the login process.
The NCSC says that large-scale attacks that directly target correct passkeys are unlikely because FIDO2 removes the ability to cheaply reuse or relay credentials.
“In short, when services support them, passkeys provide stronger protection for users than traditional MFA/2SV,” the NCSC said.
Still, there are concerns regarding the adoption of passkeys, such as the risk of synchronisation, questions regarding multi-factor authentication.
While synchronisation – when passkeys are synchronised across devices – does present a novel risk, the main control factor is the authentication protection the sync account, which often already exists in MFA deployments.
Recommended reading
- 65% of Cyber-leaders Reuse Old Passwords
- World Password Day: Are Passkeys the Future?
- Kaspersky: 45% of Passwords Could be Hacked Within 1 Minute
Traditional MFA may be effective, but the NCSC says it remains “fundamentally vulnerable to phishing” while passkeys remove this type of attack via cryptographic binding authentication.
“On a broader scale, moving towards phishing‑resistant authentication reduces one of the most persistent causes of cyber compromise. The technology is mature, the standards are established, and adoption now represents a practical opportunity to improve security for users and organisations alike,” Dave Chismon, NCSC CTO for Architecture wrote.





