The UK’s National Cyber Security Centre (NCSC) is recommending passkeys as the default authentication method that businesses should offer to consumers, citing industry advances that make them a more secure and user-friendly alternative to passwords. In a post published this week, the agency said that passkeys can now be recommended to both the public and businesses as the primary authentication method.

“Passkeys should now be consumers’ first choice for login,” the UK cybersecurity authority said, adding that passwordsare “no longer robust enough for the modern world.”
“Passkeys are a newer method for logging into online accounts that do most of the work for users, requiring only user approval instead of having to enter a password. This makes passkeys faster and easier to use and more difficult for cyberattackers to breach,” the NCSC added.
Passkeys: Focus on phishing-resistant authentication
The service said passkeys should be used where supported, describing them as phishing-resistant.
See also: AI Zealot can autonomously hack Cloud systems
The NCSC said its analysis examines common techniques, including phishing, credential reuse and session hijacking, and assesses how credentials are exposed throughout their lifecycle, from creation and storage to use.
“Passkeys are resistant to phishing attacks and eliminate the risks associated with password reuse,” the service said.
In the accompanying technical paper , the NCSC said that traditional authentication methods , including passwords combined with one-time codes, remain “ inherently vulnerable to phishing .” In contrast, FIDO2 -based credentials , such as passkeys , are “ as secure or more secure than traditional MFA against all common credential attacks observed .”
However, the NCSC cautioned in the technical paper that “although much of the analysis in this paper also applies to enterprise authentication scenarios (for example, personnel authenticating to a Single Sign On), the different threat model and usage scenarios mean that this paper is not intended for enterprise risk assessment.”

How passkeys change the attack model
The NCSC added that passkeys reduce risk by removing reliance on shared secrets and binding authentication to the legitimate service.
See also: Microsoft capitalizes on Anthropic's Mythos
According to the service, this prevents credential reuse and relay attacks, as the authentication cannot be intercepted and reused by an attacker.
Passkeys use cryptographic key pairs stored on the user's device, with authentication being linked to device-based verification, such as biometrics or PINs.
Shift to user-level authentication
For organizations that provide online services to customers, the guidance marks a shift in how authentication is implemented at the user interface level.
“This is a fundamental architectural change, not an incremental authentication upgrade,” said Madelein van der Hout, senior analyst at Forrester. “It moves organizations beyond the password-plus-MFA paradigm toward a phishing-resistant foundation.”
Van der Hout said passkeys eliminate the risks associated with credential theft by using cryptographic authentication tied to the device instead of shared secrets.
“Organizations that treat this as a simple credential change will underinvest,” he said. “Those that treat this as a broader identity modernization opportunity will move forward.”
See also: New Mac malware directly targets developer keys
The NCSC said organizations should also consider how authentication is implemented throughout the user journey, including account recovery and workarounds.
While passkeys reduce reliance on passwords, the service noted that weaker processes, such as password resets or account recovery flows, can still introduce risk if not properly secured.
Adoption challenges
The NCSC said that passkeys are not yet universally supported and recommends using password managersand MFA ( where passkeys cannot be used).
Van der Hout said implementation challenges are likely, particularly for organizations operating across multiple platforms and user environments.

“Legacy systems and fragmented identity environments present significant barriers,” he said. He added that organizations also need to consider non-human identities. “Any passkey strategy that ignores the machine identity layer will create new security gaps,” he said.
Device requirements and account recovery processes may also affect how passkeys are deployed.
Hybrid model during transition
A complete transition away from passwords is unlikely in the near future, according to analysts. “A hybrid model to last several years,” van der Hout said, as organizations continue to support both passkeys and traditional authentication methods.
During this period, organizations will need to manage authentication through multiple login options, while ensuring that alternative methods do not weaken overall security.
The NCSC said that moving to passkeys (a phishing-resistant authentication) could reduce a significant cause of cyber breaches, particularly in services that rely on user login credentials.
