---
source_url: "https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in?utm_source=openai"
title: "Passkeys are more secure than traditional ways to log in | National Cyber Security Centre"
mirrored_at: 2026-08-04T01:03:34.405Z
host: www.ncsc.gov.uk
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in__q__utm_source_openai"
---

> **Original source:** https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in?utm_source=openai

Dave Chismon

![Digital Key Hologram on Futuristic Computer Code. 3D Render](https://www.ncsc.gov.uk/sites/default/files/styles/uncropped_2xs/public/2026-04/passkeys%20blog%20item.jpg?itok=QRm_ldrV)

asbe via Getty Images

At CYBERUK 2026 in Glasgow, the NCSC announced that we will begin recommending passkeys wherever a service supports them, and two‑step verification (2SV) where it does not. This shift will be reflected through our ongoing refresh of guidance rather than as a single sudden change.

This is not a decision taken lightly. It is based on extensive engagement with websites, app developers, technology vendors and the FIDO Alliance, alongside significant technical and sociotechnical research carried out by the NCSC.

As part of CYBERUK, we published a paper comparing – from an individual user’s perspective – [the security properties of traditional multi‑factor authentication (MFA/2SV) and FIDO2 credentials](https://www.ncsc.gov.uk/paper/traditional-user-and-fido2-credentials-personal-use), including passkeys.

* * *

## How we compared different login methods

All credentials go through a lifecycle: they are created, stored and used, and often need to be synchronised, revoked or recovered. At different points in that lifecycle, credentials are vulnerable to different types of attack, and not all attackers have the same capabilities.

By breaking authentication down in this way – and focusing on the most common real‑world attack techniques – it becomes possible to compare very different credential types in a consistent and meaningful way.

Our analysis focused on the attacks most commonly seen against individuals today, including phishing, credential reuse and session hijacking.

* * *

## Our assessment

From this analysis, the NCSC assesses that: 

-   **All traditional MFA methods** – including passwords combined with SMS codes, email codes, time-based One Time Passwords generated by apps or physical tokens, push approvals – are inherently phishable. 
    
-   **FIDO2 credentials, including passkeys, are as secure or more secure than traditional MFA** against all common credential attacks observed in the wild. 
    
-   When user verification is required as part of the login, **FIDO2 authentication constitutes multi‑factor authentication**.
    
-   Because FIDO2 removes the ability to cheaply reuse or relay credentials, **large**‑**scale attacks directly targeting correctly implemented passkeys are unlikely**.
    

In short, when services support them, passkeys provide stronger protection for users than traditional MFA/2SV. 

* * *

## Addressing common concerns

Some concerns are frequently raised about passkeys. In practice, many are either manageable or apply equally to traditional approaches. Here are our answers to some of the most common questions:

### “What about synchronisation?”

Passkeys can synchronise across devices using platform services. This is sometimes presented as a novel risk, but most people already rely on similar cloud‑based synchronisation for password managers, email and some authenticator apps. The key control is the strength of the authentication protecting the sync account – a requirement that already exists in many MFA deployments.

### “Are passkeys really multi‑factor?”

Yes. Where user verification is performed (typically by however the user normally logs into their device), FIDO2 credentials combine something the user has (the cryptographic key) with something they are or know. Multiple factors do not need to be on multiple, separate devices, and many traditional MFA implementations already deliver all factors through a single phone.

### “Isn’t traditional MFA good enough if done properly?”

Traditional MFA can be effective, but it remains fundamentally vulnerable to phishing because secrets or approvals can be observed and relayed during a live session. Passkeys remove this class of attack entirely by cryptographically binding authentication to the legitimate service. 

* * *

## Getting the most benefit

As with any security control, passkeys are most effective when implemented and used sensibly. Users still depend on the security of their devices and credential managers, and services should give users clear ways to manage and remove credentials and to set up recovery options.

Importantly, our assessment doesn't assume perfect usage or perfect implementation. Even under realistic conditions, passkeys offer stronger protection than the best implemented traditional MFA. 

* * *

## Choose passkeys – and raise the bar

For individuals logging into websites and apps, passkeys and other FIDO2 credentials are as secure or more secure than traditional MFA/2SV, and – when user verification is used – are themselves multi‑factor. 

Where services support passkeys, they should generally be used. Where they do not, traditional 2SV remains an important fallback. 

On a broader scale, moving towards phishing‑resistant authentication reduces one of the most persistent causes of cyber compromise. The technology is mature, the standards are established, and adoption now represents a practical opportunity to improve security for users and organisations alike. 

##### Dave Chismon

##### NCSC CTO for Architecture