Passkeys and Cyber Essentials: Can Passkeys Replace MFA?
Published 9 October 2026
What a passkey is
A passkey is a FIDO2 credential. It is a cryptographic key pair: the private key stays on your device or security key, and the service only holds the public key. To sign in you unlock the passkey locally, usually with a fingerprint, face or device PIN, and the device proves possession of the key.
That combines something you have (the device holding the key) with something you are or know (biometric or PIN). It is also resistant to phishing, because the credential is bound to the genuine website and will not work on a lookalike.
What NCSC v3.3 actually says
The requirements say authentication to cloud services must use MFA. In the passwordless section, the NCSC states that FIDO2 authenticators, including passkeys, are regarded as MFA. You do not need a password plus a passkey; the passkey on its own meets the MFA requirement.
For the broader picture on which accounts need MFA and which methods are accepted, see our Cyber Essentials MFA requirements guide. This page answers the narrower passkey question.
Passkeys vs password plus authenticator app
| Password + authenticator app | Passkey (FIDO2) | |
|---|---|---|
| Meets CE MFA requirement | Yes | Yes |
| Resistant to phishing | Partly. Codes and push prompts can be relayed or approved by mistake. | Yes. Bound to the real site. |
| Password still needed | Yes, and it must meet CE password rules | No, for that sign-in route |
| User experience | Two steps | One unlock gesture |
Platform passkeys vs security keys
- Platform (synced) passkeys live in the device's credential manager, such as Windows Hello, Apple iCloud Keychain or Google Password Manager, and may sync across a user's devices.
- Device-bound passkeys stay on one device and do not sync. Microsoft Authenticator can hold these for work accounts.
- Roaming security keys are physical FIDO2 keys (USB, NFC) that work across devices.
All are FIDO2 authenticators. For admin accounts, many organisations prefer device-bound passkeys or hardware keys so the credential cannot drift onto a personal device through syncing. That is a sensible design choice rather than a Cyber Essentials rule.
When "passwordless" does not automatically mean compliant
- Emailed magic links or one-time codes are passwordless but are not FIDO2 passkeys. Judge them on whether they genuinely provide two factors.
- A passkey that is optional does not help if users can still sign in with password alone. MFA must be enforced, not just available.
- Fallback routes such as legacy protocols, app passwords or a "sign in another way" option that bypasses MFA undermine the passkey. Check there is no way around it.
- Some accounts left out, such as a break-glass admin or a contractor, still need MFA, whether by passkey or another accepted method.
Admin and cloud accounts
Administrator accounts for cloud services must use MFA, and passkeys are an excellent fit. Make sure the admin portal itself is covered, not just the user sign-in page. Separate admin accounts from day-to-day accounts as required elsewhere in the scheme. See Cyber Essentials access control.
How to evidence passkey-based authentication
- The identity provider policy that requires phishing-resistant or FIDO2 authentication for the relevant users and admins.
- A report of registered authentication methods per user, showing who has a passkey.
- Confirmation that legacy or basic authentication is blocked.
- A list of any users without a passkey, and which other MFA method they use.
- For each in-scope cloud service that does not use your central identity provider, a note of how MFA is enforced there.
Microsoft 365 users can follow our Microsoft 365 Cyber Essentials guide for the wider tenant settings.
