The UK’s National Cyber Security Centre has formally recommended that consumers and businesses adopt passkeys as their default authentication method, reversing decades of official guidance centered on password complexity, rotation, and management best practices.
The announcement, made at the CYBERUK 2026 conference in Glasgow, marks a significant shift in UK government cybersecurity policy. The NCSC, which operates as part of GCHQ, now advises individuals to use passkeys wherever a service supports them and to use strong passwords combined with two-step verification where passkey support is not yet available. The agency is also urging enterprises to offer passkeys as the default login option for all customer-facing digital services.
Passkeys use cryptographic key pairs – a public key stored by the online service and a private key secured on the user’s device. Authentication requires local biometric verification, such as a fingerprint scan or facial recognition through the device’s built-in sensors, or alternatively a device PIN, before the private key is used to complete the login. The private key never leaves the device and is never transmitted during the authentication process, making passkeys inherently resistant to phishing attacks, credential stuffing, and password database breaches.
A new NCSC technical report published alongside the announcement concludes that passkeys are at least as secure as, and generally more secure than, pairing the strongest possible password with two-step verification. The agency had stopped short of endorsing passkeys in 2025, citing unresolved implementation challenges around account recovery and cross-platform portability, but said progress within the technology industry over the past year has addressed those concerns sufficiently to support a public recommendation.
The FIDO Alliance, which maintains the technical standards underpinning passkeys, has been tracking enterprise adoption gains and reports that passkey deployment has surged in the US and UK over the past year. Google, eBay, and PayPal all support passkeys, and Google data cited by the NCSC indicates that just over half of active Google users in the United Kingdom have registered at least one passkey on their accounts.
The NCSC’s guidance is directed at consumer-facing services and explicitly notes that internal enterprise authentication scenarios fall outside the scope of this recommendation. The endorsement positions biometric device-level authentication as the practical successor to the password era for mainstream consumer services.
Sources: NCSC, The Register
–
By the ID Tech Editorial Team






Follow Us