Passkey
What is Passkey?
A passwordless authentication credential based on the FIDO2 standard that uses public key cryptography and biometrics for secure, phishing-resistant sign-in.
Terms that appear alongside passkey
Each of these is named in at least one of the same controls as passkey. The number is how many controls name both.
- authentication 6 shared controls
- policy 2 shared controls
- attestation 2 shared controls
- session token 2 shared controls
- password manager 2 shared controls
Frameworks that govern passkey
What the standards actually require on passkey
Requirements naming passkey across 6 standards, quoted from the control text.
Discoverable credentials (formerly Resident Credentials) per WebAuthn L3 6.3 + CTAP2.1 are credentials whose private-key + per-credential metadata (rpId + userHandle + signCount) are stored on the authenticator.
FIDO2-Passkey-Discoverable · Passkeys (Discoverable Credentials) and Account Recovery →Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication ensures the validity of the claimed identities of the entities participating in communication (e.g.
X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication · ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Factor + Cryptographic Authentication →Identity and Access Management (IAM) is a critical control area per FSA Cybersecurity Guidelines + intersects with FISC Security Guidelines + Japan Banking Customer Authentication Standards + APPI access control.
JP-FSA-CYB-Identity-Access-Management-Privileged-Access-MFA-Zero-Trust-Just-In-Time-Banking-Customer-Authentication · Japan FSA Cybersecurity Identity and Access Management + Privileged Access + MFA + Zero Trust + Just-In-Time + Banking Customer Authentication + Risk-Based Authentication + Out-of-Band + Biometric + FIDO2 + Internet Banking Security →Kuwait NCF Protect function (Access). Access Control and Identity Management aligned with NIST SP 800-53 AC family + ISO 27001 A.9 + Zero Trust principles.
KNCF-Protect-Access-Control-IAM-Privileged-MFA-Zero-Trust-Identity-Lifecycle-IAG-PAM · Kuwait NCF Protect + Access Control + IAM + Privileged + MFA + Zero Trust + Identity Lifecycle →Implement authentication per NIST SP 800-63-4 Volume B (Authentication and Authenticator Lifecycle). Approve authenticator types per Section 4 covering (a) memorised secrets (Section 4.1), (b) look-up secrets (Section 4.2), (c) out-of-band devices (Section 4.3...
NISTSP63R4-3 · Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators →Where identity is established without a password, use a recognised passwordless method such as a FIDO2 authenticator or passkey, biometric, hardware security key or token, push notification or one-time code, and manage it as the authentication control for the...
CE-AC.8 · Passwordless Authentication →Questions people ask about passkey
What is Passkey?
Why is Passkey important for compliance?
Which compliance frameworks address Passkey?
Where can I learn more about Passkey?
See how Passkey applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.