Passwordless Authentication
What is Passwordless Authentication?
Authentication methods that verify user identity without traditional passwords, using alternatives such as biometrics, hardware tokens, or magic links.
Frameworks that govern passwordless authentication
What the standards actually require on passwordless authentication
Requirements naming passwordless authentication across 3 standards, quoted from the control text.
Where identity is established without a password, use a recognised passwordless method such as a FIDO2 authenticator or passkey, biometric, hardware security key or token, push notification or one-time code, and manage it as the authentication control for the...
CE-AC.8 · Passwordless Authentication →Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication ensures the validity of the claimed identities of the entities participating in communication (e.g.
X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication · ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Factor + Cryptographic Authentication →Implement phishing-resistant authentication (FIDO2/WebAuthn, PKI) as the default. Support passwordless authentication where feasible.
SBD-DEV-04 · Phishing-Resistant Authentication →Questions people ask about passwordless authentication
What is Passwordless Authentication?
Why is Passwordless Authentication important for compliance?
Which compliance frameworks address Passwordless Authentication?
Where can I learn more about Passwordless Authentication?
See how Passwordless Authentication applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.