Philippines Central Bank Mandates FIDO Passwordless Authentication by 2026, HID Global Launches Compliance Solutions

Abstract colorful puzzle pieces pattern, illustrating concepts of problem-solving, teamwork, and system integration through interlocking shapes in warm shades of red, orange, and yellow fading into cool tones of blue and teal.

The Bangko Sentral ng Pilipinas (BSP) has established a June 25, 2026 deadline for banks and financial institutions in the Philippines to transition from password-only authentication to more robust, phishing-resistant methods under the Anti-Financial Account Scamming Act (AFASA). The regulation mandates the implementation of passwordless authentication based on FIDO (Fast Identity Online) standards, including passkeys, physical security tokens, and other credentialing solutions that reduce dependence on traditional passwords and one-time passcodes (OTPs). The regulatory change follows a 35 percent increase in online fraud and identity scams in the Philippines over the past two years.

Financial institutions must implement systems that integrate fraud management with comprehensive identity verification, specifically deploying technologies supporting passwordless, phishing-resistant authentication to strengthen their cybersecurity infrastructure. The move follows a broader global trend toward passwordless authentication, as major technology companies have been accelerating their transition away from traditional passwords.

In response to these requirements, HID Global has introduced a new line of FIDO-certified hardware credentials and an Enterprise Passkey Management (EPM) platform designed for large-scale deployment and lifecycle management of passkeys. The company’s hardware portfolio includes Crescendo Keys, Crescendo Cards, and Omnikey readers, which integrate with identity platforms such as Microsoft Entra ID. Several devices combine physical access control with digital authentication capabilities, enabling unified security management across physical and digital domains. The development builds upon HID’s previous work with Microsoft on FIDO2-enabled smart cards.

“Passwordless authentication is no longer optional — it is now a regulatory requirement in the Philippines,” said Sean Dyon, Vice President and Head of the Authentication Business Unit at HID. “Our next-generation FIDO portfolio gives Philippine enterprises the hardware diversity and centralized management capabilities needed to deploy and manage passkeys at scale, while reducing reliance on phishable credentials like passwords and OTPs to enhance organizations’ overall cybersecurity posture.”

HID’s subscription-based EPM solution addresses deployment complexity and cost concerns by providing centralized visibility, control, and administrative oversight. The platform facilitates passwordless adoption across diverse work environments while minimizing IT support requirements. The launch comes at a crucial time, as recent FIDO Alliance research indicates 87 percent of enterprises are adopting passkeys, despite deployment challenges affecting nearly half of organizations.

The development is particularly significant given recent security concerns around authentication systems. Researchers have identified potential vulnerabilities in FIDO passkey implementations, highlighting the importance of proper deployment and management of these security solutions. HID’s comprehensive approach, combining hardware tokens with centralized management capabilities, aims to address these security considerations while facilitating Philippine financial institutions’ compliance with BSP requirements within the mandated timeframe.

Sources: Newsbytes.ph, Business Post, Fintechnews.ph