UK Cyber Agency Tells Consumers to Ditch Passwords for Phone-Based Passkey Authentication

Pattern of various antique keys and keyholes arranged on a bright yellow background, representing the concept of security, access, or unlocking solutions.

The UK’s National Cyber Security Centre has told consumers to replace passwords with passkeys, the phone-based biometric login method that uses fingerprint scans or facial recognition built into mobile devices to verify identity without transmitting credentials over the internet.

The recommendation, announced at the CYBERUK 2026 conference in Glasgow, reverses decades of official guidance centered on password complexity and rotation. The NCSC, which operates as part of GCHQ, now advises individuals to use passkeys wherever a service supports them and to use strong passwords combined with two-step verification where passkey support is not yet available. The agency is also urging enterprises to offer passkeys as the default login option for all customer-facing digital services.

Passkeys work by storing a cryptographic private key on the user’s device, typically a smartphone. When logging in, the phone’s built-in biometric sensor, whether a fingerprint reader or face unlock camera, verifies that the device owner is present before the key is used to complete authentication. The private key never leaves the device, making passkeys resistant to phishing, credential stuffing, and database breaches that plague password-based systems.

A new NCSC technical report published alongside the announcement concludes that passkeys are at least as secure as pairing the strongest possible password with two-step verification. The agency had stopped short of endorsing passkeys in 2025, citing unresolved challenges around account recovery and cross-platform portability, but said progress within the technology industry over the past year has addressed those concerns sufficiently to support a public recommendation.

The FIDO Alliance, which maintains the technical standards underpinning passkeys, reports that passkey deployment has surged in the US and UK over the past year. Google, eBay, and PayPal all support passkeys, and Google data cited by the NCSC indicates that just over half of active Google users in the United Kingdom have registered at least one passkey on their accounts.

The NCSC’s guidance is directed at consumer-facing services and explicitly notes that internal enterprise authentication scenarios fall outside the scope of this recommendation. For the millions of UK residents who already unlock their phones with a fingerprint or face scan, the shift means that same biometric gesture can now serve as a verified login across a growing number of online services.

Sources: NCSC, The Register

By the Mobile ID World Editorial Team