Identity · 145 days ago
Passwords are no longer the safe default where passkeys exist. The NCSC is telling consumers to use passkeys first and to stop relying on passwords for services that support them, because password theft and phishing remain the main way accounts are lost.
The guidance is backed by a new technical report saying passkeys are at least as secure as, and generally more secure than, a strong password plus two-step verification. The NCSC points to broad platform support from Google, Microsoft, eBay, and PayPal, and says ecosystem friction has dropped enough to make passkeys the practical default.
The shift matters because it reduces the biggest adoption barrier: fragmentation. As more major services normalize passkeys, password-based login becomes the fallback, not the standard, and that changes the baseline for consumer account security.
3 sources covering this story
NCSC: Leave passwords in the past - passkeys are the future
Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.
NCSC Backs Passkeys, Hailing a New Era of Sign-in
The UK’s NCSC has fully backed passkeys as consumers’ first choice for login, citing progress with FIDO and successful use across the NHS
NCSC: Passkeys now good enough to be the default standard
: NCSC passes judgment: passkeys pass muster, passwords fail
Part of the PlainSec briefing for 2026-04-24