Join our Newsletter — 33% off our NHI Course

What should organisations compare when evaluating passkeys versus MFA?

Compare assurance, recovery complexity and user friction rather than treating them as competing brands of the same control. Passkeys can remove shared secrets, while MFA adds layered verification. The better choice depends on whether the main problem is phishing exposure, workflow friction or privileged access assurance.

What should you compare instead of brands?

Evaluate passkeys and MFA by the security outcome they deliver, not by the label on the product. The useful comparison is whether the control reduces phishing and replay risk, how much recovery and enrolment effort it creates, and whether it fits the access model you are protecting. That is why passkeys often excel for user sign-in, while MFA remains valuable where layered assurance or step-up checks are needed.

Passkeys change the authentication model by replacing shared secrets with phishing-resistant cryptographic authenticators, which is a material shift in how sign-in is protected. MFA is a broader pattern that can range from weak second factors to stronger phishing-resistant combinations, so “MFA” alone does not tell you the assurance level. Organisations should therefore compare the actual authenticators, not just the category name, as reflected in NIST SP 800-63 Digital Identity Guidelines and Passwordless and Passkeys Guide.

Recovery is the second major comparison point because the strongest sign-in method can still fail at account recovery. Passkeys may reduce password theft, but they also require you to think through device loss, backup enrollment, help desk reset paths and fallback authentication. MFA can be easier to re-establish in some environments, but weaker recovery often becomes the attack path, especially when help desk workflows or legacy reset processes are involved. That makes recovery design part of the control, not an afterthought, and the Workforce Identity Security Guide is a useful anchor for that comparison.

Friction is the third practical dimension, but it should be measured as completed sign-ins and support burden rather than general convenience. Passkeys can reduce repeated prompts and password-related recovery tickets, while MFA can add step-up prompts or push fatigue when it is poorly tuned. The key question is which option lowers user work without weakening the assurance level required for the specific application, role or transaction.

Where the trade-offs become real

The trade-off is usually not “passkeys versus MFA” in the abstract, but “which control best fits this access path.” For ordinary workforce sign-in, passkeys can be a strong default because they improve phishing resistance and remove shared secrets from the user journey. For privileged access, high-risk actions or access to sensitive systems, organisations may still need layered step-up verification, session controls or stronger policy checks beyond initial sign-in. Comparing by use case prevents overgeneralising from a single login flow.

Implementation details matter because not all MFA is equally resistant to modern phishing. SMS codes, OTP apps and push approvals can be bypassed through relay, fatigue or social engineering, while passkeys are designed to resist those attack paths more effectively. That is why many organisations compare the authentication method itself, not merely whether “MFA” is present. The distinction shows up clearly in the MFA Guide and the broader Workforce Identity Security Guide.

There is also a lifecycle question: what happens when employees change devices, lose access, or need emergency recovery? Passkeys can simplify the steady state, but they can complicate edge cases if backup enrolment, device binding or recovery policy are not defined. MFA may be more familiar operationally, yet it can leave organisations accepting weaker factors for the sake of convenience. The right comparison is therefore the full user journey from enrolment to reset to revocation.

How to make the decision for a specific population

Start by asking what failure you are trying to reduce. If phishing, credential replay and password theft are the main concerns, passkeys usually provide the better security outcome. If the main concern is administrative flexibility, diverse device support or incremental rollout across mixed populations, MFA may remain the pragmatic intermediate control. Many organisations will need both patterns in different places rather than a single enterprise-wide winner.

The cleanest decision rule is to compare assurance, recovery complexity and user friction for the same population, same application and same risk level. Workforce users, contractors, admins and customer identities do not all need the same control mix, and privileged accounts usually deserve a higher bar than low-risk sign-in. That is the practical lens used in buyer evaluation and rollout planning, including the guidance in the IAM and Identity Provider Buyer’s Guide.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5, OWASP ASVS and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Phishing-resistant authenticators, assurance levels and recovery design are central to this comparison.
Recommendation — Map sign-in requirements to the needed assurance level and require phishing-resistant authentication where risk justifies it.
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Workforce authentication choices determine how employees and admins prove identity to systems.
IA-5 — Authenticator Management Passkeys and MFA both depend on lifecycle handling of authenticators and recovery paths.
IA-9 — Service Identification and Authentication If the comparison extends to machine or service access, authentication strength must still be governed.
Recommendation — Specify stronger authenticator requirements for workforce sign-in and privileged access. Control enrollment, rotation, reset and revocation for every authenticator type. Apply distinct authentication rules for non-human accounts and service-to-service access.
OWASP ASVS V6 — Authentication Application sign-in decisions depend on authentication strength, fallback handling and phishing resistance.
Recommendation — Verify that the chosen sign-in method resists phishing and cannot be bypassed through weak fallbacks.
CIS Controls v8 CIS-5 — Account Management Passkey and MFA rollout both depend on account lifecycle, recovery and revocation discipline.
Recommendation — Standardise account lifecycle handling and remove stale recovery paths.

Practitioner Guidance

What to verify: Test the real recovery path before trusting the control. A passkey programme is only stronger than MFA if device loss, backup enrolment, help desk resets and exception handling do not recreate the same attack surface you were trying to remove.

Decision rule: Use passkeys where the business goal is phishing-resistant sign-in with lower routine friction, and keep MFA where you need layered verification, step-up access or transitional compatibility. Do not evaluate them as substitutes unless the access path, user population and recovery process are the same.

What practitioners underestimate: The strongest login method can be weakened by the weakest fallback. If legacy reset steps, push approvals or shared recovery channels remain in place, the effective security outcome may be much closer to conventional MFA than to the passkey ideal.

Practitioner takeaway: Compare the control as a full operating model, not a single authentication event, because assurance is determined by sign-in strength, recovery design and how much friction users will actually tolerate.