Yes, when phishing resistance is a real requirement and the organisation can operate certificate lifecycle management reliably. OTP may still fit lower-risk use cases, but it leaves a broader replay and interception surface than hardware-backed certificate authentication.
When certificate-based authentication is the stronger choice
Certificate-based authentication deserves priority when the sign-in path must resist phishing, replay, and interception, especially for workforce admin access, remote access, and machine-to-machine trust. OTP is still useful in some lower-risk contexts, but it is weaker where an attacker can trick a user, proxy a login, or reuse a code quickly enough to win the race.
That is why phishing-resistant MFA is now a central design goal in NHIMG’s MFA Guide. A certificate, particularly when paired with hardware protection, changes the attacker’s job from stealing a short-lived code to breaking a stronger cryptographic binding to a device or key material.
What OTP still does well, and where it breaks down
OTP remains attractive because it is easy to deploy, widely understood, and often better than passwords alone. The problem is that many OTP formats, especially SMS and app-generated one-time codes, can still be intercepted, relayed, phished, or approved under pressure. In practice, OTP often reduces opportunistic abuse without fully closing the path for a determined adversary.
Attackers routinely exploit those weaknesses by using relay kits, adversary-in-the-middle phishing, SIM swap, or help desk manipulation. Incidents such as Twilio 0ktapus breach 2022 and Change Healthcare breach 2024 show how a weak or absent second factor can become a direct path to account takeover and downstream compromise.
How to decide between certificate auth and OTP
Use certificate-based authentication when the account controls high-value systems, when the organisation can manage certificate issuance and revocation cleanly, and when device trust or private-key protection is part of the security goal. Use OTP only where the blast radius is limited, the threat model is simpler, and the operational burden of certificate lifecycle management would create more risk than it removes.
Machine Identity, PKI and Certificate Lifecycle Guide is the key operational reference here, because certificate strength is only useful if issuance, renewal, revocation, and key protection are reliable. For workforce use, Passwordless and Passkeys Guide shows the closest modern analogue: phishing-resistant authentication that reduces code interception risk while shifting control to device-bound credentials.
Risk and Threat Considerations
OTP increases exposure when the adversary can observe, relay, or coerce the code entry step. The practical failure is not just “a weaker factor”, it is that OTP is often still a shared secret in motion, which gives attackers multiple interception points and a short replay window.
Failure mechanism: A phisher, relay proxy, SIM swapper, or session hijacker obtains the OTP before it expires, then completes authentication as the legitimate user. In larger environments, the same weakness scales across help desk resets, remote access portals, and legacy MFA flows.
Impact: The attacker gains authenticated access, often with enough privilege to move laterally, steal session tokens, or reset additional controls. Where the account protects administrative or production access, the result can be full environment compromise rather than a single login event.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST SP 800-57 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Phishing-resistant auth is central to choosing certs over OTP. |
| Recommendation — Prefer phishing-resistant authentication and avoid OTP where interception risk matters. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The choice hinges on authenticator lifecycle, issuance, and revocation. |
| IA-9 — Service Identification and Authentication | Certificates are a strong fit for mutually authenticating systems and services. | |
| Recommendation — Manage authenticators with enforced lifecycle, rotation, and revocation controls. Use certificate-based authentication for service-to-service trust where mutual proof is needed. | ||
| NIST SP 800-63 | AAL3 — Authenticator Assurance Level 3 | Phishing-resistant authenticators are the core differentiator versus OTP. |
| Recommendation — Target AAL3-style phishing-resistant authenticators for sensitive access paths. | ||
| NIST SP 800-57 | Key Management | Certificate auth depends on protected private keys and managed cryptoperiods. |
| Recommendation — Protect private keys and define rotation and revocation policy before rollout. | ||
Practitioner Guidance
Decision rule: If the account protects admin access, production systems, or remotely reachable infrastructure, prefer certificate-based or otherwise phishing-resistant authentication over OTP. If the use case is low risk and you cannot support certificate operations reliably, OTP can be an interim control, but it should not be treated as equivalent protection.
What to verify: Confirm who owns issuance, renewal, revocation, and device replacement before you commit to certificates. If those lifecycle steps are weak, certificate-based authentication can fail operationally even when it is cryptographically stronger.
What good looks like: The stronger control is the one your team can actually sustain, with clear recovery paths, fast revocation, and no dependence on user-chosen behaviour during the login step.
Practitioner takeaway: Choose the factor that best resists realistic attack paths, not the one that is easiest to explain; for high-value access, that usually means moving away from OTP and toward phishing-resistant certificate-based authentication.
Related resources from NHI Mgmt Group
- When should organisations prioritize passwordless authentication over broader AI automation?
- How can organisations decide when certificate-based authentication is worth the effort?
- How do organisations know if certificate-based authentication is actually reducing risk?
- Why do organisations still need certificate-based authentication when FIDO exists?