By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: YubicoPublished October 21, 2025

TL;DR: Passkeys are increasingly being used beyond login for signing, digital wallets, and high-value approvals, while post-quantum prototypes and crypto-agility work show where the authentication stack is heading, according to Yubico. The governing challenge is no longer password replacement alone, but whether identity controls can support possession, intent, and selective disclosure without expanding trust in the wrong places.


At a glance

What this is: This is a Yubico-authored view of how passkeys are expanding from authentication into signing, digital identity, and post-quantum experimentation.

Why it matters: It matters because identity teams will need to govern stronger authenticators across login, approval, and lifecycle workflows without treating passkeys as a single-purpose replacement for passwords.

By the numbers:

👉 Read Yubico's analysis of passkeys, digital identity, and post-quantum prototypes


Context

Passkeys are a stronger form of human authentication that replace passwords with cryptographic proof tied to a device or platform credential. The article argues that the next stage is broader than login, extending into signing, approvals, digital wallets, and post-quantum readiness. For identity teams, that shift raises governance questions about where authentication ends and where high-assurance authorization begins.

The operational gap is that many IAM programmes still treat credentials as login artefacts only. Once the same authenticator is used to approve sensitive actions, sign digital identity claims, or support wallet-based interactions, lifecycle control, assurance level, and recovery design all become part of the identity problem.

Yubico also frames the post-quantum discussion as prototype-level work rather than a shipping capability. That is the right distinction for practitioners, because crypto-agility and standards maturity matter more than marketing claims when authentication is tied to regulated or high-value workflows.


Key questions

Q: How should organisations deploy passkeys for enterprise access?

A: Use device-bound passkeys for privileged and sensitive access, and treat synced passkeys as a consumer convenience rather than an enterprise assurance baseline. The practical test is whether the credential can be inventoried, revoked, and kept outside cloud recovery workflows that attackers can abuse. If not, the deployment does not meet enterprise-grade control expectations.

Q: When do passkeys improve security but still leave governance gaps?

A: Passkeys improve security when they replace reusable secrets, but governance gaps remain if fallback authentication, recovery, or exception handling still relies on passwords or OTPs. If those paths remain open, the organisation may have improved the primary login but left the real control boundary unchanged.

Q: How should security teams prepare identity systems for post-quantum cryptography?

A: They should start with a complete inventory of where cryptography underpins authentication, federation, signing, and encrypted transport. Then they should rank systems by business lifetime and migration complexity, because the most dangerous dependencies are the ones that must remain trusted for years. Crypto-agility matters when replacement can happen without re-architecting the whole identity stack.

Q: How do passkeys relate to digital wallets and verifiable credentials?

A: Passkeys prove control of the authenticator, while verifiable credentials prove something about the person or subject. The two are complementary when the wallet preserves selective disclosure and the identity programme separates proof of possession from proof of attributes.


Technical breakdown

Passkeys as phishing-resistant authenticators

Passkeys are based on asymmetric cryptography, which means the private key stays on the user device while the public key is registered with the service. That design removes reusable shared secrets from the login flow and makes phishing far harder than password and OTP-based authentication. In practice, passkeys are a form of federated or platform-backed human authentication, not an autonomous identity system, so the governance model remains human IAM with stronger cryptographic assurance.

Practical implication: identity teams should map passkey use to assurance levels, recovery controls, and enrollment governance rather than treating it as a UX-only upgrade.

From login to signing and approval workflows

The article describes using the same hardware-backed credential to sign sensitive actions, not just authenticate at the front door. That changes the role of the authenticator from proof of presence at login to proof of possession and intent at the moment of approval. Once a passkey authorizes code pushes, wire initiation, KMS root rotation, or policy changes, the control boundary shifts into privileged action governance and step-up authentication design.

Practical implication: teams should define which actions can rely on passkey-based approval and which still require separate privileged workflows or additional checks.

Post-quantum signatures and crypto-agility

Post-quantum cryptography aims to keep signatures resistant to future quantum attacks, but the article correctly notes that the work is not product-ready and requires new hardware plus mature standards. Crypto-agility is the ability to change algorithms, protocols, and attestation flows without redesigning the whole trust model. That matters because authentication systems that cannot rotate cryptographic assumptions will age badly as standards evolve.

Practical implication: architecture teams should inventory where key material, attestation, and signature protocols would block a future algorithm migration.


NHI Mgmt Group analysis

Passkeys are becoming an identity control surface, not just a password replacement. The article shows the category moving from login into approvals, wallets, and selective disclosure. That widens the governance surface from authentication assurance to action authorization and identity proofing. Practitioners should treat passkeys as part of the identity lifecycle, not as a one-time MFA upgrade.

The real policy question is not whether passkeys are stronger, but which actions they are allowed to authorise. A credential that can approve code changes, KMS rotations, or financial transfers sits in a different risk class from a login-only factor. That distinction belongs in PAM, IAM, and transaction approval design, because the same authenticator can support very different risk decisions.

Crypto-agility is now an identity governance requirement. The article’s post-quantum prototype demonstrates that the technical path exists, but the operational path depends on standards maturity, device capability, and migration planning. Organisations that hard-code current algorithms into identity flows will create future lock-in. Practitioners should expect cryptographic change management to sit alongside classic identity lifecycle governance.

Passkey-enabled digital identity raises the bar for privacy-preserving assurance. The article’s wallet discussion reflects a broader shift toward proving enough about the subject without oversharing. That aligns with modern IAM principles where credential strength, selective disclosure, and user control have to coexist. Practitioners should view this as a sign that identity architectures must support both trust and minimisation.

Hardware-backed identity will matter more as sensitive workflows move beyond human login. The same device-based trust that resists phishing at authentication time can also anchor higher-value actions if the governance model is clear. That does not eliminate policy risk, but it gives identity teams a stronger trust primitive to build on. The practitioner task is to decide where that primitive belongs in the control stack.

From our research:

  • The ratio of non-human to human identities now exceeds 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which shows how quickly non-human governance lags behind usage growth.
  • This broader lifecycle gap is explored in the Ultimate Guide to NHIs, alongside rotation, offboarding, and Zero Trust implications.

What this signals

Passkeys will keep moving deeper into approval and wallet workflows, which means IAM teams need to separate login assurance from transaction authorisation. The most common programme failure will be assuming that stronger authentication automatically solves privileged action governance, when the real issue is where the same authenticator is permitted to operate.

Credential-to-claim convergence: passkeys, verifiable credentials, and hardware-backed signing are starting to converge into a single trust layer. That convergence is useful, but it also means identity teams must define boundaries for selective disclosure, recovery, and device trust before those controls become entangled in business-critical processes.

The more organisations use devices as the root of trust for human identity, the more important lifecycle operations become. Enrollment, reproofing, lost-device recovery, and revocation need to be designed as continuously governed identity events, not one-time setup tasks.


For practitioners


Key takeaways

  • Passkeys are expanding identity governance beyond login into approvals, wallets, and signed actions.
  • Crypto-agility and post-quantum readiness now belong in identity architecture planning, not only in cryptography roadmaps.
  • The governance challenge is deciding which actions a passkey may authorise, not simply whether it can replace a password.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BPasskeys map directly to phishing-resistant authenticators and assurance levels.
NIST CSF 2.0PR.AC-7Passkey-based access ties into access control and verification of identities.
NIST SP 800-53 Rev 5IA-5Authentication and authenticator management are central to passkey lifecycle governance.
ISO/IEC 27001:2022A.8.5Authentication information management is relevant when passkeys support login and signing.

Use SP 800-63B to set assurance, enrollment, and authenticator lifecycle rules for passkey deployments.


Key terms

  • Passkey: A passkey is a passwordless credential based on public key cryptography. A private key stays on the user’s device, while a public key is stored by the service. During login, the device signs a challenge after local unlock, which reduces phishing and eliminates shared secret reuse.
  • Crypto-Agility: Crypto-agility is the ability to change cryptographic algorithms, certificates, and trust dependencies without redesigning production systems. It matters because cryptographic standards evolve, and organisations need accurate inventories and automated lifecycle controls before they can migrate safely.
  • Verifiable Digital Credential: A verifiable digital credential is structured identity data that can be checked cryptographically by a relying party. Instead of relying on visual inspection, the verifier validates issuer signatures and presentation rules, which gives the control a clearer trust basis than an image-based document.
  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.

What's in the full article

Yubico's full post covers the product and standards detail this analysis intentionally leaves aside:

  • Keynote context from FIDO Authenticate on the current direction of passkeys and post-quantum authentication
  • Technical explanation of how security keys support signing flows inside a standards-based digital wallet
  • Prototype details for post-quantum signatures, including the hardware constraints and standards gaps
  • The collaboration example behind wwWallet and why verifiable credentials and passkeys are being positioned as complementary

👉 Yubico's full post covers the keynote context, prototype details, and wallet use cases in more depth

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org