TL;DR: Passwordless authentication, passkeys, and phishing-resistant MFA are accelerating, but the real challenge is scaling trust across platforms, privacy models, and future post-quantum requirements, according to OneSpan’s commentary on Gartner’s July 2025 Hype Cycle for Digital Identity. The important shift is that passwordless is now table stakes, not an end state, and IAM teams need to plan for what comes after it.
At a glance
What this is: OneSpan argues that passwordless identity is now a baseline and the next challenge is building scalable trust controls around portability, privacy, and future authentication shifts.
Why it matters: IAM teams need to treat passkeys and phishing-resistant MFA as part of a broader identity architecture, not the finish line, because trust, interoperability, and future-proofing still determine programme viability.
Context
Passwordless authentication removes passwords from the authentication path, but it does not remove the need to govern trust. The article frames digital identity as a control plane for access, security, and assurance, then argues that the real work now lies in scaling that trust across ecosystems, privacy models, and future authentication requirements.
For IAM and security teams, the practical issue is not whether passkeys work. It is whether identity architecture can support them consistently across devices, platforms, and relying parties while preserving user privacy and preparing for later shifts such as post-quantum authentication and verifiable credentials.
Key questions
Q: What should IAM teams watch when rolling out passwordless login?
A: Watch enrollment assurance, recovery, device revocation, and exception handling. Passwordless only stays strong if the enrolled device remains trusted and the recovery path does not fall back to weak shared secrets. The programme should also verify that badges, passkeys, or hardware keys are managed through the same identity lifecycle as other credentials.
Q: Why do passkeys not eliminate the need for continuous authentication?
A: Passkeys reduce phishing and credential replay, but they only prove the user at the point of login. They do not prove the same user is still present after session hijack, device compromise, or account takeover. Continuous authentication addresses that gap by reassessing trust during the session, not just at entry.
Q: When should organisations prioritise verifiable credentials over other identity upgrades?
A: When portability, privacy minimisation, and reusable identity claims are real programme goals, and when the relying-party ecosystem can support them. If the surrounding ecosystem is immature, verifiable credentials add complexity without much operational benefit. Prioritise them where the business case is strongest and acceptance is credible.
Q: What should security teams prepare for after passwordless adoption becomes standard?
A: They should prepare for cryptographic transition, ecosystem interoperability, and identity governance that works beyond the login step. Passwordless reduces one class of risk, but it does not end the need to manage trust, recovery, privacy, or future authentication models such as post-quantum approaches.
Technical breakdown
Why passkeys need ecosystem-wide trust controls
Passkeys and phishing-resistant MFA improve authentication by reducing password exposure and phishing susceptibility, but they still depend on enrollment, binding, recovery, device support, and policy consistency. That means the control problem shifts from password secrecy to ecosystem trust. If one platform or app handles credentials differently, the assurance model fragments. In practice, passwordless only works at scale when identity, device, and policy decisions align across the full access path.
Practical implication: treat passkey adoption as an ecosystem design problem, not a single-factor replacement.
Why continuous authorisation changes the identity model
Continuous authorisation, often discussed as AuthZEN, moves identity decisions closer to the moment of access and away from one-time login events. That matters because authentication alone cannot capture changing context, risk, or resource sensitivity after a session starts. In modern IAM, the trusted state is not fixed at sign-in. It must be reevaluated as conditions change, especially when access spans cloud services, SaaS, and mixed trust boundaries.
Practical implication: pair strong authentication with ongoing authorisation decisions for higher-risk access paths.
How verifiable credentials reshape portability and privacy
Decentralized identity and verifiable credentials aim to let users carry reusable identity claims across contexts without exposing more data than necessary. The technical appeal is portability with less reliance on centralised account reuse, but the governance challenge is interoperability. Without common standards and acceptance across ecosystems, privacy gains stay theoretical. The article’s point is that reusable identity must remain controllable, not just convenient.
Practical implication: evaluate verifiable credential pilots for interoperability, disclosure minimisation, and relying-party readiness.
NHI Mgmt Group analysis
Post-passwordless identity is a trust architecture problem, not an authentication feature problem. Passwordless removes a common attack surface, but it does not solve how identity is bound, reused, recovered, or governed across platforms. The market conversation has moved beyond login mechanics to the question of whether the surrounding trust model can scale. Practitioners should treat passwordless as one control layer inside a larger identity fabric.
Continuous authorisation is the right answer to a trust model that no longer ends at sign-in. Static authentication assumptions break down when risk changes during a session, across devices, or across services. That is why post-passwordless programmes will need more than stronger login factors. They will need policy decisions that stay alive after authentication and track context as access unfolds.
Portable identity: the next stage of digital identity will be judged by whether claims can move safely across ecosystems without recreating password-era sprawl. Verifiable credentials promise less friction and better privacy, but only if the ecosystem supports common standards and predictable trust decisions. Otherwise, organisations simply trade one form of account fragmentation for another. Practitioners should test portability against governance, not just user experience.
Post-quantum readiness is now part of identity planning, not a separate cryptography conversation. The article correctly links future authentication resilience to post-quantum security because identity systems depend on cryptographic trust chains that will age. That means IAM roadmaps can no longer stop at phishing resistance. They have to account for how authentication, key material, and trust infrastructure will behave under later cryptographic transition pressures.
From our research library:
- eBay's passkey data shows 55-60% of passkey adoption happens on mobile, against around 20% on desktop.
What this signals
Portable identity will become the next governance test for IAM programmes. Once passwordless is no longer novel, the question becomes whether identity claims can move safely across applications, devices, and organisations without recreating fragmented account logic. That shifts programme focus from replacing passwords to controlling how trust is expressed and reused.
Post-quantum readiness belongs on the identity roadmap now. Authentication systems depend on cryptographic trust chains, and those chains will eventually face transition pressure. Teams that wait until the migration becomes urgent will discover that identity governance, federation, and recovery logic all need to move together.
For practitioners
- Map identity trust boundaries Inventory where passwordless, passkeys, and phishing-resistant MFA are actually enforced, then identify the platforms and applications that still rely on weaker fallback paths.
- Design for cross-platform portability Check whether your authentication and identity proofing choices can travel across browsers, devices, and relying parties without forcing separate account silos.
- Pilot continuous authorisation Use high-risk applications to test whether access should be re-evaluated during a session rather than only at login, especially where context shifts quickly.
- Start post-quantum planning now Review authentication, federation, and key dependencies that will need transition planning when cryptographic assumptions change.
Key takeaways
- Passwordless reduces authentication friction and phishing exposure, but it does not by itself solve the broader trust architecture problem.
- The article’s central message is that IAM programmes must now account for portability, privacy, interoperability, and future cryptographic change.
- Identity teams should treat passkeys and phishing-resistant MFA as foundational controls while planning for continuous authorisation and post-quantum transition.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the technical controls, while GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B — Authentication | The article centres on phishing-resistant authentication and passwordless sign-in. |
| Recommendation — Use SP 800-63B to anchor passwordless and phishing-resistant authentication requirements. | ||
| NIST Zero Trust (SP 800-207) | Continuous verification — Continuous verification | The article argues that trust must be reassessed beyond the login event. |
| Recommendation — Apply continuous verification principles to keep access decisions current after authentication. | ||
| NIST AI RMF | MANAGE — AI risk management | Only lightly relevant where the article references future identity and trust governance patterns. |
| Recommendation — Use MANAGE to align emerging identity controls with governance and accountability. | ||
| GDPR | Art.5 — Principles relating to processing of personal data | Verifiable credentials and privacy minimisation touch personal data governance. |
| Recommendation — Apply Art.5 principles when designing portable identity and disclosure-minimising credential flows. | ||
Key terms
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
- Passkey: A passkey is a passwordless credential based on public key cryptography. A private key stays on the user’s device, while a public key is stored by the service. During login, the device signs a challenge after local unlock, which reduces phishing and eliminates shared secret reuse.
- Continuous authorization: Continuous authorization is the practice of rechecking access as a session unfolds instead of trusting a single login decision. It matters for AI workflows because the request, context, retrieved data, and downstream action can all change between prompt and execution, making static approval too blunt.
- Verifiable Digital Credential: A verifiable digital credential is structured identity data that can be checked cryptographically by a relying party. Instead of relying on visual inspection, the verifier validates issuer signatures and presentation rules, which gives the control a clearer trust basis than an image-based document.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org