Join our Newsletter — 33% off our NHI Course

CIAM certifications, passkeys, and accessibility: what changes now?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Customer identity fraud remains costly, with Javelin Strategy & Research cited by Strivacity showing new account fraud rose 109% and account takeover losses rose 90% in 2021, while the average victim loss exceeded $1,000. The practical lesson is that CIAM trust now depends on verifiable controls across authentication, security, and accessibility, not brand claims.

Editorial analysis by NHI Mgmt Group, based on content published by Strivacity: “Strivacity’s PCI DSS, WCAG & SOC2 Certifications Explained”.

By the numbers:

  • According to Javelin Strategy & Research cited by Strivacity, new account fraud rose 109% in 2021.
  • According to Javelin Strategy & Research cited by Strivacity, account takeover losses increased 90% in 2021.
  • According to Javelin Strategy & Research cited by Strivacity, the average per-victim loss across identity fraud was more than $1,000.

Key questions

Q: How should teams validate CIAM trust beyond vendor claims?

A: Treat third-party certification as one input, then verify that it covers the specific customer journeys you operate.

Q: Why do passkeys still leave account takeover risk in place?

A: Passkeys remove reusable secrets from login, but they do not eliminate weaker alternate paths attached to the same account.

Q: What breaks when accessibility is missing from CIAM design?

A: Users with disabilities may be unable to complete sign-in, recovery, or challenge flows, which creates both service friction and security workarounds.

Practitioner guidance

  • Define CIAM trust criteria against external assurance Map customer identity journeys to the standards and audits that matter for your environment, including authentication, privacy, and accessibility evidence.
  • Adopt phishing-resistant customer authentication Prioritise passkeys and other FIDO2-based flows where they reduce password risk without breaking support for common consumer devices.
  • Embed accessibility testing into CIAM reviews Test the customer identity experience against WCAG outcomes in the exact flows users depend on, especially login, recovery, and step-up authentication.

Bottom line: CIAM trust is moving toward verifiable evidence, with certifications, authentication standards, and accessibility all contributing to the assurance model.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

CIAM certifications are an assurance mechanism, not a branding exercise: In customer identity, external validation matters because the control surface extends beyond authentication into recovery, accessibility, privacy, and fraud resistance. A certification does not prove perfect security, but it does show that the provider accepted third-party scrutiny over the operating model. For practitioners, the relevant question is whether the certification maps to the customer journeys that actually carry risk.

A question worth separating out:

Q: Should identity teams prioritise FIDO2 or WCAG first in CIAM programmes?

A: If the programme is already struggling with phishing and password risk, phishing-resistant authentication usually comes first. If the immediate failure is that legitimate customers cannot complete the journey, accessibility work is the faster trust repair. In mature CIAM programmes, both should be treated as parallel trust controls.

👉 Read our full editorial: CIAM certifications change the trust calculus for customer identity


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.