TL;DR: The 2025 FIDO report shows 75% of global consumers now know about passkeys, 48% of the top 100 websites already support them, and nearly half of consumers have abandoned purchases after forgetting passwords, according to Descope. Passwordless adoption is no longer a UX experiment; it is becoming a customer IAM control and conversion issue at the same time.
NHIMG editorial — based on content published by Descope: 2025 FIDO Report on the passwordless future and passkey adoption
By the numbers:
- 75 percent of global consumers are now aware of passkeys.
- 48% of the top 100 websites reviewed by the FIDO Alliance offered passkeys as a login method.
Questions worth separating out
Q: How should organisations roll out passkeys without breaking customer login flows?
A: Start with journeys that already tolerate fallback, such as signup, account recovery, and step-up authentication.
Q: When do passkeys reduce risk enough to replace passwords as the default method?
A: They make the most sense when phishing resistance, reduced account takeover exposure, and lower friction all matter at once.
Q: What do security teams get wrong about passwordless authentication?
A: The most common mistake is treating passwordless as a user-experience upgrade instead of an identity control change.
Practitioner guidance
- Define where passkeys are primary Map customer journeys and classify which account types can move to passkeys first, then reserve passwords for only the cases that genuinely need them.
- Design fallback and recovery paths first Document how users recover access when devices are lost, unsupported, or shared so passwordless deployment does not recreate weak recovery patterns.
- Measure business and security outcomes together Track passkey adoption, login completion, support ticket reduction, and account takeover signals in the same rollout dashboard.
What's in the full article
Descope's full post covers the operational detail this analysis intentionally leaves for the source:
- Passkey integration options across web and mobile authentication journeys
- Low-code and no-code flow design for staged passwordless rollout
- A/B testing approaches for comparing passkeys with other authentication methods
- Fallback authentication handling for devices that are not WebAuthn-compatible
👉 Read Descope's analysis of the 2025 FIDO passkey report and passwordless adoption →
Passkeys and passwordless auth: what should IAM teams change now?
Explore further
Passwordless authentication is now a customer IAM control, not just a convenience feature. The article shows that passkeys are being evaluated against abandonment, support cost, and account takeover exposure at the same time. That shifts the conversation from login preference to identity risk management, because the authentication method now affects both fraud surface and conversion loss. Practitioners should treat passwordless design as part of IAM architecture, not as a user-experience experiment.
Passwordless adoption will keep moving from UX conversation to identity governance programme work. As consumer expectations rise, teams need to plan for enrolment, replacement, recovery, and step-up decisions as part of the same authentication policy set, not as separate projects.
A question worth separating out:
Q: How do you know if passkeys are actually improving customer IAM?
A: Look for higher login completion, fewer password resets, reduced abandonment, and lower takeover signals in the same reporting cycle. If passkey adoption rises but recovery friction or support volume also rises, the programme is not yet stable. Success means both security and customer experience improve together.
👉 Read our full editorial: Passkeys are reshaping passwordless authentication for customer IAM