Ga naar inhoud

ISO 27001 ·

Passkeys and phishing-resistant MFA: SME roadmap in 2026

August 2026. Phishing-resistant MFA (FIDO2, passkeys, hardware keys) is standard in security questionnaires. SMS and email OTP are residual risk — document why or plan migration.

Roadmap

  1. IdP-first: Entra ID, Google, Okta passkey support;
  2. Admin and remote first — then broader rollout;
  3. Fallback: break-glass accounts logged and reviewed;
  4. SoA update: which systems require phishing-resistant.

Link to ISO 27001 SaaS and ISMS. NCSC and CIS IG1 emphasise MFA — passkeys are the next step.

Plan user communication: passkeys are policy, not optional gadget. Metrics: % accounts on FIDO2 in management review.

Deep dive in the knowledge base

Run the ISO 27001 readiness scan

See where you stand before investing in documents or consultants.

Start the readiness scan

← Back to overview