August 2026. Phishing-resistant MFA (FIDO2, passkeys, hardware keys) is standard in security questionnaires. SMS and email OTP are residual risk — document why or plan migration.
Roadmap
- IdP-first: Entra ID, Google, Okta passkey support;
- Admin and remote first — then broader rollout;
- Fallback: break-glass accounts logged and reviewed;
- SoA update: which systems require phishing-resistant.
Link to ISO 27001 SaaS and ISMS. NCSC and CIS IG1 emphasise MFA — passkeys are the next step.
Plan user communication: passkeys are policy, not optional gadget. Metrics: % accounts on FIDO2 in management review.
