FIDO2 / WebAuthn
FIDO2/WebAuthn: FIDO Alliance Certification, Adoption and Status

FIDO2 / WebAuthn FIDO2-FIDO-Certification: FIDO Alliance Certification Programs - Authenticator + Server + Biometric Component

FIDO Alliance certification programmes ensure interoperable + secure implementations. PROGRAMMES: (a) FIDO2 Authenticator Certification (L1 + L2 + L3 + L3+) - tests CTAP2 + WebAuthn compliance + cryptographic implementation + side-channel resistance + secure-element integration; (b) FIDO2 Server Certification - tests RP-side compliance with WebAuthn + attestation verification + extension handling; (c) UAF Authenticator + Server Certification (legacy mobile FIDO 1.x); (d) U2F Authenticator + Server Certification (legacy second-factor only); (e) FIDO Biometric Component Certification - tests biometric subsystem against FAR + FRR + PAD (Presentation Attack Detection) targets per ISO/IEC 30107-3. ACCREDITED LABS: SGS Brightsight + Cigital + Riscure + Synopsys + UL + others - independent test labs accredited by FIDO Alliance. CONFORMANCE TESTS: published test suites for authenticators + servers + clients. METADATA SERVICE STATUS: certified authenticators receive FIDO_CERTIFIED + L1/L2/L3+ status in MDS3; non-certified or non-submitting authenticators marked NOT_FIDO_CERTIFIED. ENTERPRISE BEST PRACTICE: require FIDO_CERTIFIED L2 or higher for managed-deployment authenticators + maintain inventory of certified AAGUIDs.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in FIDO2/WebAuthn: FIDO Alliance Certification, Adoption and Status

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.