FIDO2 / WebAuthn
FIDO2/WebAuthn: Authenticators, Passkeys and User Verification

FIDO2 / WebAuthn FIDO2-Passkey-Discoverable: Passkeys (Discoverable Credentials) and Account Recovery

Discoverable credentials (formerly Resident Credentials) per WebAuthn L3 6.3 + CTAP2.1 are credentials whose private-key + per-credential metadata (rpId + userHandle + signCount) are stored on the authenticator. The user-handle enables AUTHENTICATION WITHOUT USERNAME - the RP can call navigator.credentials.get() without allowCredentials + the authenticator presents matching credentials to the user for selection. PASSKEYS: marketing name for FIDO2 discoverable credentials that ALSO support multi-device sync. Apple iCloud Keychain (2022) + Google Password Manager (2023) + Microsoft Windows Hello + 1Password + Bitwarden + Dashlane support passkey synchronisation across user devices. BACKUP ELIGIBILITY (BE) + BACKUP STATE (BS) FLAGS in authenticatorData: BE indicates the credential CAN be backed up; BS indicates the credential IS currently backed up. RP USE: BE+BS=11 indicates a synced passkey; BE=0 indicates a single-device credential (security key). Account recovery: passkey sync provides recovery via account sync; single-device credentials require enrolment of multiple authenticators OR recovery code OR identity-verification reset. EXPORT/IMPORT: in 2024-2025 FIDO Alliance is developing credential-exchange-protocol (CXP) for cross-platform passkey portability; until CXP is broadly available, passkeys are typically locked to a single platform's sync ecosystem (Apple to Apple + Google to Google).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 48 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-7 A07:2025 Identification and Authentication Failures
  • AMLCTF-35 Identity Verification Standard

BSI IT-Grundschutz · 1 control

  • BSI-03 Multi-factor authentication requirements
  • DSO-3 Data Access Management
  • IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

MITRE D3FEND · 1 control

  • OWASPAPI-2 Broken Authentication and Token Management

OWASP ASVS · 1 control

  • OWASPASVS-2 Authentication and Credential Storage (V2 + V2.4)
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in FIDO2/WebAuthn: Authenticators, Passkeys and User Verification

Query this from an agent

The graph holds this control, the 48 it maps to, and the evidence behind each claim, over MCP and REST.