FIDO2/WebAuthn implementation status as of 2026. STANDARDS BASE: W3C WebAuthn Level 3 Recommendation (2024); FIDO CTAP2.1 (FIDO Alliance Proposed Standard 2021 + 2.2 Editor Draft for hybrid transport); FIDO Metadata Service v3 (FIDO Alliance 2021); WebAuthn Level 4 in development with extensions for credential-exchange-protocol + PRF improvements + cross-device coordination. PASSKEY ADOPTION: Apple iCloud Keychain (2022) + Google Password Manager (2023) + Microsoft Windows Hello (2023) + 1Password + Bitwarden + Dashlane (2023-2024) all support passkeys with sync; major sites including Google + Microsoft + Apple + GitHub + PayPal + Shopify + Best Buy + eBay + Amazon (2024-2025) support passkey login; the FIDO Alliance Passkey Pledge campaign (2024) tracks passkey adoption metrics. GOVERNMENT: NIST SP 800-63B AAL3 phishing-resistant + 2022 OMB M-22-09 + 2024 ZTA strategy mandate FIDO2 + PIV/CAC for US federal; UK NCSC + EU ENISA + Australia ACSC + Singapore CSA recommend FIDO2 for critical infrastructure + government services. THREAT EVOLUTION: 2024 attacks on passkey-sync infrastructure (account-takeover via password-recovery fallback weakness); 2024-2025 hybrid-transport BLE proximity downgrade attacks (mitigated by CTAP2.2 + WebAuthn L3 hints); enterprise FIDO2 deployments without enterprise attestation + AAGUID allowlisting (recurring audit findings). FIDO DEVICE ONBOARDING (FDO): the FIDO Alliance IoT standard for zero-touch device onboarding + ownership transfer (2022 + ongoing).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.