FIDO2 / WebAuthn — Passwordless Authentication Standard
FIDO2 is the passwordless authentication standard developed by the FIDO Alliance and W3C. FIDO2 consists of two components: WebAuthn (W3C Web Authentication API) and CTAP2 (Client-to-Authenticator Protocol). FIDO2 enables passwordless, phishing-resistant authentication using public key cryptography. Supported by all major browsers (Chrome, Firefox, Safari, Edge), operating systems (Windows Hello, macOS/iOS Face ID/Touch ID, Android biometrics), and platforms (Google Passkeys, Apple Passkeys, Microsoft Passkeys). Over 12 billion accounts can use FIDO2. FIDO Alliance has 300+ member companies. FIDO2 passkeys are the recommended replacement for passwords by NIST, CISA, and ENISA.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
CTAP2 (Client to Authenticator Protocol)
| Code | Title |
|---|---|
| FIDO2-2.1 | Authenticator API |
| FIDO2-2.2 | Transport Bindings |
| FIDO2-2.3 | PIN/UV Protocol |
| FIDO2-2.4 | Credential Management |
Passkey and Platform Integration
| Code | Title |
|---|---|
| FIDO2-4.1 | Discoverable Credentials (Passkeys) |
| FIDO2-4.2 | Platform Authenticator Integration |
| FIDO2-4.3 | Cross-Device Authentication |
Security Requirements
QKD module and network security
WebAuthn API (W3C)
| Code | Title |
|---|---|
| FIDO2-1.1 | Credential Creation (Registration) |
| FIDO2-1.2 | Credential Assertion (Authentication) |
| FIDO2-1.3 | Attestation |
| FIDO2-1.4 | Extensions |
Maps to 179 other frameworks
Frequently Asked Questions
What is FIDO2 / WebAuthn — Passwordless Authentication Standard?
FIDO2 / WebAuthn — Passwordless Authentication Standard is a compliance framework from International (FIDO Alliance/W3C) with 4 domains and 11 controls. FIDO2 is the passwordless authentication standard developed by the FIDO Alliance and W3C. FIDO2 consists of two components: WebAuthn (W3C Web Authentication API) and CTAP2 (Client-to-Authenticator Protocol). FIDO2 enables passwordless, phishing-resistant authentication using public key cryptography. Supported by all major browsers (Chrome, Firefox, Safari, Edge), operating systems (Windows Hello, macOS/iOS Face ID/Touch ID, Android biometrics), and platforms (Google Passkeys, Apple Passkeys, Microsoft Passkeys). Over 12 billion accounts can use FIDO2. FIDO Alliance has 300+ member companies. FIDO2 passkeys are the recommended replacement for passwords by NIST, CISA, and ENISA. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does FIDO2 / WebAuthn — Passwordless Authentication Standard have?
FIDO2 / WebAuthn — Passwordless Authentication Standard has 11 controls organised across 4 domains. The largest domains are CTAP2 (Client to Authenticator Protocol) (4 controls), WebAuthn API (W3C) (4 controls), Passkey and Platform Integration (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does FIDO2 / WebAuthn — Passwordless Authentication Standard map to?
FIDO2 / WebAuthn — Passwordless Authentication Standard maps to 179 other compliance frameworks. The top mapping partners are CSA CCM v4 (27% coverage), CISA ICS-CERT Advisories and Industrial Control Systems Security Guidelines (27% coverage), NIS2 Directive Implementing Acts (27% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with FIDO2 / WebAuthn — Passwordless Authentication Standard compliance?
Start your FIDO2 / WebAuthn — Passwordless Authentication Standard compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FIDO2 / WebAuthn — Passwordless Authentication Standard requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 11 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required