Cybersecurity GRC 12 items
Passwordless / FIDO2 Rollout Review
Reviews a passwordless authentication rollout using FIDO2/passkeys, covering strategy, enrollment, phishing resistance, recovery, and legacy path closure.
FIDO2NIST 800-63BNIST 800-53
Free PDF · enter your email to download.
Strategy & Standards
- Are FIDO2/WebAuthn authenticators (security keys or platform passkeys) the target method? *
- Is the target authentication assurance level (AAL2/AAL3) defined per NIST 800-63B? *
- Are high-privilege users prioritized for phishing-resistant authenticators? *
Enrollment & Provisioning
- Is identity verified before enrolling a passwordless credential? *
- Is at least one backup authenticator registered per user to prevent lockout? *
- Are authenticator attestation and key requirements enforced for high-assurance roles?
Phishing Resistance
- Is the method verified as phishing-resistant (origin-bound, no shared secret)? *
- Are weaker fallback methods (SMS OTP, push) disabled or restricted for protected apps? *
- Is Conditional Access configured to require phishing-resistant auth for sensitive resources?
Recovery & Migration
- Is a secure, phishing-resistant account recovery process defined for lost authenticators? *
- Are legacy password and MFA fallback paths closed once users are migrated? *
- Are authentication events monitored to confirm adoption and detect fallback abuse?
Download the full Passwordless / FIDO2 Rollout Review checklist
Get it as a clean, printable PDF — free.
