simpl.
Cybersecurity GRC 12 items

Passwordless / FIDO2 Rollout Review

Reviews a passwordless authentication rollout using FIDO2/passkeys, covering strategy, enrollment, phishing resistance, recovery, and legacy path closure.

FIDO2NIST 800-63BNIST 800-53

Free PDF · enter your email to download.

Strategy & Standards

  • Are FIDO2/WebAuthn authenticators (security keys or platform passkeys) the target method? *
  • Is the target authentication assurance level (AAL2/AAL3) defined per NIST 800-63B? *
  • Are high-privilege users prioritized for phishing-resistant authenticators? *

Enrollment & Provisioning

  • Is identity verified before enrolling a passwordless credential? *
  • Is at least one backup authenticator registered per user to prevent lockout? *
  • Are authenticator attestation and key requirements enforced for high-assurance roles?

Phishing Resistance

  • Is the method verified as phishing-resistant (origin-bound, no shared secret)? *
  • Are weaker fallback methods (SMS OTP, push) disabled or restricted for protected apps? *
  • Is Conditional Access configured to require phishing-resistant auth for sensitive resources?

Recovery & Migration

  • Is a secure, phishing-resistant account recovery process defined for lost authenticators? *
  • Are legacy password and MFA fallback paths closed once users are migrated? *
  • Are authentication events monitored to confirm adoption and detect fallback abuse?

Download the full Passwordless / FIDO2 Rollout Review checklist

Get it as a clean, printable PDF — free.