8-part series
US authentication requirements come from several directions at once - NIST guidance on assurance levels, CISA on phishing-resistant MFA, the FTC Safeguards Rule for non-bank financial institutions and NYDFS Part 500 in New York. This series covers what each expects, where synced passkeys satisfy it, and the state of US adoption.
Start with the first article, then read whichever answers your question.
How are passkeys regulated in the US? Learn about the latest executive order of the US government on cybeer security & advances in phishing-resistant MFA
Learn about the biggest data breaches in the USA, why the US is an attractive target for cyber attacks and how these could have been prevented.
CISA's latest guide emphasizes passkeys, showcasing the shift towards phishing-resistant MFA as the future of secure authentication
Learn why non-bank financial institutions must comply with the FTC Safeguards Rule for MFA and how passkeys can achieve secure, long-term MFA compliance.
Learn why synced passkeys are AAL2- & device-bound passkeys are AAL3-compliant after NIST's SP 800-63B supplement & what ENISA, NCSC & BSI say about passkeys.
Learn what NYDFS Part 500’s 2025 MFA deadlines must be met, who needs to adapt and how passkeys and phishing-resistant MFA help you stay compliant.
Why FBI Operation Winter SHIELD matters for passkeys, phishing-resistant MFA and the shift away from SMS and legacy authentication.
U.S. passkey providers' security gaps exposed. Developers, learn what it takes to ensure a secure login for your users.
See every login journey clearly, diagnose failures faster and keep your existing IDP in place.