FreeThe +45-page Authentication Analytics Whitepaper — measuring real login journeysDownload

8-part series

United States

US authentication requirements come from several directions at once - NIST guidance on assurance levels, CISA on phishing-resistant MFA, the FTC Safeguards Rule for non-bank financial institutions and NYDFS Part 500 in New York. This series covers what each expects, where synced passkeys satisfy it, and the state of US adoption.

Start with the first article, then read whichever answers your question.

  1. Passkeys in the USA: Passkey Regulation in the US

    How are passkeys regulated in the US? Learn about the latest executive order of the US government on cybeer security & advances in phishing-resistant MFA

    Authentication

  2. 10 Biggest Data Breaches in the USA [2026]

    Learn about the biggest data breaches in the USA, why the US is an attractive target for cyber attacks and how these could have been prevented.

    Authentication

  3. CISA Authentication and Passkeys: Why MFA is Not Enough

    CISA's latest guide emphasizes passkeys, showcasing the shift towards phishing-resistant MFA as the future of secure authentication

    Passkeys Strategy

  4. FTC Safeguards Rule: MFA for non-bank Financial Institutions

    Learn why non-bank financial institutions must comply with the FTC Safeguards Rule for MFA and how passkeys can achieve secure, long-term MFA compliance.

    Authentication

  5. NIST Passkeys: Synced Passkeys Recognized as AAL2-Compliant

    Learn why synced passkeys are AAL2- & device-bound passkeys are AAL3-compliant after NIST's SP 800-63B supplement & what ENISA, NCSC & BSI say about passkeys.

    Passkeys Strategy

  6. NYDFS Part 500 MFA requirements 2025 (New)

    Learn what NYDFS Part 500’s 2025 MFA deadlines must be met, who needs to adapt and how passkeys and phishing-resistant MFA help you stay compliant.

    Authentication

  7. Why the FBI backs Passkeys in Operation Winter SHIELD

    Why FBI Operation Winter SHIELD matters for passkeys, phishing-resistant MFA and the shift away from SMS and legacy authentication.

    Passkeys Strategy

  8. Why US Passkey Providers Don't Help Towards Secure Passkeys

    U.S. passkey providers' security gaps exposed. Developers, learn what it takes to ensure a secure login for your users.

    Passkeys Strategy

Add authentication observability to your rollout

See every login journey clearly, diagnose failures faster and keep your existing IDP in place.

  • Works with your existing stack
  • Diagnose failures faster
  • Prove adoption and impact