A recommendation worth noticing

In April 2026, the National Cyber Security Centre said passkeys should become the default way consumers sign in. The agency had previously been cautious while platform support, recovery and interoperability matured. Its new position signals that the balance has shifted. A passkey uses public-key cryptography: the service keeps a public key while the user’s device protects the private credential. There is no reusable secret for a fake website to collect and replay.

What passkeys solve

Passwords fail because people reuse them, attackers steal databases and convincing phishing pages capture both passwords and one-time codes. A properly implemented passkey is tied to the genuine service, making accidental disclosure far harder. The experience can also be simpler. A person approves access using the same fingerprint, face or device PIN already used to unlock a phone. The biometric normally stays on the device and is not sent to the website.

Recovery is the hard edge

People lose phones and move between ecosystems. A secure sign-in method can still fail users if recovery is confusing or falls back to a weak help-desk process. Services need to test the complete lifecycle, offer understandable device management and maintain a measured fallback during migration. Passkeys do not eliminate malware or manipulation, but they remove one of the internet’s most productive attack surfaces. That makes the NCSC’s change of tone a practical security milestone.

UK TECH TRENDIndependent analysis for the British technology market.

Continue to all articles