Independent UK technology advice — clear, honest and jargon-free.
7 minute read

What Are Passkeys, and Should I Switch From Passwords?

The UK's own cyber-security agency now recommends passkeys over passwords for most accounts. Here's what they actually are, how much safer they really are, and the genuine friction points nobody mentions in the marketing.

How passkeys actually work

A passkey is a pair of cryptographic keys created when you set one up on a website or app. A public key is stored with that service; a private key never leaves your device, kept in secure hardware like your phone's or laptop's dedicated security chip. When you log in, the service sends a one-time 'challenge,' and your device signs it using the private key — unlocked by your fingerprint, face or PIN — and sends the signature back. No password ever travels over the internet, and because the signature is cryptographically tied to the real website's address, a convincing fake login page simply can't get a valid response, even if you're tricked into visiting one.

The UK's own security agency has a clear recommendation

The National Cyber Security Centre — the public-facing arm of GCHQ — has explicitly told consumers passkeys should now be their 'first choice' for authentication, and that passwords should be phased out where possible. Its own assessment is that passkeys are 'at least as secure as, and generally more secure than, pairing the strongest password with two-step verification.' That's a notably strong, specific endorsement from a body that doesn't hand them out lightly.

The evidence backs that up. FIDO Alliance research covering 11,000 consumers across 10 countries, including the UK, found a 93% login success rate for passkeys against 63% for passwords, and separately found a third of people had experienced an account compromise or breach notification in the past year — a reminder of the real, ongoing cost of password-based security.

Who actually supports them

Google, Apple, Microsoft and Amazon all support passkeys broadly, and Microsoft made them the default sign-in option in 2025. UK banking is more of a mixed picture: Revolut has led the way, rolling out passkeys for personal and business accounts from early 2025. Traditional high-street banks have moved more slowly — as of recent reporting, NatWest's own fraud team confirmed passkeys hadn't yet been rolled out, and Monzo had made no public announcement. UK government and NHS services have begun adding passkey sign-in too, per the NCSC.

The friction nobody puts in the marketing

  • Cross-platform syncing is genuinely awkward: Apple's iCloud Keychain passkeys don't sync to non-Apple devices, Windows lacks native passkey sync, and moving a passkey between Android and Apple ecosystems is difficult by design.
  • If your device or cloud account is lost, compromised or inaccessible, your passkeys can become unavailable — recovery options vary a lot by provider and aren't standardised across the industry.
  • Not every website supports passkeys yet — only an estimated fifth to a quarter of the top 1,000 websites did as of early 2026, so passwords aren't going away for most people any time soon.
  • Even the NCSC's own framing acknowledges this: the title of its blog post recommending passkeys is literally 'Passkeys: they're not perfect but they're getting better.'

How adoption is actually going

FIDO Alliance's 2026 State of Passkeys report found 90% of people are now aware of passkeys and 75% have enabled one on at least one account — but only 49% use them regularly when available, and just 40% have them switched on across most of their apps. That gap between 'set one up once' and 'use them as a daily habit' is the clearest sign the transition is still very much in progress rather than complete.

Sources

Prepared by the UKTechExpert editorial team · Published · Checked for evidence, clarity and UK relevance.

How we workReport a correction