UK Plans Transition From Passwords to Passkeys With New Timeline

UK Plans Transition From Passwords to Passkeys With New Timeline

The UK government has announced a bold move to implement passkey technology across its digital platforms, aiming to enhance security and protect citizens’ GOV.UK accounts from cyber threats. This shift, revealed at the CYBERUK 2025 conference in Manchester, marks a significant step towards replacing the existing SMS-based two-factor authentication system with a more robust solution by the end of 2025.

Key public services offered through GOV.UK, including benefits, childcare support, and tax credits, will adopt this advanced authentication system, positioning the UK as a pioneer in adopting passwordless technology at a national level.

Introducing Passkeys: A Leap Forward in Secure Authentication

Passkeys represent a breakthrough in online security. Unlike traditional passwords, which can be easily compromised, passkeys use advanced cryptography to secure accounts. These digital credentials are linked to a user’s profile on a specific site or app and are designed to make unauthorized access nearly impossible.

A passkey system works by storing a private key on the user’s device, which is used to generate a unique cryptographic signature. This signature is verified by the public key stored on the server. The authentication process is seamlessly carried out through biometric recognition, such as fingerprints or facial scans, eliminating the need for users to recall and input complicated passwords.

The WebAuthn API, part of the Credential Management API, facilitates this secure system by integrating public key encryption. When a passkey is registered, the browser works with an authenticator to create and store the necessary credentials securely on the server.

The Key Benefits of Passkeys

  1. Phishing Resistance: Since passkeys are only functional with their registered services, they are immune to phishing attacks.
  2. Faster Logins: Passkeys save valuable time by bypassing the need for passwords and SMS codes, speeding up the login process.
  3. Cost Savings: Transitioning away from SMS-based verification will significantly lower operational costs for public services.
  4. No More Password Hassles: Passkeys remove the risk of forgotten or mistyped passwords, eliminating the tedious reset process.

The UK’s Commitment to Security Innovation

Feryal Clark, Minister for AI and Digital Government, highlighted the importance of this transition, noting it would not only simplify user interactions with government services but also help reduce fraud and phishing risks that hinder economic progress.

The NHS has already set the stage by becoming one of the first global government agencies to adopt passkeys, sharing valuable insights into its successful rollout at the CYBERUK 2025 event.

Furthermore, the National Cyber Security Centre (NCSC) is preparing to introduce passkey support on its myNCSC platform, expected later this year. The UK government has also joined the FIDO Alliance, an industry group focused on shaping passwordless authentication standards.

Ollie Whitehouse, NCSC Chief Technical Officer, emphasized the urgency for organizations across the UK to transition away from outdated password-based and multi-factor authentication methods, recommending passkeys as the optimal solution to combat cyber threats such as phishing and credential stuffing.

“The adoption of passkeys will not only improve security but also streamline the login process, offering users a quicker, safer, and more efficient experience,” Whitehouse said.

By joining the FIDO Alliance, the UK government is ensuring its active participation in the development of next-generation authentication standards, solidifying the nation’s position at the forefront of global cybersecurity advancements.

More Articles & Posts