
Leave Passwords in the Past: Why the NCSC Is Backing Passkeys for Login Security
The UK’s National Cyber Security Centre (NCSC) has delivered a clear new message: “Leave passwords in the past – passkeys are the future.” In April 2026, the NCSC formally updated its guidance to recommend using passkeys as the default way to log in wherever services support them, instead of traditional passwords (even those paired with multi-factor authentication). This is a major shift in cyber security advice, and overturns decades of password-centric best practices.

















