Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A sound multi-factor authentication (MFA) solution uses distinct authentication factors, protects the exchange, resists replay, and offers a phishing-resistant method. The required strength depends on the assurance level and the rules that apply to your organization. Under NIST SP 800-63B Revision 4, AAL2 requires a phishing-resistant option; AAL3 requires phishing-resistant cryptographic authentication with a non-exportable private key.

What makes authentication multi-factor?

For an authentication event to count as multi-factor, it must use either a multi-factor authenticator or two separate factors. A password and a browser cookie do not become two factors merely because both are involved in a login. The factors must be distinct in the authentication event.

NIST SP 800-63B Revision 4 is a U.S. federal digital identity standard. Its assurance levels offer a useful way to organize security requirements, but they do not automatically impose the same obligations on every private-sector service. Organizations must separately identify applicable laws, contracts, sector rules, and internal risk policies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How AAL2 and AAL3 differ

NIST sets different requirements for each assurance level. AAL2 and AAL3 are not interchangeable; choose controls according to the assurance level the system must meet.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Requirement AAL2 AAL3
Authentication A multi-factor authenticator or two separate factors Phishing-resistant cryptographic authentication
Replay resistance At least one authenticator must be replay-resistant Required
Phishing resistance The verifier must offer at least one phishing-resistant option Required
Private-key protection No non-exportable-key requirement stated for AAL2 Cryptographic authenticator must use a non-exportable private key; syncable authenticators must not be used
Authentication intent No AAL2 requirement stated here Required
Overall session timeout No more than 24 hours No more than 12 hours
Inactivity timeout No more than one hour No more than 15 minutes

These requirements are from NIST SP 800-63B Revision 4. NIST distinguishes mandatory requirements from recommendations; confirm the exact normative language for the control you are implementing.

Biometrics are not a factor on their own

Under NIST, a biometric is not an authenticator by itself. It is used with a physical authenticator or to activate one, such as when a fingerprint unlocks a device-bound credential.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What phishing resistance means in practice

Phishing resistance is a property of the authentication protocol, not simply a claim that a method is secure. NIST defines it by whether an impostor verifier can obtain secrets or valid outputs without relying on the user to spot the deception. Manually entered one-time passwords (OTPs) and out-of-band codes can be relayed to an impostor and do not qualify as phishing-resistant under this definition.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WebAuthn and FIDO2 can provide phishing resistance through verifier name binding: the authenticator uses the authenticated domain name to select the credential, preventing it from being used at an impostor domain. NIST describes this mechanism in SP 800-63B, Section 3.2.5.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How the main MFA options compare

Method Phishing resistance Operational fit Important caveat
FIDO2/WebAuthn security key or platform authenticator High when correctly supported and configured; verifier name binding protects against credential use at an impostor domain Roaming keys connect by USB or NFC; platform authenticators are built into supported devices Check service, device, and recovery support before rollout
Enterprise PKI smart card Can be phishing-resistant through cryptographic authentication and channel binding in applicable implementations Fits organizations with mature identity and PKI operations; may require card provisioning and readers Less widely available and depends on mature identity management
App-based number matching Not equivalent to a phishing-resistant cryptographic protocol Uses a phone app and user interaction A stronger interim option than simple approve-or-deny push prompts when phishing-resistant MFA is not yet available
OTP or text/email code Not phishing-resistant when a user manually enters the code Often familiar and broadly usable Codes can be phished or relayed; CISA ranks text and email among weaker options

CISA discusses roaming and platform authenticators, PKI, and migration planning in its phishing-resistant MFA guidance. Its business MFA guidance also describes a relative hierarchy of methods. A physical security key is not a universal fit: verify FIDO2/WebAuthn support for each account, device, and operating system, and plan how users will recover access.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to prioritize an MFA rollout

  1. Inventory systems and accounts. Record current MFA coverage, enforcement gaps, and systems that cannot support MFA. Assign each unsupported system an upgrade, integration, migration, or risk-escalation path.
  2. Protect high-value access first. Prioritize administrators, remote access, email, systems containing sensitive data, and critical services. CISA recommends broad coverage across business systems, with priority for administrators and people handling sensitive data.
  3. Offer a phishing-resistant method and plan the transition. Where immediate migration is not feasible, number matching is a stronger interim choice than simple push approval. Keep appropriate compensating controls in place while moving toward phishing-resistant authentication.
  4. Test the full authenticator lifecycle. Exercise enrollment and binding, lost-device handling, recovery, revocation, replacement, and help-desk procedures. Recovery needs vary by assurance level and deployment; a single recovery pattern is not appropriate for every system.
  5. Check user and platform compatibility. Account for accessibility, multiple-device needs, fallback risks, and vendor dependencies. A successful login on one service does not establish compatibility with every account.
  6. Set session and reauthentication rules. Align timeouts with the assurance level and system risk, using the NIST limits in the table when those requirements apply.

CISA recommends requiring MFA broadly and planning upgrades or migration for systems that cannot support it. Its general guidance also recommends number matching as an interim measure when phishing-resistant MFA cannot yet be implemented: More than a Password.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.