Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Organizations should plan to replace SMS-based multi-factor authentication (MFA) with phishing-resistant sign-in, usually using FIDO/WebAuthn passkeys or security keys. That is a clear direction in recent guidance from CISA and NIST—but it is not a single deadline imposed on every organization. The right migration depends on the systems in use, the assurance required, and the rules that apply to the organization.

Why organizations are moving beyond SMS MFA

A text-message code can add a hurdle beyond a password, but it is not designed to resist phishing. A user can be tricked into entering the code on an impostor site, where an attacker can relay it to the legitimate service. Because the code is entered manually, it is not cryptographically bound to the specific site or sign-in session.

NIST’s Digital Identity Guidelines, Revision 4, state that manually entered one-time passwords are not phishing-resistant. The guidelines classify public switched telephone network (PSTN) authenticators, including SMS one-time codes, as restricted and call for a migration plan in case they become unacceptable. This is a standards requirement within the guidelines’ stated digital identity context, not proof of a universal private-sector deadline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA’s January 2023 fact sheet recommends planning for phishing-resistant MFA, and its December 2024 mobile guidance says organizations should migrate away from SMS-based MFA. Taken together, the guidance supports a deliberate transition rather than an assumption that every organization must switch on the same date.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Why passkeys are the practical phishing-resistant option

FIDO authentication, commonly implemented through WebAuthn, uses a cryptographic credential tied to the legitimate service. During sign-in, the browser and authenticator verify the site’s identity, so a credential cannot simply be relayed to a lookalike website in the way a typed code can. CISA describes FIDO/WebAuthn as the only widely available form of phishing-resistant authentication and notes that support is built into major browsers, operating systems, and smartphones.

“Passkey” does not mean a particular kind of device. A passkey can be stored by an authenticator built into a phone or computer, or it can be a roaming physical security key. The choice is about how credentials are created, controlled, backed up, and recovered—not simply whether the employee carries a token.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

NIST’s April 2024 supplement recognizes that correctly implemented syncable authenticators, including passkeys, can provide phishing resistance and can simplify recovery and use across devices. It also describes additional requirements for their use at Authentication Assurance Level 2 (AAL2) and cautions that syncable authenticators are not suitable for every application or service. Organizations should evaluate the applicable assurance requirements and how the passkey provider controls access to synced credentials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose an authenticator model that fits the workforce

There is no single best deployment for every organization. Compare options against the organization’s assurance requirements, device fleet, application support, credential-control policy, recovery process, and support capacity.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Option Where it fits Key decision
Platform passkey Employees signing in on supported phones or computers they can use for work Confirm device and service compatibility, management requirements, and whether the organization permits the provider’s syncing and recovery model.
Roaming FIDO security key Users who need a separate authenticator, including some shared-device situations or users who need a physical backup Check connector type, device compatibility, identity-provider support, issuance, replacement, and backup-key procedures.
SMS code as a temporary fallback Legacy applications or accounts that cannot yet use phishing-resistant authentication Keep the exception limited, apply interim safeguards, and assign an upgrade or migration plan. A text code remains vulnerable to phishing.

CISA’s December 2024 guidance describes hardware FIDO keys as most effective where feasible and accepts passkeys as an alternative. That does not mean every employee needs to buy a key: platform passkeys may already be available on supported devices. Nor does it mean a physical key automatically solves recovery or compatibility; those need to be designed into the rollout.

How to replace SMS MFA with passkeys

  1. Inventory where SMS is used. List the accounts, applications, identity providers, user groups, and recovery flows that rely on text codes. Include administrator accounts, remote access, cloud services, and business-critical systems.
  2. Prioritize sensitive access. Start with administrators and accounts that can reach sensitive data or change security settings. Identify which services support FIDO/WebAuthn and whether access can be managed centrally through the organization’s identity provider.
  3. Set the policy and select the credential model. Decide which users may use platform passkeys, when a roaming key is required, and whether syncing is allowed. Check assurance obligations, managed-device coverage, credential-provider controls, application compatibility, onboarding effort, and support needs.
  4. Design enrollment and recovery before broad rollout. Document how users enroll, replace a lost or changed device, regain access, and obtain help. Define backup authenticator and break-glass procedures, and limit who can authorize recovery. A strong sign-in method is only as dependable as the account-recovery path around it.
  5. Pilot with representative users and applications. Test enrollment, routine sign-in, device replacement, recovery, and administrative workflows with the actual devices and services employees use. Use the results to resolve compatibility and support issues before expanding enrollment.
  6. Remove SMS fallback where the service and recovery design permit. If a user can bypass a passkey by choosing a text code, the account still has a weaker route that may be phished. Review both sign-in and account-recovery settings; some services retain SMS for recovery, so eliminating every text message may not be possible.
  7. Track exceptions and retire them deliberately. For applications that cannot yet use phishing-resistant MFA, record the affected users and systems, apply interim controls, and set an owner and review point for upgrading, migrating, or replacing the application.

What to do when an older application only supports SMS

First determine whether the application can be placed behind the organization’s identity provider or single sign-on (SSO). CISA notes that MFA can often be added through enterprise identity integration even when an individual business application lacks its own MFA support. Validate that the integration covers the relevant access paths, including administrative and remote access.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

If FIDO/WebAuthn cannot be added immediately, treat the application as an exception rather than counting its SMS code as phishing-resistant MFA. CISA identifies number matching and additional controls as possible interim measures, but number matching is not phishing-resistant. Pair any temporary measure with a documented plan to upgrade, migrate, or replace the system.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some services may continue to send SMS during account recovery even after passkey sign-in is enabled. Review what that recovery route allows an attacker to do, whether it can be restricted, and how support staff verify identity before restoring access. The goal is to reduce reliance on text codes without creating an unworkable recovery process.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the guidance does—and does not—require

CISA’s recommendations establish a strong direction toward FIDO authentication and away from SMS MFA. NIST’s Revision 4 guidance gives a standards-based reason to plan for migration from restricted PSTN authenticators. The NIST requirements apply in their specified digital identity context; neither source establishes one cross-sector deadline for every private organization.

Before setting a deadline, determine which regulatory, contractual, or program requirements apply to the organization and its systems. Then set migration milestones according to risk, technical readiness, and the consequences of leaving SMS enabled. The cited guidance does not establish organization-specific legal duties or a universal schedule.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.