Request a demo

Find out today the difference that Callsign’s unique solution can make to your business.

Seeing is believing.

General enquiries, support and press

By submitting this form, you agree to Callsign’s Privacy Policy

Success

Error

Thank you for your request

Success

In the meantime, connect with Callsign for insights on authentication and fraud prevention

Back to Knowledge & Insights

From Passwords to Passkeys: Meeting Banking Regulations with FIDO Authentication - Part II

FIDO
PSD2
SPC
WebAuth
Passkeys

As mentioned in my previous article here, there are some challenges with deploying FIDO in a PSD2-compliant fashion, including:

  • Synchronisation of device keys between devices through cloud accounts, breaking non-replication of the possession-element required by PSD2.
  • User sharing the Passkey with somebody through Apple Airdrop, also breaking the non-replication of the possession element required by PSD2
  • No dynamic linking of the amount and the beneficiary account, requiring additional solutions for auditable authentication code creation to demonstrate compliance with PSD2

I also mentioned that SPC is one of the emerging standards that are aiming to solve the PSD2 compliance of FIDO Passkeys. However, FIDO and WebAuthn standards are evolving to try to solve this problem too.

The current WebAuthn standard is Level 2 that was adopted in 2021 ​[1]​. The latest draft version of WebAuthn Level 3 was published May 2026 ​[3]​, and is on track to become the adopted standard at some point in the future.

New Functionality in WebAuthn Level 3

WebAuthn Level 3 is providing the ability for relying parties to be informed and take policy decisions based on the possible for the key to participate in:

  • backup
  • peer-to-peer sync,
  • cloud sync,
  • local network sync,
  • manual import/export,
  • etc.

The relying party has the possibility to detect the following possible states for the key ​[2]​:

  • the key cannot be backed up, synced or exported
  • the key can be backed up, synced or exported in the future, but it is not currently backed up, synced or exported
  • the key is currently backed up, synced or exported.

This enables relying parties to use WebAuthn Level 3 to have a better understanding of the risk or replication of the possession element when using FIDO for PSD2 authentication.

Benefits and Drawbacks

Using WebAuthn Level 3 is a step forward to enable PSD2 compliance of FIDO Passkeys. However, there are several things to keep in mind:

  • The standard is currently not implemented by all the popular platforms, so banks would still need to have a fallback solution for clients who only support WebAuthn Level 2.
  • There doesn't seem to be a way to block a key from being backed up, synchronised, or exported, only to detect that it might happen in the future, or that it has already happened.
  • The standard specifies that if the client is unsure of the status of the key or it was backed up, synced or exported in the past, but it is no longer be the case, then the client should act as if the key was not backed up, synced or exported. This creates a compliance risk for cases where the status of the key is uncertain to the client. A safer alternative would have been for the client to assume that the key has been synced or exported if the status is unclear.

Therefore, banks still have to carefully manage their compliance approach even with WebAuthn Level 3, by keeping the above limitations in mind.

Conclusion

Banks implementing WebAuthn Level 3 needs to also implement auditable assurance of key attributes over time. They also need to implement compensating controls to assure non-replication of FIDO Passkeys, when it is indicated that the key might be backed up, synced or exported in the future. This should be handled in a flexible orchestration and policy engine to make sure that policy changes can be done quickly and effortlessly when standards and platform approaches are updated again.

This provides some improvement in the compliance of FIDO Passkeys as a PSD2 possession element, but it does not address the need for dynamic linking of payment details during the authentication. Therefore, banks also need to have an auditable and compliant approach to generate PSD2 authentication codes for dynamic linking in addition to the FIDO Passkey signature.

Callsign provides a comprehensive authentication, fraud and orchestration platform, which helps banks be PSD2 and PSD3/PSR compliant, when implementing FIDO Passkeys for the users ​[3]​. It also inlcudes an orchestration engine that enables policy and user journey changes within minutes, cutting lead-times and improving agility in a changing authentication and compliance landscape.

References

[1]

World Wide Web Consortium (W3C), “Web Authentication: An API for accessing Public Key Credentials Level 2,” April 2021. [Online]. Available: https://www.w3.org/TR/webauthn...;

​[2]

​World Wide Web Consortium (W3C), “Web Authentication: An API for accessing Public Key Credentials Level 3,” May 2026. [Online]. Available: https://www.w3.org/TR/2026/CR-...;

​[3]

​Callsign, “PSD2 cheatsheet,” April 2026. [Online]. Available: https://www.callsign.com/knowl...;



​​​

​​​

Start you FIDO journey now, take the next step by speaking to one of our experts to get input and inspiration for your authentication strategy.

By submitting this form, you agree to Callsign’s Privacy Policy

Success

Error

Thank you