SanRa
FIDO · Phishing-resistant authentication

Passkeys that
survive phishing.

A practical framework for FIDO readiness — FIDO2, WebAuthn, CTAP and passkeys mapped into policy, recovery, enterprise rollout and evidence. Educational only; not a FIDO Alliance certification.

Open the framework
Your readiness signal 0% complete

Work through the checklist. Progress stays in this browser only.

Why this exists

Passwords fail people.
FIDO fails attackers.

FIDO Alliance standards (FIDO2 / WebAuthn / CTAP) enable phishing-resistant, public-key authentication — including passkeys. This portal turns that into a workable programme: scope, authenticator policy, recovery without secret questions, IdP integration, operations and assurance evidence.

Readiness framework

Seven domains. Work them in order.

Mark each item as you build evidence. Use this as a rollout and assurance conversation — not as a certificate.

Discuss gaps with SanRa

This framework is educational. It is not legal advice, a FIDO Alliance certification, or a determination of product or programme conformity.

Standards lens

Building blocks that usually matter first

01 · WebAuthn / FIDO2

Browser and platform APIs for registration and assertion — origin-bound credentials that defeat classic phishing.

02 · CTAP

Client-to-authenticator protocol for roaming security keys and platform authenticators under user presence / verification.

03 · Passkeys

Synced or device-bound credentials with discoverable credentials, UX for sign-in, and ecosystem recovery paths.

04 · Attestation

When and how to verify authenticator make/model (AAGUID), enterprise allowlists, and privacy trade-offs.

05 · User verification

PIN, biometric or local factor on the authenticator — and when UV is required vs user presence alone.

06 · Human factors

Enrolment friction, lost-device recovery, helpdesk social engineering, and how people actually adopt passkeys.

Related frameworks

ISO/IEC 27001

Access control inside
the ISMS.

Map FIDO adoption to access control, authentication and cryptography themes in your information security management system.

Open ISO 27001 framework

ISO/IEC 42001

AI systems still need
strong identity.

Agentic and AI-augmented workflows amplify account takeover risk — phishing-resistant auth remains foundational.

Open ISO 42001 framework

WP-01

The Neuron Doctrine
of Security.

SanRa thought leadership on human factors and security in the age of AI-augmented systems.

Download whitepaper
Start a readiness conversation

Roll out FIDO without
breaking recovery.

ibrahim.mukherjee@icloud.com

Read our privacy notice.