Consumer-facing digital services are under increasing pressure to improve security while reducing friction. Passwords no longer meet these demands, accelerating the adoption of passwordless authentication based on passkeys, biometrics, and adaptive risk. Based on the latest KuppingerCole research and market analysis, this webinar examines how modern passwordless approaches are reshaping consumer identity and access management. It explores how passkeys work, how they integrate into CIAM architectures, and which architectural, UX, and regulatory considerations organizations must address to deploy passwordless authentication securely and at scale.
Alejandro Leal, Senior Analyst at KuppingerCole Analysts has been covering the passwordless authentication market for more than five years, analyzing vendors, standards, and real-world deployments across consumer and enterprise use cases. In this session, he brings a research-driven, vendor-neutral perspective grounded in KuppingerCole’s latest market analysis, translating technical developments around passkeys, biometrics, and CIAM into practical insights for decision-makers and practitioners.
Hello everyone and welcome to the webinar Passwordless Authentication B2C. My name is Alejandro Leal. I'm a Senior Analyst at KuppingerCole and today we'll be discussing some of the latest insights on this topic and most of the content here is based on the Leadership Compass that we published in January together with my colleague Mike Small. So now let me share with you the slides. So before we begin I'd like to just remind you guys of the instructions as always. You guys are not, you're muted centrally so there's no need to mute or unmute yourself.
We'll be conducting two poll questions and you can also have, so we're not going to have a Q&A session at the end but if you have any question during my slides just feel free to type on the control panel and if I'm not too focused on what I'm saying then I will address those questions. If not, towards the end of my slides I will look at the questions and then we can address those as well. And we'll be recording the webinar so in the coming days you will see it on our website together with the slides.
Okay so the agenda for today, I'll just give a brief intro to the topic then we'll be discussing the DLC, the results and the market analysis. So just to set the stage a little bit, the Leadership Compass had 28 vendors participating. It was published in January and the LC password list for enterprises was just published, if I'm not mistaken it was last week or this week. So you can also take a look at those results and we will be having a separate webinar on that LC in the coming weeks. So let's start with something very simple and that is reality.
If you look at this slide, these are not isolated incidents. These are headlines from the past few months and you can go back in time, any year, any time and you will see something like this. And the patterns are the same, password reset emails trigger panic, massive credential leaks exposing millions and sometimes billions of accounts, critical infrastructure is compromised through a single password and even silly passwords like solarwinds123 can lead to systemic breaches. And what's most telling is that entire businesses can also be brought down by something as basic as one weak credential.
As analysts we've been talking about the weaknesses of passwords for years but what's changed is the scale and frequency. Passwords are no longer just a usability problem, they're not just annoying or inconvenient, they are now a structural security liability. And most importantly this is not just an enterprise issue. In the consumer space the impact is even more severe. We see more cases of account takeover fraud, loss of customer trust, regulatory penalties and direct financial damage.
So when we talk about passwordless today we're not just talking about innovation for its own sake but we're talking about a necessary response to a model that is fundamentally broken. But I think before going into passwordless it's important to talk about the fact that if passwords are failing so visibly the next question is does passwordless look the same everywhere? And the answer is no. Both the enterprise and consumer environments are trying to solve the same underlying problem which is how to authenticate users securely without creating unnecessary friction.
But they do so under very different conditions. So if we look at the enterprise organizations usually have much more control. They can define workflows around IAM policies, managed devices, employee training and internal security protocols. That means they can that means they can take they can often ask users to tolerate a little bit more friction in exchange for stronger control and assurance. But in the consumer space that is completely different. In B2C the organization does not have control over the user's device, environment or behavior in the same way as in the enterprise.
So customers expect authentication to feel immediate, intuitive and almost invisible. And many of you in the audience you both play the same role. If you're working in a passwordless company or or your own company has already implemented passwordless or hasn't and you're still using passwords you know the pain and annoyance of that and you also know the same experience when you're trying to buy something online as a consumer. So customers want to move across mobile, web and app experiences without any disruption. Customers expect self-service, they expect privacy, they expect consistency.
So while enterprise passwordless is often about policy enforcement and admin control, consumer passwordless is really about balancing security with experience at scale. And I think that distinction matters because a solution that works well for the enterprise maybe will not automatically work well for customer-facing use cases. Of course ideally maybe if you have time later and you want to look at the leadership compass for enterprises then you can compare the two reports and see which vendors score well in both reports and which vendors have a solution that can address both use cases.
But in B2C success depends not just on security strength but on whether the user journey remains simple enough that people actually adopt it. And I think that is why this market deserves to be looked at on its own terms. So this distinction I think is important. So I have the first poll question which is what is the primary driver for your interest in passwordless? And last year or more like a year and a half ago we had the same question and these were the results. So I'd be curious to know if you still share the same opinion on this question.
So it was not surprising to see that in B2C the user experience perhaps was pointed out as more important. At that time the primary driver was user experience followed by security. What's interesting is not just the result itself but the timing. Given how quickly this space is evolving especially when we see the adoption of fast the adoption of fast keys, new regulation and increasing fraud it would be very interesting to see how these results might look today. So please I would be happy if you could answer this poll. Maybe you don't have to answer the other one but this one would be nice.
Anyway so building on that why are we seeing such a strong momentum towards passwordless especially in consumer environments? I think there are three forces converging. First is friction. So traditional usernames and passwords create constant disruption in the user journey. Forgotten passwords, failed logins, wizard flows. These are not just inconveniences but they also directly impact conversion rates, customer satisfaction and ultimately revenue. Secondly security. Passwords are not secure. They're vulnerable.
Phishing, credential stuffing and reuse of passwords across services have made account takeover one of the most common and costly threats in B2C environments. And it's important to remember that attackers are not breaking into systems. They are logging in and that's a fundamental shift into how we need to look at this problem. And third the alternative is now viable with passwordless.
Fast keys, device bound credentials, biometrics. We finally have the components and the methods that are both secure and easier to use. They are phishing resistant by design and are increasingly supported across major platforms. So this is not just about replacing passwords. It's about moving to a model where security and user experience are no longer in conflict but they can actually reinforce each other. And that is why passwordless is no longer experimental. It is becoming the default direction for modern digital identity.
So keeping our goal we believe that passwordless will continue to gain momentum, will continue to be adopted but passwords are not going anywhere. It's going to take a lot of time for that to happen and I think that's something that many of the vendors realized because for example I published the first leadership compass on leadership compass on passwordless back in 2022. So almost four years ago and back then there were a lot of vendors that branded themselves as passwordless and that was all over their marketing all over the slides when I had briefings with them.
And later on last year or this year when I talked to some of those same vendors they have a completely different direction. I mean they're still of course addressing passwordless but they have a different approach to that because many of them realized that for most organizations overcoming legacy systems is a challenge. So how can organizations get there? Because again the reality is most environments are not starting from scratch. They are dealing with legacy systems, legacy applications and existing user bases. So that means that passwordless is not a switch you just flip.
It's a migration and in most cases a phased one. So first organizations need to in a way bridge the gap. That often means running hybrid models where passwordless methods are introduced slowly alongside existing credentials. So passwords may still exist in the background even if they're no longer the primary user experience and that's why it's very important when you talk to a potential passwordless vendor you need to understand the way they can approach this hybrid scenario. Second there is a need to align with modern standards.
So protocols like 502 and web apps are becoming foundational not just for security but also for interoperability across devices and platforms and this was one of the challenges that those passwordless vendors realized later on. Interoperability is key. Third identity becomes more centralized and orchestrated. So instead of isolated authentication mechanisms, organizations move toward platforms that can manage policies with signals and user journeys in a consistent way. So the key takeaway here is passwordless is not just a technology shift.
It's an architectural transition and it's one that requires careful integration with what already exists while progressively moving toward a more modern identity model. Here are just some other challenges, obstacles in passwordless adoption. So while the direction is clear, the journey is not without these challenges. So first also many organizations don't know where to start. They struggle to align business and IT priorities. As we already discussed, legacy integration remains a major barrier and scalability, especially on-prem, can be limiting.
We also still see cultural resistance, what we might call the old school mentality around passwords. Many people are used to them. Many people don't really understand the problem with them. If you talk to someone outside of our industry, maybe, yeah, they will say, yeah, it's annoying to remember all these passwords, but what's the big deal? What are pass keys? How do they even work? So even some people are skeptical of the pass keys. So there's some resistance and there's some education that needs to be addressed by vendors and by people like us.
And there's also practical concerns, cost, product selection, regulatory complexity, and in some cases, the lack of strong authentication options. So adoption is not just a technical shift. It's organizational, operational, and sometimes even cultural.
Now here, I'd like to shift gears and now try to give you an idea on the evaluation criteria that we used for our leadership compass reports. So when we evaluate vendors in this space, we look beyond just whether they support passwordless. We assess a combination of capabilities that, in our opinion, are critical for real world B2C deployments. So this starts with the breadth of authentication methods, support for pass keys, biometrics, and standards like 502 and WABOT. But that alone is not enough.
We also look at adaptive risk, fraud prevention, because authentication today is not just about logging, but it's about continuously assessing trust. Equally important is orchestration. So how well solutions can manage policies, integrate signals, and adapt authentication flows dynamically? From a customer perspective, user experience is, of course, central. So that also includes the process of onboarding, self-service, and flexible UI design. And from a more technical standpoint, developer experience, APIs, and integration capabilities are key, especially in digital native environments.
And finally, areas like device lifecycle management and secure account recovery are critical. Especially the account recovery is one of the main problems we've seen in our research since the first LC in 2022. Many companies don't provide any strong account recovery mechanisms. The fallback is just username and password. So that's just a little bit strange to have, just to keep it nicely. So overall, our evaluation reflects a shift from authentication as a single event to authentication as a continuous, orchestrated, risk-aware, and user-centric journey.
So now, let's look at some key insights from the market. And then after this slide, we'll show you the LC results. So just when we look at the markets, we see a clear pattern. Vendors broadly fall into two categories. On one side, we have consumer identity and access management and broader IAM platforms that embed passwordless as part of a larger identity fabric. These platforms usually have strong integration into directories, SSO, constant management, and customer data platforms.
They're particularly attractive for organizations looking for consolidation, governance, and a unified approach to identity. But on the other side, we see specialist vendors. These providers are more narrowly focused, but often highly optimized. So they tend to innovate faster, especially in areas like behavioral biometrics, device intelligence, and advanced orchestration. In many cases, they address specific challenges, such as fraud detection or continuous authentication. So the key decision for buyers is not just about features. It's more about strategy.
Do you consolidate into one platform that provides breadth and integration? Or do you combine specialized components that offer depth and innovation in specific areas? Increasingly, organizations are taking a hybrid approach. So they're leveraging a core IAM platform, while integrating specialist capabilities where needed. And that aligns well with the concept of identity fabrics that we like to talk about at Kupinger Core.
Ultimately, the choice really depends on how passwordless fits into the broader identity architecture, and how much flexibility versus consolidation the organization is willing to manage. So that brings us now to the leadership compass for B2C password authentication. If you're familiar with our research, you will see that we have a new chart. So we recently updated our leadership compasses. What this chart shows is how vendors balance product maturity on the horizontal axis with innovation on the vertical axis. And in the top right quadrant, we see the overall leaders.
Vendors that combine strong product capabilities with a high level of innovation. And the size of the bubble depends on the market ranking. In this market, the leaders include players like Bing Identity, One Cosmos, Okta, Microsoft, and Transmit Security. These vendors typically offer a combination of 502-based authentication, adaptive risk engines, and increasingly orchestration capabilities to design end-to-end customer journeys.
But we also see strong contributions from large platform providers such as IBM and Thales, which bring scale, ecosystem integration, and global reach, particularly important for large B2C deployments. At the same time, innovation is not limited to the largest vendors. Specialists like Futuray, Beyond Identity, Hyper, and others are pushing the boundaries in areas such as device-bound credentials, continuous authentication, and behavioral analytics. So overall, this is a market where maturity and innovation coexist.
Buyers are not just choosing between vendors, they're choosing between different approaches to solving the same problem. From highly integrated platforms to more specialized innovation-driven solutions. So here we have some key findings. Long story short, passwordless adoption is accelerating across both the enterprise and the consumer space. Fast keys are gaining strong momentum, although adoption is still uneven due to ecosystem and device diversity.
We also see a shift toward multi-factor passwordless approaches combining biometrics, device trust, and contextual risk, especially in high assurance use cases. Innovation is often driven by specialist vendors, while larger platforms provide integration and scale. At the same time, behavioral biometrics and AI-driven continuous authentication are emerging as important differentiators, as well as the account recovery mechanisms that these solutions provide. And finally, deployment flexibility remains critical, particularly in regulated industries where data residency and control are key.
Especially here in Europe, there's a lot of talk about the idea of digital sovereignty, and this is an area that deserves particularly attention from the North American vendors. So overall, this is a market that is evolving quickly, but not yet fully mature. And it's my last slide. I wanted to conclude with one of the observations from this latest LC.
So to close, it's important to recognize that we're not just dealing with the end of passwords, which could take a long time to make it happen, or perhaps even in 10, 15, 20, 30 years, passwordless will be pretty mainstream, but somewhere in the dark corners of the internet, there will be someone using a password. So we're probably never going to get rid of them, but that remains to be seen. But we're also, in a way, witnessing a broader identity transition. It's a fact that passwords are declining, but they're not gone.
But new threats are emerging, especially in the context of quantum computing, which has the potential to challenge the cryptographic foundations of today's authentication methods. And this is where crypto agility becomes critical. Organizations and vendors need to be able to adapt quickly to new cryptographic standards without disrupting user experience. There are already some NIST guidelines that outline the procedure and the recommendations on how organizations can take this leap. And we have also published advisory notes on PASKIS and on the NIST recommendations.
So if you're more interested in that, feel free to reach out and I can help you find these documents. But what we see also in the LC is that many vendors are already preparing for this future. So when we looked at the questionnaires that we sent the vendors, we saw several and way more vendors than the previous report saying that they're already looking at the quantum potential scenario. So they're not only investing in passwords and authentication, but in architectures that can evolve, that can support new standards, stronger cryptography, and more resilient identity models.
So in that sense, passwordless is not the end states. It's a step toward a more flexible, future-proof approach to digital identity. One that is ready not just for today's threats, but for what is often referred to as Q day. And with that positive note, with those news that thankfully some vendors are already addressing this problem, I'd like to thank you all for your attention. And before we conclude the webinar, I'll just like to have one more poll question. So if you could take a look at that. And we can also discuss the first poll question. Here's some related research.
The PASKIS in practice one is the one I just mentioned on the NIST guidelines. And it also talks about preparing for Q day. Then the passwordless for enterprises were just published. So in the coming days, if you decide to download the slides, you can click the link and access those documents. And just a reminder for those of you who will attend EIC, we will be having several sessions on this topic. So feel free to reach out to me and I'll be happy to talk to you in Berlin. And here's just another reminder on other research services that we provide. So thank you. I hope you enjoyed the webinar.
Hope it was informative. And if you have any questions, just reach out to me.
But first, before addressing the questions, I'd like to quickly take a look at the poll results. So just to remind you, the poll question was, what is the primary driver for your interest in password authentication?
And oh, okay. So a completely different result. So 63% said improved security. 33% enhanced user experience, and just 4% cost reduction. 0% compliance. So maybe nobody cares about these guys, but it's fine. Improved security, that's very interesting. Maybe that's a reflection of how people see passwords. And the real issue of passwords is that they're not only convenient, but they're not just secure. And they can cost profit. They can cost revenue. They can be damaging for any organization.
The second poll question, which of the following best describes your organization's approach to authentication? And the options were passwordless, MFA, username, password, others. So it looks like 50% of you already have passwordless authentication.
40% MFA, including passwords, and only 5% username slash password, and another 5% others slash not sure. So that's good news. It means it's a journey. We don't expect organizations to, again, flip the switch, but to take a phased approach and get there eventually. So we have some questions. So the first question is, how do you evaluate the European identity wallet plus verifiable credentials versus PASKIs, both regarding advantages slash disadvantages of each, also in terms of adoption?
Well, that's a very, very good question. We had a webinar last week on the topic of the European identity wallet. So I suggest that you guys watch the webinar. It was very informative. We had a lot of members of the audience. I'd say that one of the issues with the wallet, which was discussed in the webinar from last week, is that there's still no clear business use cases for a lot of organizations. So member states are supposed to offer a wallet by the end of this year, probably some of them earlier next year. But there's still issues when it comes to how are people going to adopt this?
How are people going to use it? The EU is a supranational organization with different member states, and each country has a different approach on how they're addressing the wallet. So it's a very interesting project, and it remains to be seen. I think with PASKIs, it's maybe a little bit different because it's already embedded in major platforms, in Apple, Microsoft, Google. So it doesn't require too much effort, let's say.
And with the wallet, there's also lots of questions around privacy, about, you know, in Europe, if your country had some experience with authoritarianism in the past, then there's still a strange dynamic between citizens and the government when it comes to history. So how would citizens react to the wallet, even though people in the industry keep people in the industry keep educating them about privacy, etc, etc. But a lot of people that maybe are not part of the industry and people that are, you know, out there, they may not have trust. So there are some challenges when it comes to adoption.
But that's a good question. Another question is, is there more data that can be provided on the vendor comparisons?
Well, if you have access to our research, you can see the full report. We also have a chart on product leadership, innovation leadership, market leadership, and we have a dedicated chapter for each of the 28 vendors, together with a spider graph that measures the capabilities from the, well, I'm not sharing my screen anymore, but the evaluation criteria that we used to assess these vendors. So if you look at the report, then you can see how each vendor addresses each of those criteria.
The next question is, FIRO Alliance is really pushing pass keys, but interoperability is still a very real issue. And though there are some work around, they still add friction for the end user. The other issue is the TCO to implement migrate to pass keys.
Well, yeah, that's true. It's interoperability is one of the main factors that hinders adoption. And I believe there's one more question.
Typically, a user has both username, password, and pass keys. Even when the user is using mainly pass keys, the existing username slash password are weakening security, only due to the fact that they are existing. As a bad person can use it, so I have to disable or remove username, password authentication.
Well, it's similar to what I was talking about with the account recovery problem, that if a vendor has different mechanisms for account recovery, including QR codes, one-time passwords, username slash password, well, these are not very secure, especially the latter one. These are not very secure options. And in the questionnaire, we actually gave more, let's say, points to the vendors that for account recovery didn't even offer username slash password. So we tried to look for vendors that were only offering secure methods of account recovery.
So as long as the user slash password remains in the equation, the organization, the user, anyone will be in danger. Because as we keep saying, attackers don't breach systems, they log in.
Well, I think that's all from our side. Thank you very much for your time, for your questions. And please, if you have any further questions or comments, just reach out to me. Thank you very much, and I wish you all a very nice day.
See All Locations
See All Locations