Skip to content
Technical Guides

Cyber Essentials v3.3 and passwordless authentication: what the scheme allows

Passwordless sign-in with FIDO2, Windows Hello, and mobile credentials is rising fast. This article explains how v3.3 treats passwordless authentication and what to declare in the self-assessment.

A glowing fingerprint on a dark circular scan

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

8 min read

Share

Section 01

Cyber Essentials v3.3 and passwordless authentication: what the scheme allows

Passwordless sign-in - FIDO2 security keys, Windows Hello biometrics, passkeys on phones - is rapidly becoming the default for UK enterprise. v3.3 does not prohibit passwordless; it defines what passwordless configurations pass the MFA requirement.

This article clarifies which passwordless setups are acceptable under CE v3.3 and which require additional compensating controls.

Section 02

The scheme's test

MFA under v3.3 requires two independent factors. Traditional MFA is "password + something else". Passwordless combines two factors into one action - typically possession (key/device) + biometric (face/fingerprint) or possession + PIN.

Verify the actual service authentication and its independent factors. A device biometric or one-time code alone does not automatically establish MFA. The NCSC requirements, pages 20-22, recognise FIDO2 passkeys with user verification; product names and sample answers alone do not prove the resulting implementation.

Section 03

FIDO2 security keys

A FIDO2 security key (YubiKey, SoloKey, Titan) requires:

  • Possession of the key (factor 1).
  • PIN or biometric to unlock the key (factor 2).

This passes CE v3.3 MFA. We recommend phishing-resistant FIDO2 for privileged access as hardening; the scheme does not mandate a preferred administrator factor.

Section 04

Windows Hello for Business

Windows Hello for Business uses a device-bound public-key credential or certificate. It is not universally a FIDO2 credential; check the deployment and authentication path. Sign-in requires:

  • Possession of the device (factor 1).
  • Biometric or PIN (factor 2).

This passes v3.3 MFA when deployed correctly:

  • Verify the actual Windows Hello for Business authentication model. Consumer Windows Hello can also provide user verification when unlocking a supported passkey; its name alone does not determine the result.
  • Deployed via Intune or Group Policy with TPM-bound credentials.
  • Apply the appropriate credential controls. The six-character device-only unlock rule is valid, but is not a universal minimum for every MFA factor or Windows Hello authentication flow.

Assessors sometimes ask for a screenshot of the Intune Windows Hello for Business policy to verify it is the Business variant (not consumer Windows Hello).

Section 05

Passkeys

Passkeys can be device-bound (including hardware security keys) or synchronised through a supported credential provider. They are not all synchronised through Apple or Google.

Verify possession and user verification in the sign-in flow, provider recovery and protection of synchronised credentials. Describe the actual credential store and recovery path rather than assuming every passkey needs an iCloud or Google account. See Microsoft's Windows Hello FAQ for platform distinctions.

Section 06

Face ID / Touch ID on mobile banking apps

Some line-of-business mobile apps authenticate with device biometrics. Determine whether the biometric unlocks an authenticated credential and whether the app actually establishes the required independent factors. MDM and remote wipe can strengthen device management but are not universal scheme prerequisites for MFA.

Section 07

What does not pass

  • "We use biometric login" without clarifying what the underlying factor is. Assessor will ask - biometric alone is not a second factor if the first factor is also biometric.
  • A Windows Hello label alone. A local unlock and a service passkey flow are different; verify the credential and factors rather than categorically classifying consumer Hello as single-factor.
  • Face unlock alone without establishing how the cloud service authenticates. MDM absence alone is not an MFA failure.

Section 08

What to declare in the self-assessment

When the self-assessment asks about MFA, state clearly:

  • Which users use passwordless.
  • Which technology (FIDO2, Windows Hello for Business, passkey).
  • How the device is registered (Intune, Jamf, manual).
  • How the backup factor works if the primary device is lost (recovery key, fallback MFA).

A clean answer:

> "All 42 corporate Windows 11 laptops are Intune-enrolled with Windows Hello for Business. Users sign in via biometric to an Entra ID passwordless credential bound to the device TPM. Administrators use FIDO2 hardware keys (YubiKey 5C NFC) as the primary factor and Microsoft Authenticator number-matching push as fallback. Mobile users authenticate via passkeys stored in Entra ID, protected by device biometric."

This is an illustrative description, not an automatic passing answer. Verify the credential technologies and resulting authentication in your actual environment.

Section 09

Service account question

Machine tokens or certificates can provide passwordless authentication for automation, but do not constitute interactive human MFA. Manage those identities separately from user sign-in. Document each service account separately:

  • Purpose.
  • Scope.
  • Rotation policy.
  • Monitoring.

Section 10

Bottom line

v3.3 allows passwordless. Configure it correctly - Windows Hello for Business, FIDO2, passkey with protected sync - and declare it clearly in the self-assessment. Passwordless can be stronger than traditional password + MFA and is increasingly the correct choice for UK SMBs and MSPs.

Start Cyber Essentials | MFA pillar | See pricing

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group