"Cyber criminals often look for the easiest route to access important accounts, which means login details remain a common target," said Jonathon Ellison, director for national resilience at the UK's National Cyber Security Centre (NCSC).
GOV.UK One Login expands passkeys to 23 million users
The UK government is giving more than 23 million people the chance to ditch passwords for passkeys as part of a wider rollout across GOV.UK One Login. The expansion follows a trial involving more than 300,000 users and aims to simplify access to a range of public services while strengthening authentication. GOV.UK One Login is intended to provide a single account for accessing government services rather than requiring users to navigate a collection of separate sign-in systems.
One Login already underpins sign-ins for checking State Pension details, managing tax services, and accessing childcare support — among other government functions — and the broader passkey rollout will reach the service’s existing user base of roughly 23 million people.
How passkeys work: fingerprints, Face ID, device PIN and cryptographic credentials
Passkeys let people sign in using a fingerprint, Face ID, or a device PIN instead of entering a password and waiting for a two-factor authentication (2FA) code. The government describes passkeys as using cryptographic credentials that are tied to the website or app for which they were created; the biometric data or PIN used to unlock a passkey remains on the user's device and "isn't seen or stored by GOV.UK One Login."
That design is presented as a deliberate contrast to passwords, which the government says can be stolen, reused, or handed over to convincing fake login pages. Because passkeys rely on credentials bound to a specific site or app, the government and the NCSC argue they are "highly phishing-resistant," reducing the value of credential-based attacks aimed at government accounts.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleEarly results: adoption, speed claims and optionality
The government reports that nearly one in ten daily One Login sign-ins are already being made using passkeys. Officials claim passkey sign-ins are up to eight times faster than logging in with a username, password and 2FA code. Despite those figures, the rollout is not mandatory: passkeys remain optional and "passwords aren't disappearing just yet," allowing users who prefer the old method to continue signing in the traditional way.
The reported speed and uptake reflect a combination of the user experience offered by device-level authentication (biometrics or PIN) and the gradual migration of users from password-plus-SMS 2FA to passkeys.
Savings for Whitehall and public nudges from the NCSC and the Digital Government Minister
There is a financial motive alongside the security case. The government says the switch to passkeys is already saving taxpayers nearly £600 a day in SMS costs. Officials noted that every authentication text adds to the government's phone bill, and the reduction in SMS usage is a measurable near-term dividend of the rollout.
Digital Government Minister Stephanie Peacock framed the effort as both a convenience and a fraud-reduction measure: "Nobody enjoys hunting for a forgotten password or waiting for a text message code just to check their tax return or renew a document," she said. The NCSC has been encouraging users to switch to passkeys, echoing the director for national resilience’s emphasis on passkeys as a way to frustrate attackers and save the public time.
What this means for One Login users, Whitehall and the NCSC
- One Login users: More than 23 million account holders are being offered a new, optional authentication method that promises faster sign‑ins and removes reliance on SMS 2FA; biometric data or device PINs remain on the user’s device and are not stored by One Login.
- Whitehall (government finance teams): The rollout already reports nearly £600 a day in SMS savings, a concrete line-item reduction in authentication costs that can be tracked as passkey uptake increases.
- National Cyber Security Centre (NCSC): The NCSC is promoting passkeys as a "highly phishing-resistant alternative" to passwords and is actively encouraging the public to adopt them to reduce account-takeover risk.
Passkeys for GOV.UK One Login represent a coordinated push to move tens of millions of public-service accounts away from password-and-SMS models toward device-based cryptographic authentication. The government can point to early adoption — almost 10 percent of daily sign-ins — and immediate SMS savings as proof points; users, meanwhile, retain the choice to keep using passwords for now. Whether the combination of convenience, cost savings and the NCSC’s security messaging will persuade the remaining majority of One Login users to switch is the question that will determine how quickly SMS costs and password-based risk decline.




