# FIDO2 for DORA Compliance: Strong Authentication for Financial Entities > DORA holds EU financial entities to strict ICT risk-management and access-control standards. How FIDO2 and passkeys support DORA's identity, privileged-access and resilience requirements, and where to start. Source: https://playciso.com/blog/fido2-dora-compliance · Published: 2026-09-26 · Publisher: PlayCISO (https://playciso.com) --- DORA — the EU Digital Operational Resilience Act — is the financial sector's counterpart to NIS2, and it is now the baseline for banks, insurers, investment firms and the critical ICT third parties that serve them. It never says "FIDO2." What it does require is robust ICT risk management, strong authentication, least-privilege control of privileged accounts, and demonstrable operational resilience. Phishing-resistant FIDO2/WebAuthn authentication supports all four, which is why it shows up in so many DORA readiness plans. ## The DORA angle: strong authentication plus resilience Two DORA themes pull toward FIDO2. First, strong authentication and identity/access management: DORA expects financial entities to prevent unauthorised access to ICT systems, and origin-bound FIDO2 credentials defeat the phishing and adversary-in-the-middle attacks that OTP and push MFA do not. Second, operational resilience: DORA is fundamentally about staying operational under stress, and an authentication programme where every user holds two or more authenticators is inherently more resilient to lockout and device loss than a single-factor or single-device scheme. ## Mapping FIDO2 to DORA - Strong authentication: FIDO2 is phishing-resistant by construction — the strongest, most defensible answer to "how do you authenticate access to critical financial systems?" - Privileged access: device-bound hardware keys for operators of core banking, trading and payment infrastructure prevent silent credential theft off endpoints. - Third-party risk: DORA extends to critical ICT third parties — requiring FIDO2 for their access to your systems is an auditable third-party control. - Resilience: multiple registered authenticators per user reduce lockout risk and support continuity expectations. ## A DORA-aligned rollout order - Privileged financial-system access. Hardware security keys for admins and operators of core banking, payments and trading platforms. - Remote and third-party access. Enforce FIDO2 at the identity provider for anything reachable externally, including vendor portals. - General workforce passkeys. Synced passkeys for primary IdP sign-in across staff. - Resilience and cleanup. Two authenticators per user; remove SMS/OTP fallback on hardened accounts. ## Evidence to keep DORA is evidence-driven. Keep FIDO2 coverage figures for privileged, third-party and general populations; a register of accounts that still permit a phishable fallback; and the two-authenticator coverage rate. Those map directly to the access-control and resilience questions an examiner will ask. See the broader [FIDO2 & passkeys options assessment](/blog/fido2-passkeys-benefits-options-assessment) and the [FIDO2-for-NIS2 guide](/blog/fido2-nis2-compliance); assess your identity exposure with the free [Identity Risk tool →](/tools/identity-risk) ## Frequently asked questions **Does DORA require FIDO2?** No — DORA is technology-neutral. It requires strong authentication and robust IAM; FIDO2/WebAuthn is a leading phishing-resistant way to meet that. **Why does FIDO2 fit DORA?** It provides phishing-resistant access, device-bound keys for privileged operators, and lockout resilience when users hold multiple authenticators. **Does DORA cover ICT third parties?** Yes — requiring FIDO2 for third-party access to your systems is a concrete DORA-aligned control. **Where do we start?** Privileged access to core financial systems with hardware keys, then remote/third-party access, then workforce passkeys.