PCI DSSBy Noor Ul Ain Ali · 31 Jul 2026 · 5 min readShare on LinkedIn

Phishing-Resistant MFA Scored 8.8/10. Traditional MFA Scored 2.0. Here Is Why.

New Cianaa research systematically reviewed 81 studies comparing FIDO2/WebAuthn against SMS, TOTP and push MFA. The security gap is roughly fourfold, and it matters for PCI DSS Requirement 8.5.1.

Most organisations treat multi-factor authentication as a solved problem. The box is ticked, MFA is switched on, and attention moves elsewhere. The uncomfortable finding from our new research is that the form of MFA you chose matters far more than the fact that you have it, and the gap between the options is not marginal. It is roughly fourfold.

Our systematic review, published open access with a DOI, examined 81 peer-reviewed academic papers and industry reports comparing FIDO2/WebAuthn cryptographic authentication against the traditional methods most organisations actually run: SMS one-time codes, authenticator app codes (TOTP), push notifications and email verification codes. We scored each across ten attack vectors and six security dimensions.

The headline numbers

The results were not close.

  • FIDO2/WebAuthn scored 8.8 out of 10 for overall security effectiveness.
  • Traditional MFA methods scored between 2.0 and 3.8 out of 10.
  • FIDO2/WebAuthn resisted roughly 90% of phishing attacks, against 20 to 30% for conventional approaches.

Put plainly, phishing-resistant authentication offered around four times the protection of the MFA most organisations currently rely on, while remaining usable enough for enterprise deployment. That last point matters, because the usual objection to stronger authentication is friction, and the evidence did not support treating that as a blocking trade-off.

Why traditional MFA keeps failing

The reason for the gap is structural, not a matter of implementation quality. SMS codes, TOTP codes and push approvals all share one fatal characteristic: they can be relayed by a human being who has been deceived.

If an attacker builds a convincing fake login page, the victim enters their password and then obligingly types in the six-digit code as well. The attacker relays both to the real site in real time. The second factor was present, it worked exactly as designed, and it protected nothing, because the user handed it over. Push notifications fail a related way: an attacker who has the password simply sends approval prompts until a tired or distracted user taps accept.

This is why the arrival of AI-generated phishing makes the choice urgent. As we discussed in our analysis of AI-enabled phishing, the tells that awareness training taught people to spot are gone. When the deception becomes indistinguishable from the real thing, controls that depend on the user not being fooled stop being controls.

What FIDO2 does differently

FIDO2/WebAuthn changes the shape of the problem rather than strengthening the same weak link. Authentication is performed by a cryptographic key pair, and the key is bound to the legitimate website’s domain. The private key never leaves the user’s device and is never transmitted, so there is nothing for the user to read out, retype or forward.

The consequence is that a phishing site simply cannot complete the ceremony. If the domain does not match, the credential will not respond. The protection does not depend on the user noticing anything is wrong, which is precisely why it holds up when the user is completely deceived.

What this means for compliance, not just security

The standards are moving in the same direction the evidence points. PCI DSS v4.0.1 now requires, under Requirement 8.5.1, that MFA systems resist replay attacks and cannot be bypassed, alongside the Requirement 8.4.2 obligation to apply MFA to all access into the cardholder data environment. Those are exactly the properties that separate cryptographic authentication from code-based methods.

An organisation running SMS codes today may still satisfy the letter of the requirement, but it is operating at the weakest end of what the standard permits, and the research suggests that end is considerably weaker than most decision-makers assume. For anyone planning an MFA rollout or refresh, the practical implication is to skip the intermediate step: deploying TOTP now and migrating to passkeys in two years means paying for two projects and carrying the weaker control in the meantime.

A realistic path forward

Adopting phishing-resistant authentication does not have to be an all-or-nothing programme. The sensible sequence is to start where compromise hurts most: administrators, privileged accounts and anyone with access to sensitive environments. Extend to all users of critical systems next, and keep a fallback method during transition, while making sure that fallback cannot quietly become the bypass that undoes the control.

The wider lesson from the review is that authentication has quietly become a decision with a measurable security consequence. Having MFA is no longer the meaningful question. Which MFA, and whether it survives a user being deceived, is.

Frequently asked questions

Is FIDO2/WebAuthn really more secure than authenticator app codes?

Substantially, yes. Our systematic review of 81 sources scored FIDO2/WebAuthn at 8.8 out of 10 for security effectiveness against 2.0 to 3.8 for traditional methods including TOTP, with around 90% phishing resistance compared to 20 to 30%. The difference comes from FIDO2 binding credentials to the legitimate domain, so a phishing site cannot complete authentication even if the user is fully deceived.

Why is SMS-based MFA considered weak?

SMS codes can be relayed. A user who has been phished will enter their password and then the code into a fake page, which the attacker passes to the real site in real time. SMS is also exposed to SIM-swap and interception attacks. It is better than a password alone, but it sits at the weakest end of the MFA options.

Does PCI DSS require phishing-resistant MFA?

PCI DSS v4.0.1 Requirement 8.5.1 requires MFA systems to resist replay attacks and to be resistant to bypass, and Requirement 8.4.2 extends MFA to all access into the cardholder data environment. It does not mandate FIDO2 by name, but cryptographic authentication is the approach that most cleanly satisfies those properties.

Is FIDO2 too difficult for everyday users?

Our analysis of the security and usability trade-off found FIDO2/WebAuthn maintained acceptable usability while delivering roughly four times the protection. Passkeys on phones and laptops have made enrolment and daily use considerably simpler than the hardware-key-only era, which is why the evidence no longer supports treating usability as a reason to stay with codes.

Read the full research

The complete systematic review, including the attack-vector scoring and enterprise deployment recommendations, is published open access and free to cite: Comparative Security Analysis of FIDO2/WebAuthn versus Traditional Multi-Factor Authentication (DOI 10.5281/zenodo.21715492).

Cianaa assesses authentication controls against PCI DSS and ISO standards across New Zealand and Australia. If you are planning an MFA rollout or want your current implementation tested against Requirement 8.5.1, talk to our assessors or browse our open-access research.

PCI DSS assurance

Talk to Cianaa Technologies

Talk to our QSA team about scoping, gap remediation, and Report on Compliance under PCI DSS 4.0.1.

Book a discovery call
Enjoyed this article?

Get the next one in your inbox

One email when we publish. Written by named auditors, never by a marketing robot. Unsubscribe anytime with one click.

Double opt-in. No spam, no list-selling, covered by our privacy policy.

Similar Posts