WhatsApp Passkey Adoption Surpasses 1 Billion, Adds Stronger Two‑Step Verification
What Happened — WhatsApp announced that over one billion users now protect their accounts with passkeys, a password‑less authentication method backed by device biometrics or screen‑lock. The service also upgraded its two‑step verification from a six‑digit PIN to a full, configurable password and allows multiple passkeys per account for cross‑platform users.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a real‑world implementation of strong logical access controls (SOC 2 CC6.1) that reduce reliance on shared secrets.
- Provides audit‑ready evidence: passkey enrollment logs and password‑policy settings can be captured as continuous compliance artifacts.
- Aligns with the “Identity & Access Management” control family, helping organizations prove they enforce MFA and password complexity during SOC 2 examinations.
Who Is Affected – Consumer messaging platforms, SaaS communication tools, and any organization that integrates WhatsApp for business communications (tech‑SaaS, endpoint security, and broader digital services).
Recommended Actions – Review your own authentication policies, map passkey and enhanced two‑step verification to SOC 2 CC6.1 requirements, and begin collecting enrollment and password‑policy logs as part of your continuous‑compliance evidence set. Source: Security Affairs
Technical Notes – Passkeys rely on the FIDO2/WebAuthn standard, storing credentials on the device and protecting them with biometrics or screen‑lock. The new two‑step verification replaces a numeric PIN with a full password, increasing entropy and resistance to credential‑stuffing attacks. Source: same as above