August 18, 2026 • by HID Global John Harbridge

Law enforcement agencies are increasingly targeted by credential theft, phishing and ransomware attacks. While the FBI’s Criminal Justice Information Services (CJIS) Security Policy requires multi-factor authentication (MFA) for access to Criminal Justice Information (CJI), many traditional MFA methods remain vulnerable to phishing, stolen one-time codes, push fatigue and session hijacking.

What is FIDO2?
FIDO2 is an open authentication standard designed to provide phishing-resistant authentication using cryptographic credentials rather than passwords, one-time passcodes or shared secrets. Organizations can deploy FIDO2 with security keys, smart cards, passkeys and other authenticators to strengthen identity security and improve the user experience.

The problem is clear: having MFA is no longer the same as being protected. SMS codes, authenticator apps, push notifications and one-time passcodes are better than passwords alone. However, they still rely on users to make the right decisions in the face of increasingly sophisticated attacks.

According to a 2026 FIDO Alliance and HID study, 70% of organizations experienced at least one identity-related security incident in the previous 24 months, including credential-based breaches, phishing attacks that bypassed MFA and failures to revoke access when employees left the organization. The risk is particularly acute in the public sector — those organizations reported the highest rate of identity-related security events of any industry, as well as the highest rate of manual credential revocation processes. As a result, law enforcement agencies are exploring phishing-resistant authentication approaches.

Organizations that view identity protection as a strategic investment rather than a compliance exercise will be better positioned to protect sensitive data while improving the user experience for officers, investigators, dispatchers and support personnel.

CJIS Compliance Is Driving Authentication Modernization

The CJIS Security Policy establishes the minimum security requirements for organizations that access, process or store CJI. In addition, recent policy updates reinforced MFA requirements for both privileged and non-privileged access to CJIS-connected resources. The objective is straightforward: reduce the risk that stolen credentials can be used to gain unauthorized access to sensitive criminal justice systems.

For many agencies, the initial response was to deploy traditional MFA technologies such as:

  • SMS codes
  • Authenticator applications
  • Push notifications
  • One-time passcodes

While these methods are significantly better than passwords alone, they remain vulnerable to modern phishing attacks, adversary-in-the-middle attacks, and social engineering techniques. In the FIDO Alliance Identity Report, nearly one-third (32%) of organizations reported a phishing or social engineering attack that bypassed their existing MFA solution. And despite 94% of organizations expressing confidence that they could revoke all access within 24 hours of employee separation, 35% reported failing to do so during the previous two years.

This reality is prompting many CJIS-regulated organizations to evaluate stronger authentication approaches.

Why FIDO2 Matters for Law Enforcement

For law enforcement agencies, the value of FIDO2 extends beyond compliance. Agencies must provide secure access to Criminal Justice Information (CJI) across headquarters, substations, patrol vehicles, detention facilities and remote environments, while defending against increasingly sophisticated credential theft and phishing attacks.

By replacing shared secrets such as passwords with cryptographic credentials, FIDO2 helps reduce the risk of credential compromise while supporting a streamlined authentication experience for officers, dispatchers, investigators and support personnel. Authentication can be performed with a simple tap, biometric gesture or PIN using:

Unlike traditional password-based authentication, the private cryptographic key remains on the user’s device and is never transmitted during authentication. Instead, the device signs the application’s challenge, helping to make credential theft significantly more difficult.

Most importantly, FIDO2 is designed to provide phishing-resistant authentication. Because credentials are cryptographically bound to a legitimate website or application, users cannot unknowingly present valid credentials to a fraudulent site.

Law enforcement agencies must also support access across a growing ecosystem of records management systems, computer-aided dispatch (CAD) platforms, mobile data terminals, evidence management systems and cloud services. FIDO2 provides a standards-based approach that can help agencies strengthen authentication, reduce user friction and support long-term identity modernization efforts.

Why FIDO2 Strengthens the Security Conversation

Regardless of where an agency lands on the FIPS discussion, there is growing consensus on one issue:

Phishing-resistant authentication provides significantly stronger protection than traditional MFA methods.

This is where FIDO2 has become especially relevant.

Traditional MFA approaches may satisfy baseline compliance requirements, but many remain vulnerable to credential theft, MFA fatigue attacks and sophisticated phishing campaigns. FIDO2 addresses these risks through cryptographic authentication that cannot be replayed or easily intercepted.

Organizations increasingly recognize this advantage. In the FIDO Alliance/HID study, the leading reason cited for adopting passwordless, phishing-resistant authentication was to reduce the risk of phishing and credential-based breaches (45% of respondents).

Additionally, 44% of organizations identified reducing password reset and help desk costs as a primary driver for moving to passwordless authentication. These findings reflect a broader shift toward authentication strategies that improve both security outcomes and operational efficiency.

For agencies seeking to move beyond compliance and improve their overall cybersecurity posture, FIDO2 offers a practical path toward higher-assurance authentication.

Why Traditional Authentication Falls Short for CJIS Requirements

It is important to recognize that CJIS does not specifically mandate FIDO2. The policy requires multi-factor authentication and appropriate protection for criminal justice information.

However, FIDO2 provides an effective way to satisfy those requirements while adding capabilities that many traditional MFA technologies lack, including phishing resistance, improved usability and strong cryptographic security.

For agencies planning future identity investments, FIDO2 represents a transition from:

Password + MFA → Passwordless, Phishing-Resistant Authentication

This evolution enhances both security and user experience.

FIDO2 helps address several common challenges:

1. Phishing Attacks

Most credential theft attacks depend on users revealing passwords or MFA codes. FIDO2 removes shared secrets from the authentication process, effectively preventing users from being tricked into using their credentials on phishing sites.

2. Balancing Security, Compliance and User Experience

Officers and dispatchers require immediate access to information and, therefore, need authentication methods that enhance security while reducing user friction and operational burden. Biometric gestures, ID badge taps or passkey authentication are often faster than entering passwords and verification codes.

This balance is particularly important in mission-critical environments where rapid access to information can directly affect operations.

3. Costly Rip-And-Replace Projects

One common misconception about adopting phishing-resistant authentication is that organizations must replace their existing credentials and infrastructure. In reality, many public-sector organizations can begin by building on investments they have already made.

For example, employee ID badges used for physical access can often be extended to support secure digital access as well. This approach allows agencies to improve cybersecurity while minimizing disruption, reducing deployment costs and simplifying the user experience through a single credential for both physical and logical access.

4. Alignment With Zero Trust

Many public sector organizations are adopting Zero Trust architectures that emphasize strong identity assurance and continuous verification. FIDO2 aligns naturally with these principles through cryptographic authentication and phishing resistance.

As agencies evaluate FIDO2 solutions, an important question frequently arises:

Does CJIS require FIPS 140-3-validated credentials?

The answer is more nuanced than many organizations initially expected.

CJIS requires “Advanced Authentication” for access to CJI and references NIST SP 800-63B  as the technical framework for implementing those controls. Because NIST SP 800-63B establishes Authentication Assurance Levels (AALs), many security teams and auditors interpret CJIS requirements as aligning closely with AAL2 authentication practices.

This has led some organizations to conclude that authenticators used for CJIS access should leverage FIPS 140 validated cryptographic modules, particularly when hardware security keys, smart cards or other cryptographic authenticators are deployed.

However, CJIS does not explicitly state that all authenticators used by CJIS-covered organizations must be FIPS 140 validated. The debate often centers on how broadly NIST requirements should be applied beyond federal agencies and how auditors interpret the relationship between CJIS and SP 800-63B.

As a result, agencies across the country have reached different conclusions.

Some organizations have adopted FIPS-validated credentials as part of their CJIS strategy because:

  • Internal security teams interpret CJIS alignment with NIST SP 800-63B as supporting FIPS validation
  • Auditors have recommended or required FIPS-validated credentials during compliance reviews
  • Agencies want to align with federal cybersecurity practices
  • Security leaders want to future-proof identity investments as standards continue to evolve

As agencies evaluate authentication technologies, it is also important to recognize that FIPS-validated options are increasingly available within the FIDO ecosystem. For example, HID’s Crescendo 4000 Dual-Interface Card and Crescendo Key recentlyachieved FIPS 140-3 Level 2 validation. For organizations whose procurement policies, auditor recommendations or long-term security strategies favor FIPS-validated credentials, solutions such as HID Crescendo can provide a path to combining phishing-resistant FIDO authentication with validated cryptographic assurance.

At the same time, other organizations have successfully implemented CJIS-compliant MFA strategies using authentication approaches that are not built around FIPS-validated authenticators.

The key takeaway is that FIPS validation is often an important consideration in procurement, audit or risk management. Still, agencies should evaluate requirements based on their own compliance obligations, auditor guidance, legal interpretations and risk tolerance.

Key Questions for Technology Leaders

As law enforcement organizations evaluate authentication modernization initiatives, several questions are worth considering:

  • Is our current MFA solution resistant to phishing attacks?
  • What devices are already in place today (e.g., ID badges)?
  • How much time and money are spent managing passwords and account recovery?
  • How can we improve security while reducing operational friction for officers and staff?
  • What guidance have our auditors provided regarding authentication technologies and credential assurance?
  • Do we have requirements for FIPS-validated authenticators today, or anticipate needing them in the future?
  • How does our identity strategy align with broader Zero Trust initiatives?
  • What is our roadmap toward passwordless authentication?

These discussions increasingly differentiate organizations focused on basic compliance from those building long-term cyber resilience.

Looking Ahead

CJIS compliance remains the baseline. The greater opportunity is building an identity security strategy capable of defending against today’s threat landscape and tomorrow’s emerging risks.

While organizations may continue to debate the relationship between CJIS, NIST SP 800-63B and FIPS 140-3 validation, there is little debate that phishing-resistant authentication represents the next phase of identity security modernization.

As law enforcement agencies continue investing in cloud services, mobile access and modern digital infrastructure, FIDO2 offers a practical path toward stronger security, reduced operational friction and better protection of CJI.

Organizations that begin the journey toward phishing-resistant authentication today will be better prepared for the evolving cyber threats of tomorrow.

Frequently Asked Questions

1. Does CJIS require FIDO2?

No. The CJIS Security Policy does not mandate FIDO2 or any specific authentication technology. Instead, it requires multi-factor authentication and appropriate controls to protect Criminal Justice Information (CJI). Many agencies are evaluating FIDO2 because it supports phishing-resistant authentication, helps reduce exposure to credential-based attacks and can improve the authentication experience for users.

2. What is phishing-resistant authentication?

Phishing-resistant authentication is designed to prevent users from unknowingly providing valid credentials to fraudulent websites, applications or attackers. Rather than relying on passwords or one-time codes, phishing-resistant authentication uses public-key cryptography to ensure credentials can only be used with legitimate services.

3. How does FIDO2 differ from traditional MFA?

Traditional MFA typically combines a password with a second factor such as a one-time code, push notification or token. FIDO2 replaces reliance on shared secrets with cryptographic credentials, helping reduce the risk of credential theft, phishing and account compromise while simplifying the user experience.

4. Can passkeys support CJIS security objectives?

Passkeys are built on FIDO standards and can help organizations strengthen authentication security while reducing dependence on passwords. When deployed appropriately, passkeys can support phishing-resistant authentication initiatives and broader efforts to protect sensitive information and systems.

5. Why are agencies moving beyond passwords?

Passwords remain one of the most common targets for cyberattacks, including phishing, credential stuffing and account takeover attempts. Agencies are increasingly exploring passwordless and phishing-resistant authentication methods to reduce risk, improve user experience and strengthen overall identity security.

6. Can FIDO2 work with existing authentication infrastructure?

In many environments, yes. Organizations can often introduce FIDO2 alongside existing identity and access management infrastructure rather than requiring a complete replacement. This can help agencies modernize authentication while leveraging current technology investments.

7. How does FIDO2 help prevent credential theft?

FIDO2 uses public-key cryptography instead of storing reusable passwords or shared secrets. The private cryptographic key remains on the user’s device and is never transmitted during authentication. This design significantly reduces the effectiveness of phishing attacks, credential interception and password theft techniques.