← All articles

consultant

BSI Releases TR‑03188 'Passkey Server' (v1.0, July 2026)

BSI releases TR‑03188 v1.0, an operational guide to deploy server‑side passkeys (FIDO2/WebAuthn). A milestone for phishing‑resistant MFA and GDPR Article 32 compliance.

Excerpt — In late July 2026, Germany’s BSI published a 48‑page technical guideline on server‑side passkey deployment. Here is how phishing‑resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 — and how to roll it out painlessly.

Key facts

The Bundesamt für Sicherheit in der Informationstechnik (BSI) announced the release of Technische Richtlinie TR‑03188 “Passkey Server” version 1.0, an operational profile detailing threat models, assurance levels, and MUST/SHOULD requirements for passkey authentication servers. The official announcement was echoed by BSI and the trade press in July 2026 — a Linux‑Magazin article confirms v1.0 availability, while BSI points to the TR‑03188 page and its PDF (48 pages) on its website (official mirrors and posts). BSI’s explicit objective: make passkeys an operational “state of the art” and define secure server‑side configurations (BSI post).

Why does this matter to Luxembourgish and EU leaders? Because phishing‑resistant MFA (FIDO2/WebAuthn passkeys) blocks “AiTM” and “device‑code” attacks that bypass OTP/SMS and authenticator apps. Meanwhile, regulatory pressure (GDPR, NIS 2, CSSF) now demands proportionate, state‑of‑the‑art measures — and TR‑03188 finally provides a clear, auditable server‑side playbook for Europe.

The applicable legal framework

GDPR Article 32 requires controllers and processors to implement appropriate technical and organizational measures, “taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risks.” In other words: if robust, proven mechanisms exist to reduce a high risk of unauthorized access (here, credential or session theft), they must be considered and justified. Official text: EUR‑Lex — Article 32.

Beyond GDPR, several European authorities explicitly recommend phishing‑resistant MFA. For instance, ENISA highlights phishing risks and, in its technical guidance on risk management measures, recommends phishing‑resistant MFA as a best practice (ENISA technical docs, 2025‑2026). On standardization, NIST SP 800‑63B defines “phishing resistance” and cites WebAuthn/FIDO2 as an example meeting the verified domain binding criterion. These references strengthen the proportionality argument required by Article 32.

The technical solution to deploy

Passkeys (FIDO2/WebAuthn) replace shared secrets (password + OTP) with an asymmetric cryptographic key pair: the private key stays in the authenticator (hardware‑backed or OS‑protected), the public key is registered on the server. At authentication time, the user completes a proof of possession bound to the service’s domain, which makes phishing ineffective (the signature cannot be replayed elsewhere).

The novelty of TR‑03188 is a server‑side to‑do list:

  • Threat models and assurance levels: graded requirements (normal/substantial/high) depending on authenticator robustness and account recovery paths. Weak recovery (email links, SMS OTP) degrades the overall level.
  • Integration: “build vs buy” options — FIDO2 libraries, dedicated FIDO2 server, IAM module, managed cloud — and configuration requirements on the Relying Party (RP).
  • Hardening: RP identifiers management, attestation where needed, device enrollment and re‑binding policies, discoverable vs non‑discoverable registrations per use case.
  • Logging and evidence: structured authentication logs (attempts, factors used, results, device binding) for GDPR/NIS 2 audit and investigation.

Useful references: ISO/IEC 27001 Annex A (A.8/A.5 identity and access controls), NIST SP 800‑63B (authenticators and phishing resistance), ENISA authentication best practices.

How Luxgap delivers this

  • ISO 27001 governance: our Lead Implementer/Lead Auditor consultants frame the risk assessment (process/risks, Art. 32) and the authentication policy design (required assurance level, use cases, account recovery, BYOD, third‑party access). We align controls with TR‑03188 and document GDPR proportionality justifications.
  • Managed SOC 24/7: our analysts connect authentication feeds (IdP, FIDO2 server, reverse proxy) into the SIEM, define detections (impossible travel, re‑binding anomalies, repeated failures by source) and automate common responses (SOAR).
  • Fractional DPO/CISO consultants: we orchestrate updates to registers, access policies, and incident playbooks (CNPD/ILR notification if required), and prepare the evidence expected during audits.

Practically, we offer a three‑step journey: 1) risk/obligations framing (GDPR Art. 32, NIS 2 if applicable); 2) proof‑of‑value on a priority scope (administration, VPN, cloud consoles); 3) phased rollout with a passwords → passkeys migration plan and hardened recovery policy.

Real‑world case in Luxembourg or the EU

An anonymized example: an asset manager subject to NIS 2 migrated its admin access and SaaS consoles to FIDO2 passkeys within 8 weeks:

  • Weeks 1–2: risk analysis, integration model selection (managed FIDO2 server connected to the IdP), definition of enrollment and recovery paths without email/SMS.
  • Weeks 3–5: pilot on 60 sensitive accounts (IT, finance, leadership). Activation of password‑less policies and strong device binding. Logging streamed to Luxgap’s SIEM.
  • Weeks 6–8: extension to privileged staff, progressive password deactivation where possible, update of third‑party access procedures.

Results: measurable reduction of phishing‑based account takeover attempts (no pilot account compromise), time‑to‑detect under 5 minutes thanks to SOC alerts, and an Article 32 compliance dossier ready (measures, tests, registers, effectiveness evidence).

Getting started

  1. Map critical access: privileged accounts, SaaS consoles, VPN, sensitive apps. Assess AiTM/phishing risk on each flow.
  2. Choose your TR‑03188 integration model: library, FIDO2 server, IAM module, or managed service. Require WebAuthn support and comprehensive logs.
  3. Harden account recovery: ban email links and SMS OTP for sensitive accounts. Use strong recovery keys and verified procedures.
  4. Run a password‑less pilot on a limited scope (admins, leadership). Measure adoption and incidents; adjust policies.
  5. Feed your SIEM: collect and correlate authentication events (success/failure, key registrations, method changes) and define response playbooks.

Official sources

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →