Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
94% Claim 24-Hour Revocation, 35% FailedOAuth & OIDC
3 min readFor IT Governance & Compliance Teams

94% Claim 24-Hour Revocation, 35% Failed

What Happened

A study by the FIDO Alliance and HID surveyed 500 IT and cybersecurity decision-makers across five countries and sectors. The research highlighted a significant gap: 94% of organizations believed they could revoke all access within 24 hours of an employee's departure, but 35% faced delays or failures in doing so over the past two years. Additionally, 70% reported at least one identity-related security incident.

The Public Sector had the highest incident rate, with 43% experiencing access revocation failures and a 20% manual credential revocation rate, more than double that of the IT/Technology sector.

Timeline

June 2024 to June 2026: Organizations faced identity-related security incidents while managing an average of three separate credential systems. During this period, 35% failed to meet their 24-hour revocation commitment.

June 15, 2026: Findings were released at Identiverse 2026, highlighting the gap between confidence and execution and its link to fragmented governance.

Which Controls Failed or Were Missing

Unified governance structure: Only 50% of enterprises had unified reporting for physical and digital identity, and just 48% consolidated budget control. Finance was the most fragmented, with 34% operating separate reporting structures despite regulatory obligations.

Lifecycle automation: A 20% manual credential revocation rate in the Public Sector indicates missing or incomplete automated workflows. Manual processes lead to delays and errors.

Comprehensive phishing-resistant authentication: While 93% reported some passkey adoption, only 13% deployed them at scale. Partial deployment leaves gaps for threat actors.

System integration: With 59% managing three or more credential systems and 58% reporting increased complexity, there's a lack of integration for timely revocation across all access points.

What the Relevant Standards Require

NIST SP 800-53 Rev. 5 (AC-2: Account Management) mandates disabling accounts within a defined time when access is no longer authorized, using automated notifications. A 24-hour window is feasible only with reliable automation.

NIST SP 800-63B (Digital Identity Guidelines) outlines credential lifecycle management, including revocation. Authenticators must be revocable before exploitation. Execution, not confidence, meets this requirement.

FIDO2 specifications define phishing-resistant authentication through public key cryptography. Comprehensive deployment is essential; selective implementation leaves vulnerabilities.

ISO/IEC 27001:2022 (A.5.18: Access Rights) requires access rights removal or adjustment upon employment changes. Fragmented governance can lead to coordination failures, violating this standard.

Lessons and Action Items for Your Team

Audit your actual revocation performance. Log every deprovisioning event with timestamps. Compare your 24-hour commitment against reality to identify unexpected gaps.

Unify governance before technology. Consolidate reporting ownership to avoid technical integration failures at organizational boundaries. Treat fragmented governance as a compliance risk.

Map every credential system. Identify every directory, authentication provider, and access control system. You can't automate revocation for unidentified systems.

Build automated deprovisioning workflows. Manual revocation introduces risk. Your Identity Governance platform should trigger deprovisioning across all systems when HR marks an employee as terminated.

Deploy passkeys comprehensively. Prioritize high-risk users and applications. Expand systematically to cover your entire authentication surface.

Instrument your identity infrastructure for compliance reporting. Gain real-time visibility into revocation latency and orphaned accounts. Track which systems cause delays.

Test your incident response for identity-based attacks. Practice revoking access under pressure, not just during scheduled offboarding.

The gap between confidence and execution isn't due to a lack of awareness. It's because governance is fragmented, systems are disconnected, and authentication is vulnerable to phishing. Close this gap by unifying governance, automating lifecycle management, and deploying phishing-resistant authentication at scale. Your incident rate will improve with execution, not just confidence.

Application Security Isn’t Optional Anymore.

You Might Also Like