The question isn't whether to adopt passkeys. With 93 percent of organizations on the adoption path and 65 percent reporting high technical familiarity, the technology is well understood. The real question is why only 13 percent have deployed them at scale, and what this execution gap reveals about organizing identity security.
The answer lies in a governance structure most enterprises inherited rather than designed: separate physical and digital identity teams. Research from the FIDO Alliance and HID shows only half of enterprises have unified reporting lines for these functions, while 48 percent have consolidated budget ownership. Finance runs the most fragmented model, with 34 percent operating fully separate reporting structures despite facing strict regulatory requirements.
This split creates a straightforward problem. When physical access and digital authentication are under different leaders, passkey rollouts stall at the coordination layer. You can't deploy phishing-resistant authentication comprehensively when half your credential systems answer to different budgets and roadmaps.
The Case for Unified Identity Governance
Consolidating physical and digital identity under a single reporting structure directly addresses the execution gap. When one leader owns both domains, passkey deployment becomes an operational decision rather than a cross-functional negotiation.
Incident data supports this. Seventy percent of organizations reported at least one identity-related security incident in the past two years. More than 170 experienced delays or failures revoking access when employees left, despite 94 percent expressing confidence they could complete revocation within 24 hours. The public sector saw the highest failure rate: 43 percent couldn't revoke access reliably, and one in five still use manual credential revocation.
These aren't technical failures; they're coordination failures. When physical badge systems and digital authentication platforms report through separate chains, no single person can see the complete picture of an identity's access footprint. Just-in-Time Elevation policies don't help if you can't enumerate what privileges exist across both domains. Certification Campaigns miss entitlements when half the Entitlement Catalog lives outside your scope.
The complexity argument is equally clear. Fifty-nine percent of organizations manage three or more credential or authentication systems. Fifty-eight percent said digital identity management has become more complex over the past two years. Adding passkeys to this environment without unified governance means adding another authentication method to coordinate across disconnected teams.
The Case for Maintaining Separate Teams
Physical and digital identity serve different operational needs with different skill requirements. Badge systems, door controllers, and visitor management platforms operate on different technology stacks than FIDO2 authenticators, OAuth 2.0 flows, and Federation Metadata. Forcing these specializations under one leader risks creating a generalist who understands neither domain deeply.
The regulatory argument cuts both ways. While finance faces strict requirements, those requirements often treat physical and digital access as distinct control domains. Sarbanes-Oxley segregation of duties rules, for instance, care about logical access to financial systems more than physical access to buildings. Audit frameworks like SOC 2 Type II evaluate these controls separately. Consolidating governance doesn't necessarily simplify compliance; it may just concentrate accountability without improving outcomes.
Budget separation also reflects real cost structures. Physical security infrastructure (cameras, badge readers, door locks) depreciates on different schedules than software licenses. Capital expenditure cycles don't align with SaaS subscription models. When finance runs separate reporting structures, they're acknowledging that physical and digital identity investments compete in different budget categories with different approval thresholds.
The operational tempo differs too. Physical security teams respond to building emergencies, visitor protocols, and facility management needs. Digital identity teams respond to authentication outages, federation trust breaks, and credential compromise. These rhythms don't naturally sync. A unified reporting structure doesn't eliminate the need for specialized on-call rotations and incident response procedures.
Where Practitioners Actually Land
Most organizations aren't choosing between full consolidation and complete separation. They're building coordination mechanisms that preserve specialized expertise while reducing the execution gap.
The 50 percent who've unified reporting lines typically maintain separate operational teams with a shared strategic leader. The CISO or VP of Security owns both domains but delegates day-to-day execution to specialists. This model works when the shared leader can translate passkey deployment into concrete requirements for both teams and enforce timeline accountability.
The other approach is unified tooling without unified reporting. Organizations deploy Identity Governance and Administration (IGA) platforms that ingest both physical and digital access data into a single Entitlement Catalog. This gives security teams visibility across domains even when organizational charts remain split. The 48 percent with consolidated budget ownership often use this model; they can't reorganize reporting lines, but they can standardize on platforms that bridge the gap.
Neither approach fully solves the coordination problem. The research shows 59 percent managing three or more authentication systems, which means most unified reporting structures still oversee fragmented technology stacks. And shared tooling only helps if both teams actually use it. When physical security keeps badge data in a separate system of record, your IGA platform can't run accurate Certification Campaigns.
Our Take
Unified reporting makes sense for most enterprises, but not as a reorganization exercise. The goal isn't to merge teams or eliminate specialization. It's to create accountability for the execution gap.
When 45 percent of organizations cite phishing and credential-based breaches as their main driver for passwordless authentication, and 44 percent want to cut password reset costs, passkey deployment becomes a business priority. Business priorities need single-threaded owners. If your physical and digital identity teams report through separate chains, neither leader can be held accountable for comprehensive deployment.
The finance sector's fragmentation is particularly telling. These organizations face the strictest regulatory requirements but run the most separated governance structures. That's not a coincidence; it's a sign that compliance frameworks haven't caught up to the reality that physical and digital access are now part of the same attack surface. Unified reporting doesn't just improve security outcomes; it positions you for the regulatory requirements that are coming.
Start with visibility before reorganizing. Deploy an IGA platform that can enumerate both physical and digital entitlements. Run a Certification Campaign that includes badge access and application permissions. If you can't complete that campaign without manual coordination between teams, you've identified your execution gap. Then you can decide whether unified reporting or better tooling closes it faster.
The 13 percent who've deployed passkeys at scale didn't wait for perfect governance. They built enough coordination to execute comprehensively. That's the benchmark.





