Your fingerprint is not replacing your passcode
The line you have read is that biometrics have made passwords obsolete, and that adding a fingerprint to a password is belt and braces. Both claims misdescribe what is happening on the device in your hand. On a modern phone, the passcode is what stands between an attacker and your encrypted data. The fingerprint is a faster way to get past a lock that the passcode is still holding shut.
What the agencies actually specify
- CISA on iOS: ‘Set a passcode on iPhone’ is the instruction that enables encryption.
- CISA on Android: ‘On newer Android versions, the device will be encrypted automatically once you set a screen lock.’
- CISA says the system-encryption credential should be ‘a password that is long, random, and unique’.
- FTC’s floor for a phone lock: ‘Use at least a 6-digit passcode.’
- NIST SP 800-63B-4 requires a 15-character minimum for a password used as the only authentication factor.
The claim: biometrics have retired the password
It is an appealing story, and the hardware encourages it. You touch a sensor, the phone opens, and you have not typed a secret. It looks like the password has been removed from the process.
It has not. It has been moved out of sight. Restart the phone and it will demand the passcode, not the fingerprint. That behaviour is the tell.
What the screen-lock credential is actually protecting
CISA’s device guidance describes encryption at rest on mobile as following directly from the lock. On iOS, setting a passcode is what turns encryption on. On newer Android versions the device is encrypted automatically once a screen lock is set.
That has a consequence people rarely state: the passcode is not guarding a lock screen, it is guarding the key to the whole encrypted volume. A four-digit PIN is not a minor inconvenience to an attacker who has the device; it is a very small number of possibilities protecting everything on it.
The FTC sets the floor at six digits and says the phone should lock when you are not using it. CISA goes further for system encryption generally, describing the credential as one that should be long, random and unique.
Where a fingerprint genuinely helps
The real benefit is behavioural, and it is substantial. Because unlocking is fast, people tolerate a much stronger passcode than they otherwise would, and they tolerate a short auto-lock timer. A six-digit passcode you type twice a day is more realistic than one you would type sixty times.
A sensor also defeats shoulder-surfing. Nobody can watch you enter a fingerprint in a queue.
So biometrics improve security indirectly, by making a strong underlying credential liveable. That is a real gain. It is not the same as the fingerprint being the security.
What to set up instead of trusting the sensor
- Set a passcode of at least six digits, per the FTC. If your phone offers an alphanumeric option, use it — it is what CISA’s ‘long, random, and unique’ language points at.
- Turn on the fingerprint or face unlock afterwards, as the convenience layer it is. Keeping the passcode strong is what it buys you.
- Set the screen to lock automatically after a short idle period. An unlocked phone on a table has no encryption story at all.
- Turn on the built-in find, lock and erase feature now. The FTC notes it is already part of mobile operating systems, and it must be enabled before the device goes missing, not after.
- Back up regularly, so that erasing a stolen phone remotely is a decision you can afford to make.
Why the password-killer framing keeps coming back
Partly because it is nearly true somewhere else. In online authentication, passkeys really are displacing passwords, and NCSC UK now recommends that users favour them where services offer them. But a passkey is a cryptographic credential stored on the device; the fingerprint merely authorises its use locally. Even there, the biometric is the gate, not the key.
Partly because ‘you are the password’ is a better marketing line than ‘this shortens the time you spend typing a passcode you should have made longer’.
And partly because the everyday experience genuinely feels like the password is gone. You go weeks without typing it. Then the phone restarts after an update, and the passcode field appears, and for a second you cannot remember what you set. That moment is the architecture showing itself.
The precise version is duller and more useful. Your biometric unlocks a credential. Make sure the credential underneath it is worth unlocking.
The one place the trade-off is real
There is a genuine consideration in combining the two, and it is not cryptographic. A password is something you can decline to disclose; a fingerprint can be applied to a sensor by someone holding your hand. The legal treatment of that difference varies by jurisdiction and is outside what these agencies publish, so treat this as context rather than guidance — but it is why most phones let you disable biometric unlock quickly, and why the passcode remains mandatory after a restart.
The practical version: know the shortcut your phone uses to force a passcode-only unlock, and use it in any situation where you would rather the device stayed shut. Neither CISA nor the FTC frames this as a general recommendation, and for most people, most of the time, the fingerprint is simply the thing that makes a strong passcode bearable.
Sources: CISA — how to protect data stored on your devices · FTC — how to protect your phone from hackers · NIST SP 800-63B-4, Digital Identity Guidelines · NCSC UK — traditional credentials and FIDO2 for personal use
Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA, the FTC, NIST and NCSC UK. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.