NETWORK AND WIFI SECURITY CyberArtical Editorial Team

Choosing between WPA2 and WPA3 on the router you already own

A red padlock in close-up, with blurred rack-mounted network equipment behind it

This is a genuine choice, unlike most encryption comparisons, because plenty of routers offer both and plenty of households have a device that struggles with the newer option. The guidance gives a clear order of preference and an important caveat about what "WPA2" means when you select it. Both are worth having before you touch the dropdown.

The two positions, side by side

  • FTC: "either WPA3 Personal or WPA2 Personal. WPA3 is the newer — and best — encryption available."
  • CISA: "WPA3 Personal or WPA2 AES (also referred to as WPA2 Pre-Shared Key [PSK])".
  • CISA puts WPA2 TKIP in the same category as WEP and original WPA: replace or upgrade the router.
  • So "WPA2" on its own is not sufficient guidance — the cipher matters as much as the protocol number.
  • FTC: routers offering only WPA or WEP are "outdated and not secure".

Pick WPA3 if the router offers it

Choose WPA3 Personal if your router offers it. The FTC calls it the newer and best encryption available and lists it first.

If it does not, WPA2 is acceptable — but specifically WPA2 with AES, which routers also label WPA2-PSK. Not WPA2 with TKIP, and not a mixed mode that keeps TKIP available.

If neither is available, that is the replace-the-router case rather than a choice.

How the two are actually presented to you

Router menus are inconsistent, and the wording matters more than the marketing. You will typically see some subset of: WEP; WPA-PSK; WPA2-PSK; WPA2-PSK (AES); WPA/WPA2 mixed; WPA2/WPA3 mixed or transitional; and WPA3-SAE or WPA3 Personal.

Two of those deserve a second look. "WPA/WPA2 mixed" keeps the older, weaker protocol available for devices that ask for it, which means the network is only as strong as the weakest thing that connects to it. "WPA2/WPA3 transitional" does the same one step up: it allows WPA3 for devices that support it and WPA2 for those that do not.

Transitional mode is a reasonable compromise while you still have older devices, and it is honest to say that it is a compromise rather than the same thing as WPA3.

What each agency emphasises

  • The FTC leads on ordering. WPA3 Personal first, WPA2 Personal acceptable, and anything older means the hardware should be replaced.
  • CISA leads on the variant. Its acceptable list names WPA2 AES/PSK explicitly, and puts WPA2 TKIP in the replace-or-upgrade bucket. If your only WPA2 option is TKIP, you are not in the acceptable set.
  • Both treat this as one item on a list. The FTC pairs it with unique admin credentials, firmware updates, remote management off, WPS and UPnP off, the firewall on, and a guest network. CISA pairs it with a long, random, unique router password, routine firmware updates, guest Wi-Fi for IoT devices, and WPS disabled.

How to find out which you are actually running

  1. Log into the router’s admin interface using the address on the label, and open the wireless settings.
  2. Read the security dropdown. Note both what is selected and what else is available — the available list tells you whether this is a settings change or a hardware question.
  3. If the selection says WPA2 without naming a cipher, look for a separate encryption or cipher field nearby. AES is what you want; TKIP is not.
  4. Check the firmware version and update it before concluding WPA3 is unsupported. Some models gained it in an update.
  5. If your only options are WEP, WPA, or WPA2 TKIP, that is the replace-the-router answer — and if the router came from your internet provider, ask them before buying anything.

Choosing, and dealing with the device that will not connect

  1. Set WPA3 Personal and see what breaks. Most current phones, laptops and tablets are fine.
  2. If something will not connect, identify it specifically rather than reverting immediately. It is usually one older device, not a general incompatibility.
  3. Check whether that device has a firmware update available. Smart plugs, older printers and cameras are the usual culprits and some are fixable.
  4. If it cannot be fixed, put it on the guest network and leave the main network on WPA3. CISA’s instruction is to connect smart home and IoT devices to guest Wi-Fi where internet access is all they need — which solves this problem and the segmentation problem at once.
  5. Only if the device must be on the main network, use WPA2/WPA3 transitional mode, and treat it as temporary rather than settled.
  6. Whatever you choose, verify the cipher is AES rather than TKIP.

What people get wrong about this comparison

The first mistake is treating "I am on WPA2" as an answer. It is half of one. The cipher underneath determines whether you are in CISA’s acceptable set or its replace-the-router set.

The second is overrating the choice. Changing this dropdown is one line on a list where several other items do more for a typical household — a unique administrator password instead of the printed default, remote management disabled, current firmware, and smart devices kept off the main network. A perfectly configured WPA3 network with the factory admin password is not a well-secured network.

The third is periodic Wi-Fi password changes, which neither agency’s home guidance asks for. Both emphasise changing the defaults once to something long, random and unique, and using a guest network so fewer people hold the primary password at all.

Sources: FTC — How to secure your home Wi-Fi network · CISA Project Upskill, Module 5 · NIST IR 8425A — Requirements for consumer-grade router products

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FTC, CISA and NIST. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories