Implementation Cost by Tier (INR, 2026)
Tier 1 — Single App Pilot: ₹60,000 – ₹1,50,000 (2–4 weeks). Tier 2 — Web + Mobile Rollout: ₹2,00,000 – ₹5,50,000 (6–10 weeks). Tier 3 — Enterprise IAM Modernization: ₹6,00,000 – ₹15,00,000 (3–5 months). Tier 4 — Regulated / Bank-Grade: ₹18,00,000+ (5+ months).
The Four-Phase Rollout
Phase 1 — Pilot: Optional passkeys for one low-risk user segment (2–4 weeks). Phase 2 — Dual-mode rollout: Passkeys default, password/OTP visible fallback (4–8 weeks). Phase 3 — Password deprecation: Nudge remaining users; disable reset where passkey active (2–6 months). Phase 4 — Monitoring: Track failures/recovery usage by device type (Ongoing).
How to Decide If Now Is the Right Time
Score your business against five factors: how sensitive the data behind this login is, how diverse your users' devices and browsers are, how much regulatory pressure (DPDP, RBI, SOC 2) you're already facing, how much legacy IAM/SSO debt you're carrying, and whether you can resource a 2–4 quarter phased migration rather than a single sprint. Two or more "high urgency" answers mean you should scope Tier 3 now rather than starting with a minimal pilot.
Frequently asked questions
- How much does it cost to implement passkeys for a business in India in 2026?
- A single-app pilot with OTP fallback typically runs ₹60,000–₹1,50,000. A web-plus-mobile rollout with a managed CIAM provider runs ₹2,00,000–₹5,50,000. Enterprise-wide IAM modernization with SSO and compliance mapping runs ₹6,00,000–₹15,00,000, and bank-grade or regulated deployments with hardware key support run ₹18,00,000 and up.
- What is passwordless authentication and how are passkeys different from passwords?
- Passwordless authentication replaces a typed secret with a cryptographic key pair generated on the user's device (the passkey/WebAuthn standard). The private key never leaves the device and nothing secret travels over the network at login, which makes passkeys resistant to phishing, credential stuffing, and password-database breaches in ways passwords structurally cannot be.
- Are passkeys compliant with India's DPDP Act and RBI guidelines?
- Neither framework names passkeys specifically, but both expect "reasonable security safeguards" and strong access control for systems handling personal or financial data. Passkeys are widely accepted by auditors as strong evidence toward those requirements because they satisfy phishing-resistant MFA expectations more cleanly than SMS OTP.