NIST SP 800-63: Why Government Agencies Are Upgrading to vSEC:CMS 7.4

Date: 2026-07-23
Author: Joakim Thorén, CEO and Founder

Version 7.4 is officially live and already making waves globally. But what does this major upgrade mean for our largest user base, the government? Let’s dive into how public sector agencies are already putting vSEC:CMS 7.4 to work.

With every major update, we like to zoom in on a single sector to showcase how credential management is reshaping their day-to-day operations. Our goal? Rid the world of passwords, free helpdesks from tedious manual work, and elevate security with every single use.

1. Localized Control: vSEC:CMS Identity On-Premises Server

To start, let’s talk about the headline news of the 7.4 release: our new on-premises authentication server, vSEC:CMS Identity. This is a massive game-changer if you fit into one of two categories:

  • You operate in highly regulated, air-gapped, or strictly on-premises environments. If your organization cannot or will not connect authentication workflows to the public cloud, vSEC:CMS Identity gives you complete, localized control over your security infrastructure.
  • You want to instantly generate and register passkeys during token issuance. This server allows you to generate passkeys directly during the credential setup process for immediate, secure authentication—closing critical security gaps and eliminating the need for temporary codes.

2. Expanding FIDO2 Hardware Choice: Yubico’s Security Key Enterprise Edition

The second major advantage of upgrading to 7.4 is the expansion of our FIDO2 portfolio. While Versasec has long been a champion of FIDO2-only tokens, version 7.4 introduces out-of-the-box lifecycle management specifically for Yubico’s new Security Key Enterprise Edition.

This integration gives our customers even more flexibility to choose the right hardware for their unique security needs and budgets. Adding these specific hardware-backed tokens to your security portfolio provides a fast track to NIST SP 800-63 compliance and a mature Zero Trust architecture. For organizations operating in cloud-native environments, deploying these tokens offers a faster, simpler path to replacing passwords. Just as importantly, it allows you to phase out highly vulnerable legacy MFA, such as SMS and mobile push OTPs.

3. High-Impact Use Cases for FIDO2-Only Tokens in the Public Sector

In the public sector, utilizing a FIDO2-only token, like the Yubico Security Key Enterprise Edition, is ideal for several key scenarios:

  • Cloud-Native & Mobile Workforces: Ideal for government personnel on the move (such as field agents, remote workers, or engineers) who need secure access to cloud-native applications and remote servers on the go.
  • Backup & Emergency Authentication: These tokens serve as the perfect secondary authenticator. If a primary token is lost, misplaced, or simply left at home, a FIDO2-only key ensures operations don’t grind to a halt.
  • Onboarding Contractors & Temporary Partners: Government agencies frequently work with external contractors. With this setup, administrators can quickly and securely provision access to exactly what temporary users need, with minimal friction.
the goal of passwordless

4. Simplified Technical Orchestration: Hybrid Environment Passkeys Management

Another massive operational breakthrough in this release is Hybrid Environment Passkeys Management. Historically, provisioning a combined PKI and FIDO2 credential was an administrative nightmare. The PKI setup required a direct connection to the local office network to request a smart card certificate from Active Directory. Meanwhile, the FIDO2 setup required a completely separate, complex enrollment process to register the key with Microsoft Entra ID.

Now, that endless, multi-step headache is officially over—all thanks to the unified orchestration of Hybrid Environment Passkeys Management.

 

5. The Safety Net: Short-Lived Temporary Domain Passwords

Even though we’re on a mission to completely eliminate passwords, we understand that sometimes temporary access is unavoidable. But it must always happen under strictly controlled circumstances. That’s why we’ve introduced Short-Lived Temporary Domain Passwords. This is a highly specific feature, so bear with me while we break down how it works.

Occasionally, users will misplace their hardware tokens, a highly valuable security asset for any organization, whether in the government or the private sector. But there’s no need to panic. The vSEC:CMS “Inactive” lifecycle state is perfect for this exact scenario. With a single click, administrators can temporarily suspend the key inside the credential until it’s safely back in the user’s hands.

How it works in practice:

First, vSEC:CMS delivers a temporary code to the user via SMS or email. The user can then use this code to set up a temporary domain password. To make this as seamless as possible, a shortcut to this recovery option is available right on the Windows login or lock screen.

Crucially, this temporary password comes with a customizable expiration window. Because it is short-lived, it serves as a stopgap—prompting the user to find their misplaced physical key, or giving IT the time they need to provision a new, secure, long-term hardware credential.

 

6. Flexible Hardware Support with Yubico YaaS Integration

At Versasec, we do the heavy lifting so you don’t have to. We provide native, out-of-the-box integrations with the strongest hardware tokens on the market, eliminating the headache of manual integration.

Because the Security Key Enterprise Edition is part of Yubico’s flexible YubiKey as a Service (YaaS) program, administrators can take advantage of powerful “pre-registration” capabilities. To deliver this experience, Versasec worked closely with Yubico’s technical team to deeply integrate YaaS into both our vSEC:CMS and vSEC:CLOUD platforms. Now, you can order pre-issued keys straight from the factory and ship them directly to your users—all managed effortlessly from your centralized Versasec console.

But our hardware expansion doesn’t stop there. We are also actively looking to integrate the YubiKey Bio Series into our portfolio. This upcoming integration will allow organizations to combine the high-assurance security of device-bound FIDO2 credentials with the frictionless experience of biometric fingerprint authentication.

Secure Your Organization Today

Whether you are looking to accelerate your transition to phishing-resistant MFA, simplify your legacy systems, or deploy cutting-edge FIDO2 tokens on-premises, vSEC:CMS 7.4 has the tools to make it happen.

Ready to see what the next generation of credential management looks like?
Contact our team today to upgrade to vSEC:CMS 7.4 today.

vSEC:CMS

Our product suite provides all the software tools to administrate and manage credentials in a secure and convenient way.

Start here

Schedule a Strategic Call

Versasec provides enterprise credential management to accelerate phishing-resistant MFA. Our solutions enable customers to securely authenticate, issue and manage user credentials more cost effectively. Schedule a 1:1 Strategic Call With Our Identity Experts.

Job Openings

We are always looking for new exceptional persons to join our team! Find out more about our job openings.

Share this article