What Is WPA3 (Wi-Fi Protected Access 3)?

Related problems: Office Wi-Fi still uses a shared password set years ago; Auditors or insurers asking how our wireless network is secured; Older devices that can't connect when we tighten Wi-Fi security; Planning a Wi-Fi 6E or Wi-Fi 7 upgrade and not sure what security it needs

Wi-Fi Protected Access 3 (WPA3) is the Wi-Fi Alliance’s current security certification for wireless networks, introduced in 2018 as the successor to WPA2. It sets how devices prove they are allowed on a Wi-Fi network and how traffic between the device and the access point is encrypted. Its best-known change is a new password handshake that is designed to resist the offline password-guessing attacks that affected shared-password WPA2 networks.

At a glance

  • WPA3 comes in Personal (shared password) and Enterprise (individual credentials) forms.
  • WPA3-Personal replaces the WPA2 pre-shared key handshake with Simultaneous Authentication of Equals (SAE), designed to resist offline password guessing.
  • WPA3-Enterprise adds an optional 192-bit security mode for high-security environments.
  • Networks in the 6 GHz band used by Wi-Fi 6E and Wi-Fi 7 require WPA3, or Enhanced Open for open networks.
  • Transition mode lets WPA2 and WPA3 devices share a network during migration, with weaker protection than WPA3 alone.

What problem it solves

Most small and mid-sized offices protect at least one wireless LAN with a shared password. Under WPA2, an attacker within range could capture the handshake when a device connected and then try millions of password guesses offline, at their own pace, without the network ever noticing. Weak or old passwords could be cracked this way, and once recovered, the password could also help decrypt traffic that had been captured.

WPA3 addresses this. Its SAE handshake means each guess requires interacting with the network, which is designed to make bulk offline guessing impractical, and it provides forward secrecy so that learning the password later does not unlock previously recorded traffic. It also requires protected management frames, which helps against some attacks that knock devices off the network. For organizations that manage wireless across many sites, it is the baseline security setting for new deployments.

How it works

WPA3-Personal. Devices and the access point use SAE to agree on encryption keys based on the shared password, without exposing material that can be attacked offline. Each session gets its own keys.

WPA3-Enterprise. Each user or device authenticates with its own credentials or certificate, typically through 802.1X and a RADIUS server tied to your directory. This is the recommended approach for corporate networks, often combined with network access control (NAC) to decide what each device can reach. An optional 192-bit mode uses stronger cryptographic suites for government and other high-security settings.

Transition mode. Access points can offer WPA2 and WPA3 at the same time so older clients keep working. This helps migration but leaves the network open to WPA2-style attacks against those older clients, so it is best treated as temporary.

Related features. Enhanced Open, based on Opportunistic Wireless Encryption, is a separate Wi-Fi Alliance certification that encrypts traffic on open guest networks with no password. It is often deployed alongside WPA3 but is not the same thing.

When it matters for buyers

  • When refreshing access points. New equipment generally supports WPA3; check that your management platform and policies use it. See our wired and wireless LAN infrastructure overview for the wider picture.
  • When moving to Wi-Fi 6E or Wi-Fi 7. The 6 GHz band requires WPA3, or Enhanced Open for open networks, so devices that support only WPA2 can’t join those networks.
  • When auditors, insurers or customers ask about wireless security. “WPA3-Enterprise with individual credentials” is a stronger answer than a shared password.
  • When buying managed Wi-Fi. Ask which security mode the provider will configure and who manages credentials.
  • When you have many IoT or legacy devices. Plan a separate network or replacement path before turning off WPA2.

Questions to ask vendors

  • Do your access points and controllers support WPA3-Personal, WPA3-Enterprise and the 192-bit mode?
  • What security mode will you configure by default, and will you use transition mode?
  • How do you handle devices that support only WPA2?
  • How do you integrate WPA3-Enterprise with our identity provider or RADIUS service?
  • How quickly do you release firmware fixes when Wi-Fi security flaws are disclosed?
  • Do you support Enhanced Open for guest networks?

How it differs from Wi-Fi standards

Wi-Fi standards such as Wi-Fi 6, 6E and 7 (IEEE 802.11ax and 802.11be) define how fast and how efficiently devices send data over the air. WPA3 is a security certification that defines how devices authenticate and encrypt that data. They are related but separate: a Wi-Fi 6 device can run WPA2 or WPA3, although newer certifications and the 6 GHz band require WPA3. WPA2, the predecessor, is still widely used, especially by older devices; WPA3 is generally the stronger choice for new networks.

Frequently Asked Questions

Is WPA3 required?
It depends on the network. Wi-Fi Alliance certification has required WPA3 support in newly certified devices for several years, and networks using the 6 GHz band (Wi-Fi 6E and Wi-Fi 7) require WPA3 or Enhanced Open for open networks. Elsewhere it is a strong recommendation rather than a legal requirement, though some industry frameworks and customer contracts may expect it.
Will our older devices work with WPA3?
Not all of them. Older laptops, printers, scanners and IoT devices may support only WPA2. Many access points offer a transition mode that accepts both, or you can run a separate network for legacy devices while you replace them.
What is the difference between WPA3-Personal and WPA3-Enterprise?
WPA3-Personal uses a shared password and protects it with a newer handshake. WPA3-Enterprise authenticates each user or device individually, usually through 802.1X and a RADIUS server, and offers an optional higher-strength 192-bit mode for sensitive environments.
Does WPA3 make our Wi-Fi secure on its own?
No. It protects the wireless connection itself. You still need strong credentials, up-to-date access point firmware, network segmentation, and controls on what connected devices can reach.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.