Switches and routers can't parse FIDO2 or PIV.
A Cisco IOS, NX-OS, or Juniper Junos device has no idea how to evaluate a WebAuthn assertion or validate a PIV certificate from an SSH client. FIDO2 was published in 2018; the AAA stack on a Catalyst 9000 was designed in the era of TACACS+/RADIUS shared secrets. The protocols don't bridge.