In my opinion you should think of WebAuthn as the first factor. If you want additional second factors (of whatever nature they may be) you can still add these of course.
Think of it like logging in using a SSH-key.
Think of it like logging in using a SSH-key.