Cryptnox SA
EAN: 7649992538301
Swiss-engineered NFC smart card combining FIDO2 web authentication and a PIV applet with on-card RSA-4096, on the NXP JCOP 4.5 (P71D600) secure element. The PIV applet is built from the same codebase that was certified under FIPS 140-3 (NIST CMVP certificate #5280). FIDO Alliance Certified (FIDO2 v2.1 + CTAP Level 1). No MIFARE — logical identity only. Blank white PVC face for in-house ID printing. For the services and platforms this FIDO2 + PIV card supports, see FIDO2 Card Compatibility — Services and Platforms.
$ 39.36
Tax included. Shipping calculated at checkout.
Out of stock · Available on request – contact us
The Cryptnox FIDO2 + PIV White PVC card puts two credentials on one printable card — a Swiss-engineered NFC smart card built on the NXP secure element (JCOP 4.5 on P71D600). It combines FIDO2 web authentication with a PIV applet that generates RSA-4096 keys on-card. The PIV applet is built from the same codebase that was certified under FIPS 140-3 (NIST CMVP certificate #5280). This variant has no MIFARE applet — it is purpose-built for logical identity.
The two applets are logically firewalled inside the secure element — each uses its own keys and memory space, so a compromise of one cannot reach the other.
Choose this FIDO2 + PIV card when you need a PIV applet on the certified chip and do not need physical door access. If you also need MIFARE building access on the same card, see the FIDO2 + PIV + MIFARE card; if you only need web authentication, see the FIDO2-only White PVC card.
The face of this card ships blank — ready for any standard PVC ID card printer (Zebra, Evolis, Fargo, Magicard, Matica). Print your company logo, employee photo, name, department or QR code on each card, then issue one credential that covers web sign-in and PIV identity. Typical buyers are corporate IT teams standardizing on smart-card hardware.
The card supports both NFC and contact (ISO 7816) interfaces. For FIDO2, tap on supported phones (iPhone 7+ on iOS 13.3+ supports FIDO2 over NFC; Android external NFC keys are mainly CTAP1 / U2F second-factor, not full FIDO2). PIV smart-card logon and signing use the contact interface through a standard USB CCID reader. For Windows desktop users, the Cryptnox Click-to-Tap Smartcard Reader adds a dedicated “tap” button that electronically simulates card extraction and reinsertion (Windows only) — see our click-to-tap tutorial.
The blank White PVC surface is dimensioned to standard CR80 ID card printer specs. You can:
The PIV applet ships blank for customer personalization, with a decoupled PIV admin key so integrators can load keys, certificates and PINs without the issuer’s card-management key.
The PIV applet conforms to NIST FIPS 201-3 and SP 800-73-4, and works with the Windows native smart-card mini-driver (Base CSP), PKCS#11 middleware and OpenSC; it is suitable for PIV-I (interoperable) credentialing.
For volumes of 500+ or pre-printed batches (1,000+ cards), get in touch via our contact form. For setup walkthroughs and service-specific tutorials, browse our FIDO2 tutorials hub.
Each part of the card is certified independently. Chip / platform certifications (NXP JCOP 4.5 on P71D600, Java Card platform):
Applet certifications (each certified separately):
Cryptography: FIDO2 attestation uses NIST P-256 (secp256r1) only; the PIV applet generates RSA-4096 / RSA-2048 / ECC P-256 / P-384 keys on-card, and private keys never leave the secure element.
The PIV applet is built from the same codebase that was certified under FIPS 140-3 (NIST CMVP certificate #5280), and the card is built on NXP JCOP 4.5 (P71D600) hardware that has been certified under FIPS 140-3 (NIST CMVP certificate #4679). Neither is deployed in the configuration covered by its certificate, and Cryptnox does not claim any FIPS certification at this stage. The P71D600 secure element is also certified to Common Criteria EAL6+ (NSCIB-CC-2300127-02), and the FIDO2 applet is FIDO Alliance Certified.
Two differences. First, this card has no MIFARE applet — it is built only for logical identity (FIDO2 web authentication and PIV), not physical door access. Second, it is built on the NXP P71D600 secure element (JCOP 4.5). The FIDO2 + PIV + MIFARE card adds MIFARE DESFire EV2 building access on a different chip (P71D321). Choose this card when you need a PIV applet and no door access; choose the MIFARE card when you also need physical access control on the same badge.
The PIV applet turns the card into a government-grade PIV smart card. It implements the NIST SP 800-73-4 PIV standard with the four standard key slots (9A authentication, 9C digital signature, 9D key management, 9E card authentication) and supports RSA-4096 as well as RSA-2048 and ECC P-256 / P-384. Keys are generated on-card, so the private key never leaves the secure element. That lets one card handle Windows / Active Directory smart-card logon (Kerberos PKINIT), S/MIME email signing and encryption, document and code signing, and certificate-based VPN or Wi-Fi (EAP-TLS). The applet ships blank — your team personalizes the keys, certificates and PINs, using a decoupled admin key so an integrator can provision the card without the issuer’s master key.
Any service that supports FIDO2, WebAuthn or legacy U2F — Google, Microsoft, Apple ID, GitHub, GitLab, AWS, Okta, Microsoft Entra ID, Google Workspace, login.gov, AGOV, SwissID, and major banks and exchanges — as a phishing-resistant second factor, and for passwordless sign-in where the service supports it. The card provides 64 on-card resident-credential (passkey) slots, up to 8 per website by default. If a service’s security settings offer a “security key” or “passkey” option, this card will work.
Windows 10/11 has full FIDO2 / passkey support plus PIV smart-card logon via the native mini-driver (Base CSP). iOS supports FIDO2 over NFC natively (any iPhone 7+, iOS 13.3+). Android currently supports only CTAP1 / U2F (FIDO1) for external NFC keys — it works as a U2F second factor on most major services, but not for FIDO2 passwordless / passkey sign-in. macOS FIDO2-over-NFC support varies by version and browser; PIV is available via CryptoTokenKit or OpenSC. Linux browsers expect a HID interface — use the Cryptnox FIDO2 HID bridge for FIDO2, and OpenSC / PKCS#11 for PIV. Always test with your specific OS, browser and service before a production rollout.
Up to 8 per website (relying party) by default, out of the card’s 64 passkey slots in total. This matters mostly for users with several accounts on the same service, typically Microsoft Entra ID. Cards without the per-website limit are available on special request — please contact us.