Cryptnox SA
EAN: 7649992538318
A dedicated PIV smart card embedding the FIPS 140-3 validated cryptographic module OpenFIPS201 v2.0 PIV Applet on NXP P71D600 (NIST CMVP #5280 — Overall Level 2, Physical Security Level 4), operating in its FIPS Approved mode. On-card RSA-4096 for Windows / Active Directory smart-card logon, S/MIME, document signing and EAP-TLS VPN. PIV only — no FIDO2 or MIFARE. Blank white PVC face for in-house ID printing.
ORDERS TO THE EU & US SHIP DIRECTLY FROM THE EU & US VIA FULFILLMENT BY AMAZON – NO IMPORT DUTIES
€ 29.50
Tax included. Shipping calculated at checkout.
The Cryptnox PIV White PVC card is a dedicated PIV smart card — a Swiss-engineered NFC / contact smart card that runs a single applet, PIV, and embeds the FIPS 140-3 validated cryptographic module OpenFIPS201 v2.0 PIV Applet on NXP P71D600 (NIST CMVP certificate #5280 — Overall Level 2, Physical Security Level 4), operating in its FIPS Approved mode. It generates RSA-4096 keys on-card for government-grade identity: Windows / Active Directory smart-card logon, S/MIME, document signing and certificate-based VPN. No FIDO2, no MIFARE — pure PIV.
The applet ships blank for customer personalization, with a decoupled PIV admin key so an integrator can load keys, certificates and PINs without the issuer’s card-management key.
Choose this card when you need a FIPS-validated PIV credential and nothing else. If you also need passwordless / 2FA web sign-in, see the FIDO2 + PIV card; if you also need physical building access, see the FIDO2 + PIV + MIFARE card.
The face of this card ships blank — ready for any standard PVC ID card printer (Zebra, Evolis, Fargo, Magicard, Matica). Print your company logo, employee photo, name, department or QR code on each card. Typical buyers are IT teams standardizing on FIPS-validated smart-card hardware for AD logon and digital signatures.
The PIV applet conforms to NIST FIPS 201-3 and SP 800-73-4, and works with the Windows native smart-card mini-driver (Base CSP), PKCS#11 middleware and OpenSC; it is suitable for PIV-I (interoperable) credentialing. On macOS the card is available via CryptoTokenKit or OpenSC; on Linux via OpenSC / PKCS#11.
The blank White PVC surface is dimensioned to standard CR80 ID card printer specs:
For volumes of 500+ or pre-printed batches (1,000+ cards), get in touch via our contact form.
FIPS 140-3 — validated module: this card embeds the FIPS 140-3 validated cryptographic module OpenFIPS201 v2.0 PIV Applet on NXP P71D600 (NIST CMVP certificate #5280 — Overall Level 2, Physical Security Level 4), deployed in its validated configuration and operating in the FIPS Approved mode. Card management uses SCP03, the FIPS 140-3 approved-mode secure channel. The certificate is held by the applet vendor; the Approved mode is verifiable on-card via the GlobalPlatform IDENTIFY command (tag 05 = 01).
Each part of the card is also certified independently.
Chip / platform certifications (NXP JCOP 4.5 on P71D600, Java Card platform):
Applet certification:
Cryptography: the PIV applet generates RSA-4096 / RSA-2048 / ECC P-256 / P-384 keys on-card, and private keys never leave the secure element.
This card embeds the FIPS 140-3 validated cryptographic module OpenFIPS201 v2.0 PIV Applet on NXP P71D600 (NIST CMVP certificate #5280, Overall Level 2 with Physical Security Level 4) — the exact single-applet configuration the certificate validates — deployed in its validated configuration and operating in the FIPS Approved mode, with SCP03 card management. The certificate is held by the applet vendor and covers the module (the OpenFIPS201 applet together with the P71D600 platform); the Approved mode is verifiable on-card via the GlobalPlatform IDENTIFY command. The underlying P71D600 platform is additionally certified to Common Criteria EAL6+ (NSCIB-CC-2300127-02).
This is a dedicated PIV card — it runs only the PIV applet, with no FIDO2 and no MIFARE. It is the most economical way to deploy a FIPS-validated PIV smart-card credential for Windows / Active Directory logon and digital signing. If you also need passwordless / 2FA web authentication, choose the FIDO2 + PIV card; if you additionally need physical building access, choose the FIDO2 + PIV + MIFARE card. All three share the same PIV applet with on-card RSA-4096.
It turns the card into a government-grade PIV smart card. It implements the NIST SP 800-73-4 PIV standard with the four standard key slots (9A authentication, 9C digital signature, 9D key management, 9E card authentication) and supports RSA-4096 as well as RSA-2048 and ECC P-256 / P-384. Keys are generated on-card, so the private key never leaves the secure element. That lets the card handle Windows / Active Directory smart-card logon (Kerberos PKINIT), S/MIME email signing and encryption, document and code signing, and certificate-based VPN or Wi-Fi (EAP-TLS).
The PIV applet ships installed but blank — no PINs, keys or certificates until your IT team personalizes it. To make integration easier, the PIV admin channel uses a dedicated, decoupled key (a separate GP Security Domain) rather than the issuer’s card-management key, so an integrator can load PIV keys, certificates and PINs without the master key; re-key it to a secret if you want gated PIV administration. For volume provisioning or pre-printed cards, use the Cryptnox contact form.
The PIV applet conforms to NIST FIPS 201-3 / SP 800-73-4 and works with the Windows native smart-card mini-driver (Base CSP), PKCS#11 middleware and OpenSC, and is suitable for PIV-I (interoperable) credentialing. On Windows 10/11 it supports native smart-card logon; on macOS it is available via CryptoTokenKit or OpenSC; on Linux via OpenSC / PKCS#11. Use the card in its contact (ISO 7816) interface through any standard USB CCID smart-card reader. The card itself is an NFC / contact smart card, not a USB security key.