Cryptnox SA
EAN: 7649992538318
A dedicated PIV smart card. The PIV applet is built from the same codebase that was certified under FIPS 140-3 (NIST CMVP certificate #5280). It is not deployed in the configuration covered by that certificate, and Cryptnox does not claim any FIPS certification at this stage. On-card RSA-4096 for Windows / Active Directory smart-card logon, S/MIME, document signing and EAP-TLS VPN. PIV only — no FIDO2 or MIFARE. Blank white PVC face for in-house ID printing.
ORDERS TO THE EU & US SHIP DIRECTLY FROM THE EU & US VIA FULFILLMENT BY AMAZON – NO IMPORT DUTIES
CHF 27.54
Tax included. Shipping calculated at checkout.
The Cryptnox PIV White PVC card is a dedicated PIV smart card — a Swiss-engineered NFC / contact smart card that runs a single applet, PIV, and. The PIV applet is built from the same codebase that was certified under FIPS 140-3 (NIST CMVP certificate #5280). It is not deployed in the configuration covered by that certificate, and Cryptnox does not claim any FIPS certification at this stage. It generates RSA-4096 keys on-card for government-grade identity: Windows / Active Directory smart-card logon, S/MIME, document signing and certificate-based VPN. No FIDO2, no MIFARE — pure PIV.
The applet ships blank for customer personalization, with a decoupled PIV admin key so an integrator can load keys, certificates and PINs without the issuer’s card-management key.
Choose this card when you need a PIV credential and nothing else. If you also need passwordless / 2FA web sign-in, see the FIDO2 + PIV card; if you also need physical building access, see the FIDO2 + PIV + MIFARE card.
The face of this card ships blank — ready for any standard PVC ID card printer (Zebra, Evolis, Fargo, Magicard, Matica). Print your company logo, employee photo, name, department or QR code on each card. Typical buyers are IT teams standardizing on smart-card hardware for AD logon and digital signatures.
The PIV applet conforms to NIST FIPS 201-3 and SP 800-73-4, and works with the Windows native smart-card mini-driver (Base CSP), PKCS#11 middleware and OpenSC; it is suitable for PIV-I (interoperable) credentialing. On macOS the card is available via CryptoTokenKit or OpenSC; on Linux via OpenSC / PKCS#11.
The blank White PVC surface is dimensioned to standard CR80 ID card printer specs:
For volumes of 500+ or pre-printed batches (1,000+ cards), get in touch via our contact form.
FIPS 140-3: The PIV applet is built from the same codebase that was certified under FIPS 140-3 (NIST CMVP certificate #5280). It is not deployed in the configuration covered by that certificate, and Cryptnox does not claim any FIPS certification at this stage. Card management uses SCP03. Each part of the card is also certified independently. Chip / platform certifications (NXP JCOP 4.5 on P71D600, Java Card platform):
Applet certification:
Cryptography: the PIV applet generates RSA-4096 / RSA-2048 / ECC P-256 / P-384 keys on-card, and private keys never leave the secure element.
The PIV applet is built from the same codebase that was certified under FIPS 140-3 (NIST CMVP certificate #5280). It is not deployed in the configuration covered by that certificate, and Cryptnox does not claim any FIPS certification at this stage. The underlying P71D600 platform is additionally certified to Common Criteria EAL6+ (NSCIB-CC-2300127-02).
This is a dedicated PIV card — it runs only the PIV applet, with no FIDO2 and no MIFARE. It is the most economical way to deploy a PIV smart-card credential for Windows / Active Directory logon and digital signing. If you also need passwordless / 2FA web authentication, choose the FIDO2 + PIV card; if you additionally need physical building access, choose the FIDO2 + PIV + MIFARE card. All three share the same PIV applet with on-card RSA-4096.
It turns the card into a government-grade PIV smart card. It implements the NIST SP 800-73-4 PIV standard with the four standard key slots (9A authentication, 9C digital signature, 9D key management, 9E card authentication) and supports RSA-4096 as well as RSA-2048 and ECC P-256 / P-384. Keys are generated on-card, so the private key never leaves the secure element. That lets the card handle Windows / Active Directory smart-card logon (Kerberos PKINIT), S/MIME email signing and encryption, document and code signing, and certificate-based VPN or Wi-Fi (EAP-TLS).
The PIV applet ships installed but blank — no PINs, keys or certificates until your IT team personalizes it. To make integration easier, the PIV admin channel uses a dedicated, decoupled key (a separate GP Security Domain) rather than the issuer’s card-management key, so an integrator can load PIV keys, certificates and PINs without the master key; re-key it to a secret if you want gated PIV administration. For volume provisioning or pre-printed cards, use the Cryptnox contact form.
The PIV applet conforms to NIST FIPS 201-3 / SP 800-73-4 and works with the Windows native smart-card mini-driver (Base CSP), PKCS#11 middleware and OpenSC, and is suitable for PIV-I (interoperable) credentialing. On Windows 10/11 it supports native smart-card logon; on macOS it is available via CryptoTokenKit or OpenSC; on Linux via OpenSC / PKCS#11. Use the card in its contact (ISO 7816) interface through any standard USB CCID smart-card reader. The card itself is an NFC / contact smart card, not a USB security key.