Cryptnox SA

Cryptnox FIDO2 Card — Hardware Security Key for 2FA, MFA & Passwordless

The Cryptnox FIDO2 card is the entry-level NFC smart card in our FIDO2 lineup — a single-application FIDO2 security card, FIDO Alliance Certified (FIDO2 v2.1 + CTAP Level 1) for 2FA / MFA on Google, Microsoft, Apple, GitHub, login.gov, AGOV, SwissID, and any FIDO2/WebAuthn service. Supports passwordless sign-in where services enable it. NFC + contact (ISO 7816) dual interface. No battery, no charging, no Cryptnox-specific software for daily use on Windows, iOS, Android U2F flows, or supported macOS/browser combinations. Linux FIDO2 sign-in requires the open-source Cryptnox FIDO2 HID bridge.

ORDERS TO THE EU SHIP DIRECTLY FROM THE EU – NO IMPORT DUTIES

 39.00

Tax included. Shipping calculated at checkout.

Description

Customer rating: ★★★★☆ 4.2 / 5 — based on 250 Amazon customer reviews. Read on Amazon.

The Cryptnox FIDO2 card is the entry-level NFC smart card in our FIDO2 lineup — a single-application FIDO2 security card with Cryptnox branding, designed for individuals and small teams who want a phishing-resistant hardware authenticator in a wallet-friendly form factor. FIDO Alliance Certified (FIDO2 v2.1 and CTAP Level 1), the card is primarily used as a hardware 2FA / MFA second factor on every major FIDO2 / WebAuthn service, with passwordless sign-in supported on the smaller set of services that have explicitly enabled FIDO2-only login (Microsoft Entra ID, Google Workspace, login.gov, AGOV, SwissID, and others).

Tap to authenticate — on phone or computer

The Cryptnox FIDO2 card supports both NFC and contact (ISO 7816) interfaces, so you can use it however your workflow demands:

  • On a phone: tap the card against the NFC area (typically the upper back of the device). On iPhone 7+ running iOS 13.3+, the card supports FIDO2 over NFC; on Android, external NFC keys are supported mainly as CTAP1 / U2F second-factor authenticators, not for full FIDO2 / passwordless flows.
  • On a desktop or laptop: use either a contactless smart card reader (place the card on the reader pad) or a contact reader (insert the card into the slot).

For Windows desktop users who sign in with FIDO2 via the contact interface, the Cryptnox dual-slot contact Smartcard Reader features a dedicated “tap” button that electronically simulates card extraction and reinsertion. When a FIDO2 service prompts you to “tap your security key,” press the button — no need to physically pull the card out and push it back in. (Tap button feature is Windows-only.) See our click-to-tap tutorial for the full FIDO2 sign-in workflow.

Why a FIDO2 card instead of a FIDO2 USB key?

A FIDO2 card delivers the same cryptographic security as a USB security key — phishing-resistant, hardware-backed, with private keys that never leave the chip’s secure element — in a credit-card form factor that fits in any wallet cardholder. No keychain dongle hanging off your laptop, no USB port hassle, no charging required.

How this FIDO2 card differs from the rest of our FIDO2 lineup

  • This card (FIDO2 basic): single-function FIDO2 only, Cryptnox-branded face, our most affordable entry point — ideal for individuals adopting 2FA / MFA for the first time.
  • FIDO2 + MIFARE DESFire card: adds a second applet for physical access control on the same chip — for users who also want to open office doors with the same credential.
  • FIDO2 White PVC: the same FIDO2 card with a blank, printable face — for organizations that customize cards with employee photos, logos, or department branding.
  • FIDO2 White PVC 25-pack: bulk pricing for IT teams deploying FIDO2 across an organization.

What does FIDO2 mean?

FIDO2 is the modern open authentication standard (WebAuthn + CTAP2) that delivers phishing-resistant strong authentication. Most services use FIDO2 cards as a hardware second factor — sign in with your password as usual, then tap the card to confirm. A growing set of services (Microsoft Entra ID, Google Workspace, login.gov, AGOV) also support FIDO2-based passwordless / passkey-style sign-in, where the card replaces the password entirely. Backed by the FIDO Alliance — a consortium including Google, Microsoft, Apple, Amazon, and major banks — FIDO2 is the foundation of modern hardware-backed authentication on the web.

Features

Built for hardware-backed 2FA / MFA on every major service

The Cryptnox FIDO2 card works as a hardware second factor on any service that supports the FIDO2 / WebAuthn / U2F standards — which is now nearly every major online platform. Passwordless sign-in is supported on the subset of services that have explicitly enabled FIDO2-only login flows.

  • Personal accounts: Google, Microsoft, Apple ID, Facebook, X, Dropbox, Bitwarden, 1Password
  • Financial services: supported where the service offers WebAuthn / FIDO2 security-key enrollment (Bank of America, supported crypto exchanges). PSD2 SCA acceptance for external FIDO2 keys varies by bank — verify with your specific bank before purchase.
  • Government identity: login.gov (US), AGOV (Switzerland), SwissID
  • Compliance environments: helps implement phishing-resistant MFA aligned with OMB M-22-09 (US federal agencies), NIS2, DORA, NIST SP 800-63B AAL3, and PCI DSS v4 — final compliance depends on the organization’s architecture and assessment

Why hardware authentication matters

Software passkeys are convenient and may sync through cloud ecosystems (iCloud Keychain, Google Password Manager). A hardware FIDO2 card keeps credentials hardware-bound inside the card’s tamper-resistant secure element — not cloud-synced, not remotely exportable, not clonable by a phished attacker. For PIN-protected FIDO2 / passwordless flows, an attacker would need both physical possession of the card and the PIN; for second-factor flows, they would typically also need the account password.

Easy to use, easy to deploy

  • Tap to authenticate on any NFC-capable phone (iOS for full FIDO2; Android for CTAP1 / U2F second-factor)
  • Contact mode for desktop: insert into any USB CCID-class smart card reader; for a smoother flow on Windows, use the Cryptnox dual-slot Smartcard Reader with its dedicated tap button (Windows only)
  • Contact mode — works through any standard USB CCID smart-card reader on Windows and supported macOS/browser combinations; Linux FIDO2 sign-in additionally requires the open-source Cryptnox FIDO2 HID bridge
  • No charging — passive NFC, no battery, equivalent lifespan to any contactless card
  • No app required for daily use — register once on each service through the standard browser flow

When to choose the Cryptnox-branded version vs the blank White PVC

This branded version is the entry-level option for individuals or pilot deployments. If you need to print employee photos or company logos on the cards, see the FIDO2 White PVC variant instead.

For setup walkthroughs, integration guides, and service-specific tutorials (Google, Microsoft, Apple, GitHub, Bank of America, login.gov, AGOV, SwissID), browse our FIDO2 tutorials hub.

Specifications

Technical specifications

  • Form factor: ISO/IEC 7810 ID-1 (CR80, credit-card size)
  • Interface: NFC (ISO/IEC 14443 Type A) + contact (ISO 7816)
  • Certification: FIDO Alliance Certified — FIDO2 v2.1 and CTAP Level 1
  • Standards supported: WebAuthn, CTAP2, FIDO U2F (legacy)
  • Secure element: NXP JCOP 4.5 on P71D600 — Common Criteria EAL 5+ augmented with AVA_VAN.5; FIPS 140-3 Overall Level 3 with Physical Security Level 4
  • Power: passive — no battery, energy harvested from the NFC reader’s RF field
  • Operating systems: Windows 10/11 — full FIDO2; iPhone 7+ / iOS 13.3+ — FIDO2 over NFC; Android — external NFC keys mainly via CTAP1 / U2F second-factor (not full FIDO2 / passwordless); macOS — FIDO2 over NFC varies by version and browser; Linux — FIDO2 sign-in requires the Cryptnox FIDO2 HID bridge
  • Applications: single-application FIDO2 / WebAuthn authenticator only — no MIFARE, no DESFire, no physical-access-control applet
  • Card face: Cryptnox-branded printed face — for a blank printable card, see the FIDO2 White PVC variant
  • Resident credentials: 64 resident-key slots for FIDO2 discoverable credentials / passkey-style deployments
  • Engineering: firmware designed in Switzerland by Cryptnox SA

Compliance

  • FIDO Alliance Certified
  • FIDO2 v2.1 + CTAP Level 1
  • ISO/IEC 7810 (card form factor)
  • ISO/IEC 7816 (contact interface)
  • ISO/IEC 14443 (NFC interface)

Certifications

Chip platform certifications (NXP JCOP 4.5 on P71D600):

  • Common Criteria EAL 5+ augmented with AVA_VAN.5 (highest vulnerability-analysis tier) — NSCIB-CC-0313985
  • FIPS 140-3 Overall Level 3 with Physical Security at Level 4 — NIST CMVP certificate #4679 (validated 2025)
  • AIS-31 compliant True Random Number Generator (chip-level)

Applet certification:

  • Cryptnox FIDO2 / U2F applet: FIDO Alliance Certified — FIDO2 v2.1 + CTAP Level 1

Supported elliptic curve (FIDO2 applet):

  • NIST P-256 (P-256 r1) only — the chip platform supports additional curves, but the FIDO2 applet exposes only NIST P-256

Frequently Asked Questions

What is a FIDO2 security key?

A FIDO2 security key is a hardware authenticator that replaces or supplements passwords using public-key cryptography. Instead of typing a password that can be phished or stolen in a data breach, you tap or insert a physical device that proves your identity with a cryptographic signature — the private key never leaves the card’s secure element. This Cryptnox FIDO2 card is certified to the FIDO2 standard (WebAuthn + CTAP2) and also supports the older U2F protocol, so it works with every major service that accepts either, from Google and Microsoft to Bank of America, GitHub, login.gov, AGOV, and SwissID.

How does this card differ from the FIDO2 + MIFARE version?

Same FIDO2 applet certification (FIDO Alliance Certified — FIDO2 v2.1 + CTAP Level 1), same web-authentication behavior, and same FIDO2 / WebAuthn service compatibility. The chip platform differs: FIDO2-only cards use NXP JCOP 4.5 on P71D600, while FIDO2 + MIFARE cards use JCOP 4 on P71D321 to support the DESFire EV2 applet. The difference is function:

  • This card (FIDO2 only): WebAuthn / FIDO2 and U2F authentication for online accounts — primarily hardware 2FA / MFA, with passwordless sign-in on services that explicitly support FIDO2 / passwordless flows.
  • FIDO2 + MIFARE DESFire card: adds a second firmware application on the same chip for physical access control (building doors, elevators, printers, time-clocks).

If you only need web 2FA and passwordless sign-in, the basic card is simpler and more affordable. If you also want one credential to open your office door, go with the FIDO2 + MIFARE version.

How do I register this FIDO2 key with my accounts?

Every major service follows the same flow:

  1. Sign in to your account (Google, Microsoft, Apple, Facebook, GitHub, etc.)
  2. Go to Security settings → Two-step verification / Security keys / Passkeys
  3. Click “Add security key” or “Add passkey”
  4. Tap the card against your phone’s NFC area, or place it on a contactless reader connected to your computer
  5. Follow the prompt to set a PIN (if required) and name the key

Registration takes 10–30 seconds per account. You can register the same card with many services — it stores a separate cryptographic key pair for each one, so no two services can link your identities through the card.

OS and browser compatibility: iOS supports FIDO2 over NFC on iPhone 7 or later running iOS 13.3 or later. Android currently supports only CTAP1 / U2F (FIDO1) for external NFC keys — not FIDO2 / CTAP2. Most major services maintain CTAP1 backward compatibility, so the card works as a U2F second-factor authenticator on Android, but the feature set is reduced and CTAP1 implementations vary. macOS FIDO2-over-NFC support varies by version and browser. Linux browsers expect FIDO2 authenticators on a HID interface — use the Cryptnox FIDO2 HID bridge to present the card to the browser as an HID-FIDO device. Windows 10/11 has full FIDO2 support across all major browsers. Always test with your specific OS + browser + service before committing to a production deployment.

Is this a FIDO Certified security key? Which compliance frameworks accept it?

Yes — this is a FIDO Certified FIDO2 security key (FIDO2 v2.1 and CTAP Level 1, WebAuthn + passkey support, with legacy U2F backward compatibility). FIDO certification is often a prerequisite or recognized building block for regulatory frameworks that require phishing-resistant hardware MFA:

  • US federal agencies — OMB M-22-09 explicitly names FIDO2 / WebAuthn as acceptable phishing-resistant authentication (acceptance for a specific deployment depends on the agency’s authenticator policy and audit context)
  • DoD contractors — CMMC 2.0 requires phishing-resistant MFA at higher maturity levels
  • US government deployments — NIST SP 800-63B AAL3 lists FIDO2 hardware authenticators
  • EU critical infrastructure — NIS2 requires strong authentication for essential and important entities
  • EU financial services — DORA requires operational resilience with phishing-resistant MFA
  • Payments — PCI DSS v4 MFA requirement for cardholder data environments
  • Consumer banking — some banks and exchanges now support external FIDO2 security keys (Bank of America, supported crypto exchanges, and others); coverage varies by institution — verify with your specific bank before purchase

If you need a documented FIDO Certified security key for a compliance deployment, or a hardware authenticator for personal use on services that support external FIDO2 keys (login.gov, AGOV, supported banks), this card qualifies as FIDO Certified hardware — final acceptance at any specific service should be verified with that service.

How do I choose the best FIDO2 security key for my needs?

“Best” depends on your priorities:

  • Portability in your wallet: card format (this product) — fits in your cardholder, works with any NFC phone, no dongle hanging off your keychain
  • Ruggedness on a keyring: metal dongle format USB / NFC keychain authenticators — built to survive keychain abuse at the cost of size and wallet-friendliness
  • Budget: this card is priced as an entry point to FIDO Certified hardware, affordable for individuals and for teams deploying FIDO2 at scale
  • Compliance-driven procurement: a traceable, documented manufacturer matters — Cryptnox firmware is designed in Switzerland by Cryptnox SA
  • Combined with physical access: if you also need one credential to open your office door, pick the FIDO2 + MIFARE DESFire version instead of the basic card

The card works with every FIDO2-compliant service — from Google, Microsoft, Apple, Bank of America, and login.gov to the Swiss AGOV and SwissID portals — so “best” really comes down to form factor, price, and whether you need dual-application (web auth + building access).

What can the Cryptnox FIDO2 app do?

The Cryptnox FIDO2 app can change the card PIN, factory reset the card, and manage resident keys (list, register, delete). It cannot migrate credentials to another card because FIDO2 private keys are generated and stored inside the secure element and never leave the card. For daily sign-in, the app is not required — registration on each service is done through the standard browser flow.

Is the Cryptnox FIDO2 card FIPS 140-3 certified?

The Cryptnox FIDO2 applet itself is FIDO Alliance Certified (FIDO2 v2.1 + CTAP Level 1). The underlying secure-element platform on this single-application FIDO2 product (NXP JCOP 4.5 on P71D600) is FIPS 140-3 Overall Level 3 validated with Physical Security at Level 4 — NIST CMVP certificate #4679, validated in 2025. FIPS 140-3 is the latest NIST cryptographic-module standard (it superseded FIPS 140-2 in 2026). The FIDO2 applet does not carry a separate FIPS certification.

What Common Criteria certification does this card carry?

The underlying NXP secure-element platform (JCOP 4.5 on P71D600) is Common Criteria EAL 5+ augmented certified, with AVA_VAN.5 (the highest vulnerability-analysis tier in CC) — Netherlands scheme NSCIB-CC-0313985. AVA_VAN.5 is the same vulnerability-analysis level required for EAL 6+ certifications. The Cryptnox FIDO2 applet runs on top of this certified platform.

Which elliptic curve does the Cryptnox FIDO2 applet use?

The Cryptnox FIDO2 applet performs all cryptographic signing on NIST P-256 (P-256 r1), the curve mandated by the FIDO2 / WebAuthn specification. The underlying chip platform supports additional curves (Brainpool 224/256/320/384/512, NIST P-224 / P-384 / P-521, and Secp256k1) on its ECC coprocessor, but the FIDO2 applet exposes only NIST P-256 to remain spec-compliant.

Select your currency
0
    0
    Shopping cart
    Your cart is emptyReturn to Shop