808bits

ID-One PIV on Cosmo V8.1

FIPS 140-2 certificate #2986 · Oberthur Technologies · data as of 2026-09-12

ID-One PIV on Cosmo V8.1, from Oberthur Technologies, holds FIPS 140-2 certificate #2986 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and initialized to Overall Level 2 per Security Policy

Certificate

Certificate number2986
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentSingle Chip
VendorOberthur Technologies · website
Hardware versionsP/Ns ‘30-5F01’ [1], ‘30-5F02’ [2], '40-6001' [3] and ’40-6002’ [4]
Firmware versionsFirmware Extension: ‘086294’+’086683’ (ID-One PIV Applet Suite 2.4.0 on Cosmo V8.1 LARGE) [1], Firmware Extension: ‘090191’ (ID-One PIV 2.4.1 on Cosmo V8.1 LARGE) [2], Firmware Extension: ‘086294’+’086693’ (ID-One PIV Applet Suite 2.4.0 on Cosmo V8.1 STD) [3] and Firmware Extension: ‘090211’ (ID-One PIV 2.4.1 on Cosmo V8.1 STD) [4]

Module description

Quoted from the NIST CMVP entry for this certificate.

ID-One PIV on Cosmo V8.1 is the next generation of Personal Identification and Verification cards. It has an AES-256 Security Architecture and support both contact and contactless communications. It supports all features described in FIPS 201-2, SP800-73-4 and SP800-76-2 including Virtual Contact Interface and fingerprint on-card comparison. It can be used as a Smart Card (PIV/CIV) to provide physical and logical access control, or embedded in a hardware token for Derived Credentials. Its additional SAM capabilities make it the ideal portable HSM for the post-issuance management of PIV cards.

Security level exceptions

  • Cryptographic Module Specification: Level 3
  • Roles, Services, and Authentication: Level 3
  • Physical Security: Level 4
  • EMI/EMC: Level 3
  • Design Assurance: Level 3

Approved algorithms (12)

AlgorithmCAVP certificates
AES4107, 4108, 4109
CVL921, 953, 954
DRBG1234
ECDSA933
HMAC2683
KAS48
KBKDF106
KTS
RSA2252, 2253
SHA-36
SHS3379, 3380
Triple-DES2245

Allowed algorithms

NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-08-10InitialUL Verification Services, Inc.
2017-11-09UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-08-10, 2017-11-09

Source documents