808bits

YubiKey 5 Cryptographic Module

FIPS 140-2 certificate #3907 · Yubico, Inc. · data as of 2026-09-15

YubiKey 5 Cryptographic Module, from Yubico, Inc., holds FIPS 140-2 certificate #3907 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode, installed, initialized, and configured as specified in Section 3 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.

Certificate

Certificate number3907
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentSingle Chip
VendorYubico, Inc. · website
Hardware versionsSLE78CLUFX3000PH and SLE78CLUFX5000PH
Firmware versions5.4.2 and 5.4.3

Module description

Quoted from the NIST CMVP entry for this certificate.

The YubiKey 5 cryptographic module is a secure element that supports multiple protocols designed to be embedded in USB and/or NFC security tokens. The module can generate, store, and perform cryptographic operations for sensitive data and can be utilized via an external touch-button for Test of User Presence. The module implements several major functions - Yubico One Time Password (OTP), FIDO/FIDO2, FIDO/U2F, PIV-compatible smart card, OpenPGP smart card, and OATH OTP authentication.

Security level exceptions

  • Physical Security: Level 3
  • EMI/EMC: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (13)

AlgorithmCAVP certificates
AESC1680
CKGvendor affirmed
CVLC1680
DRBGC1680
ECDSAC1680
HMACC1680
KAS-SSCvendor affirmed
KBKDFC1680
KDAvendor affirmed
KTS
RSAA985
SHSC1680
Triple-DESC1680

Allowed algorithms

EC Diffie-Hellman (shared secret computation provides between 128 and 256 bits of encryption strength); NDRNG; RSA (CVL Cert. #C1680, key unwrapping; key establishment provides between 112 and 150 bits of encryption strength); RSA (key unwrapping; key establishment provides between 112 and 150 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2021-04-22InitialAcumen Security
2021-08-19UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-04-22, 2021-08-19

Source documents