808bits

YubiKey 5 Cryptographic Module

FIPS 140-3 certificate #5291 · Yubico, Inc. · data as of 2026-08-28
Active. Sunset date 2031-05-21, 1726 days away.
Caveat: When operated in approved mode; When installed, initialized and configured as specified in Section 11.1 of the Security Policy; No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.

Certificate

Certificate number5291
StandardFIPS 140-3
Statusactive
Sunset date2031-05-21
Overall level2
Module typeHardware
EmbodimentSingleChip
VendorYubico, Inc. · website

Module description

The YubiKey 5 Cryptographic Module (the module) is a single-chip module validated at FIPS 140-3 Security Level 2. The module is a secure element that supports multiple protocols designed to be embedded in USB and/or NFC security tokens. The module can generate, store, and perform cryptographic operations for sensitive data and can be utilized via an external touch-button for Test of User Presence in addition to PIN for smart card authentication. The module implements several major functions - FIDO, PIV-compatible smart card, OpenPGP smart card, OATH authentication, Security Domain, and YubiHSM Auth.

Security level exceptions

  • Operational environment: N/A
  • Physical security: Level 3
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Validation history

DateTypeLab
2026-05-22InitialPenumbra Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2026-05-22

Source documents