Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #3914


Module Name
YubiKey 5 Cryptographic Module
FIPS 140-2
Sunset Date
Overall Level
When operated in FIPS mode, installed, initialized, and configured as specified in Section 3 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.
Security Level Exceptions
  • Physical Security: Level 3
  • EMI/EMC: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Module Type
Single Chip
The YubiKey 5 cryptographic module is a secure element that supports multiple protocols designed to be embedded in USB and/or NFC security tokens. The module can generate, store, and perform cryptographic operations for sensitive data and can be utilized via an external touch-button for Test of User Presence in addition to PIN for smart card authentication.The module implements five major functions - Yubico One Time Password (OTP), FIDO2, PIV-compatible smart card, OpenPGP smart card and OATH OTP authentication.
Tested Configuration(s)
  • N/A
Approved Algorithms
AES Cert. #C1680
CKG Vendor Affirmed
CVL Cert. #C1680
DRBG Cert. #C1680
ECDSA Cert. #C1680
HMAC Cert. #C1680
KAS-SSC Vendor Affirmed
KBKDF Cert. #C1680
KDA Vendor Affirmed
KTS AES Cert. #C1680
KTS AES Cert. #C1680 and AES Cert #C1680
KTS AES Cert. #C1680 and HMAC Cert. #C1680
RSA Cert. #A985
SHS Cert. #C1680
Triple-DES Cert. #C1680
Allowed Algorithms
EC Diffie-Hellman (shared secret computation provides between 128 and 256 bits of encryption strength); NDRNG; RSA (CVL Cert. #C1680, key unwrapping; key establishment provides between 112 and 150 bits of encryption strength); RSA (key unwrapping; key establishment provides between 112 and 150 bits of encryption strength)
Hardware Versions
Firmware Versions
5.4.2 and 5.4.3


Yubico, Inc.
530 Lytton Ave
Suite 301
Palo Alto, CA 94301

Jakob Ehrensvard
Phone: +1 650-283-1537

Validation History

Date Type Lab
5/3/2021 Initial ACUMEN SECURITY, LLC
8/19/2021 Update ACUMEN SECURITY, LLC