Deploying the YubiKey 5 FIPS Series

The YubiKey 5 FIPS Series chipset firmware 5.7.4 is certified under FIPS 140-3 Overall Level 2, Physical Security Level 3.

Physical Security Level 3 provides both tamper-evidence and tamper-resistance. In turn, this means the YubiKey 5 FIPS Series keys can be used in an Overall Security Level 1 or 2 environment without issue.

See NIST SP 800-63-B for guidance on the level required for your deployment.

New and Existing FIPS Deployments

New FIPS compliant submissions must fulfill the FIPS 140-3 requirements. Use YubiKey 5 FIPS Series firmware 5.7.4.

Existing deployments can continue with YubiKey 5 FIPS Series keys firmware 5.4.2 and 5.4.3, certified under FIPS 140-2 Level 1 and FIPS 140-2 Level 2

Note

YubiKey 5 FIPS Series 5.4.x FIPS 140-2 certification moved to the Sunset List, May 2026 and will be moved to the Historical List, September 22, 2026. Existing FIPS 140-2 deployments can continue after sunset.

The YubiKey 5 FIPS Series keys firmware 5.4.2 and 5.4.3, certified under FIPS 140-2 Level 1 and FIPS 140-2 Level 2, have two certificates, each corresponding to a different level of certification, but both certificates apply to the same keys.

Depending on which certification the YubiKey 5 FIPS Series is being deployed under, there are different requirements and initialization steps for securing the various functions. Each version requires more stringent initialization than the previous level. See the topic for the FIPS version you are using: