Best Hardware Security Keys (YubiKey) for Protecting Business Accounts | SmartStackHubPro
Security · Identity · Hardware

Best Hardware Security Keys (YubiKey) for Protecting Business Accounts

Operational guide to the best hardware security keys for business accounts: comparison of YubiKey 5, Security Key and FIPS Series, FIDO2 vs U2F differences, enterprise deployment and use cases.

YubiKey 5 Security Key FIDO2 FIPS 140-3
✓
The short answer

For most businesses, the YubiKey 5 NFC or YubiKey 5C NFC is the most consistent choice: it supports all protocols (FIDO2, U2F, PIV, OpenPGP, OATH-TOTP, Yubico OTP) and covers both modern cloud applications and legacy systems. For those who need only FIDO2/WebAuthn, the Security Key Series is cheaper and sufficient. For regulated environments (government, defence, healthcare, finance), the YubiKey 5 FIPS Series certified FIPS 140-3 is the only compliant choice. Regardless of model, the operational rule is two keys per employee, one primary and one backup.

Passwords are no longer enough. Two-factor authentication with SMS is vulnerable to SIM swapping. Authenticator apps (TOTP) are better, but remain vulnerable to real-time phishing: an attacker can replicate a login page and ask for the code, which the user will provide believing they are on the right site. Hardware security keys eliminate this vulnerability by architecture: they authenticate the user only if the requesting domain exactly matches the registered one.

Yubico is the reference manufacturer in this category. Its keys are used in over 160 countries and are the de facto standard for phishing-resistant authentication in businesses. This guide analyses the different YubiKey series, the differences between FIDO2 and U2F, the FIPS certifications for regulated environments, and enterprise deployment practices.

The regulatory and security landscape has changed significantly between 2025 and 2026. NIST published the final version of SP 800-63B-4 in July 2025, which defines the technical requirements for the three Authentication Assurance Levels. W3C published WebAuthn Level 3 as an official Recommendation in August 2026, stabilising the standard on which passkeys and hardware keys are based. ENISA recognised passkeys as the strongest phishing-resistant MFA method in its technical guidance for NIS2 published in June 2025. And the FIDO Alliance published guidance for FIDO authentication deployment in US government agencies in March 2025.

If you are building a complete security architecture for your business, complete your reading with our comparison of ProtonVPN vs NordVPN for privacy and the guide on how to protect business data on public Wi-Fi.

FIDO2 U2F PIV OpenPGP FIPS 140-3

Editorial and affiliate note

General information. The content of this article, including references to prices, features and certifications of the products mentioned, is published for informational and educational purposes. SmartStackHubPro.com does not provide legal, technical or cybersecurity advice. Product conditions change frequently: always verify updated information on the official websites of the respective manufacturers before making decisions.

Affiliate transparency. Some links in this article may be affiliate links. If you purchase through these links, SmartStackHubPro may receive a commission at no additional cost to you. This does not influence the editorial selection, which follows criteria of practical utility and consistency with the operational stack of international professionals.

01 · The problem

Why passwords and TOTP apps are no longer enough

Business account breaches almost never happen through sophisticated technical attacks. They happen through phishing, social engineering and credential reuse. Hardware security keys are the only authentication method that resists these threats by architecture, not by configuration.

01

TOTP apps are vulnerable to phishing

A TOTP code generated by an app is valid for a short period, but can be intercepted in real time. An attacker replicating a login page can ask the user for the code and use it immediately. A hardware key does not have this problem: it authenticates only if the requesting domain exactly matches the registered one.

02

SMS is insecure by design

SIM swapping and mobile network interception make SMS inadequate for business authentication. NIST SP 800-63B-4 classifies SMS as “restricted” and recommends against using it for high-risk authentication. Hardware keys are the designated alternative for AAL3.

03

Reused passwords are a systemic risk

A single breach on a consumer service can compromise business access if the same password is reused. Hardware keys eliminate this dependency: even if the password is compromised, access requires the physical key.

SmartStackHubPro Insight The real cost of a compromised account far exceeds the cost of hardware keys.

A single compromised business account can cost hundreds of thousands of euros in stolen data, remediation, reputational damage and potential regulatory fines. The MGM Resorts incident of 2023 had an estimated impact of $100 million. The cost of equipping a team of 100 people with two YubiKeys each is a few thousand euros. The ROI of hardware security is one of the highest in enterprise IT.

02 · FIDO2 vs U2F

FIDO2, U2F and WebAuthn: what they mean and which to use

When talking about hardware security keys, the terms FIDO2, U2F, WebAuthn and CTAP are often used interchangeably. They are not. Understanding the difference is essential to choose the right model and configure the deployment correctly.

U2F: the predecessor

U2F (Universal 2nd Factor) is the previous standard, designed only for two-factor authentication. It adds a second factor to a login with username and password: the user provides credentials and then touches the key to confirm. U2F does not support passwordless authentication: the password remains necessary. U2F is still supported for backward compatibility, but is considered superseded.

Important note: on YubiKey 5 FIPS Series devices with firmware 5.7.x and FIPS 140-3 certification, U2F is disabled. Only FIDO2 is used. This is a change introduced with FIPS 140-3: the U2F function is no longer available on these devices.

FIDO2 and WebAuthn: the current standard

FIDO2 is the current standard and supports both two-factor authentication and passwordless authentication. WebAuthn is the W3C specification that defines the interface between the browser and the authenticator (the key). CTAP is the protocol that defines the communication between the browser and the key itself. WebAuthn Level 3 became an official W3C Recommendation on 25 August 2026, definitively stabilising the standard.

With FIDO2, the key can completely replace the password. The user touches the key and authenticates, without typing anything. FIDO2 also supports resident credentials (also called device-bound passkeys), which allow login without even entering a username: the key remembers the credentials associated with the site. According to the FIDO Alliance guidance for US government deployment, device-bound passkeys can satisfy both AAL3 and AAL2, while synchronised passkeys are limited to AAL2.

How many resident credentials can a YubiKey hold?

The number of resident credentials (passkeys) a YubiKey can hold depends on the firmware and model. YubiKey 5 Series with firmware 5.7.x and later supports up to 100 device-bound passkeys, a significant increase from the 25 of previous firmware. This number is relevant for enterprise deployment: if each employee must register the key on dozens of business services, the capacity must be sufficient.

Operational reading: for new deployments, always configure FIDO2 as the primary method. U2F should be considered only for backward compatibility with legacy systems. On FIPS 140-3 devices, U2F is not available: everything goes through FIDO2.
03 · Models

YubiKey 5 Series, Security Key Series, FIPS Series and Bio Series

Yubico produces four main families of keys. The choice depends on the level of security required, the protocols needed, and the regulated environments in which the business operates.

Series Supported protocols Certifications Ideal for
YubiKey 5 SeriesFIDO2, U2F, PIV, OpenPGP, OATH-TOTP/HOTP, Yubico OTP, static passwordsFIDO L1/L2, IP68Most businesses: complete cloud + legacy coverage
Security Key SeriesFIDO2, U2FFIDO L1/L2Businesses using only modern cloud services (Google, Microsoft 365, Okta)
YubiKey 5 FIPS SeriesFIDO2, PIV, OpenPGP, OATH (U2F disabled on 140-3)FIPS 140-3 Level 2, Physical Security Level 3Government, defence, healthcare, finance, regulated environments
YubiKey Bio SeriesFIDO2FIDO L1/L2Businesses wanting biometric authentication on FIDO2

YubiKey 5 Series: the Swiss army knife

The YubiKey 5 Series is the most versatile choice: it supports all protocols, including PIV (smart card), OpenPGP, OATH-TOTP, Yubico OTP and static passwords. This makes it suitable for both modern cloud authentication (FIDO2) and legacy systems requiring smart cards or OTP.

Main models: YubiKey 5 NFC (USB-A + NFC), YubiKey 5C NFC (USB-C + NFC), YubiKey 5 Nano (USB-A, ultra-compact form), YubiKey 5C Nano (USB-C, ultra-compact form), YubiKey 5Ci (USB-C + Lightning for iPhone/iPad).

Indicative 2026 prices: from around $58 for the YubiKey 5C NFC to around $85 for the YubiKey 5Ci.

Security Key Series: the essentials at a contained cost

The Security Key Series supports only FIDO2 and U2F. It has no PIV, OpenPGP, OATH-TOTP or Yubico OTP. It is sufficient for most cloud accounts (Google Workspace, Microsoft 365, Okta, GitHub, AWS), but does not cover legacy systems requiring smart cards or hardware OTP.

When to choose it: if your business uses exclusively modern cloud services with FIDO2 support, the Security Key Series is cheaper and more than sufficient. If you need to cover legacy VPNs, digital signatures or SSH with OpenPGP, you need the YubiKey 5 Series.

YubiKey Bio Series: biometric authentication on FIDO2

The YubiKey Bio Series adds a fingerprint reader to the key. Authentication happens with the fingerprint, with the option to use a PIN as backup. It is certified FIDO2 and supports services such as Bitwarden, Okta, Google and Microsoft.

When to choose it: if your business wants a passwordless experience with biometric verification and does not need legacy protocols (PIV, OpenPGP, OATH). The YubiKey Bio is supported by most modern FIDO2 services.

Recommended choice

YubiKey 5 NFC or 5C NFC for most businesses

Complete coverage of all protocols, FIDO L2 and IP68 certifications, available in USB-A and USB-C.

Discover YubiKey →
04 · FIPS 140-3

FIPS 140-3: what it means and when it is required

FIPS 140-3 is the current United States government standard for cryptographic modules, aligned with the international standard ISO/IEC 19790:2012. It replaces FIPS 140-2, deprecated in May 2026. For businesses operating in regulated sectors or providing services to government entities, FIPS certification is often a contractual requirement.

YubiKey 5 FIPS Series: what it offers

The YubiKey 5 FIPS Series is certified FIPS 140-3 Overall Level 2 with Physical Security Level 3 (Certificate #5291). It is the only authenticator authorised by the US government to contain both DoD PKI credentials and FIDO2 passkeys on the same device.

Main features of firmware 5.7.4:

  • Support for RSA-3072 and RSA-4096 keys, in addition to Ed25519 and X25519
  • FIDO2, PIV and OpenPGP PINs with minimum 8 characters, complexity enabled by default
  • U2F disabled: only FIDO2 is available
  • Enterprise attestation: IdPs can read the key’s serial number during FIDO2 registration
  • Support for 100 device-bound passkeys (up from 25)
  • SCP11: secure channel based on asymmetric cryptography
  • NFC disabled in transit to prevent tampering before deployment

Who needs FIPS 140-3

FIPS 140-3 certification is required for:

  • US federal agencies and defence contractors. NIST has set 21 September 2026 as the deadline for new government systems that must use FIPS 140-3 validated cryptographic modules.
  • Businesses in regulated sectors (healthcare with HIPAA, finance with PCI-DSS, energy with NERC CIP)
  • Organisations that must comply with NIST SP 800-63B AAL3: AAL3 requires a hardware-based token resistant to verifier impersonation
  • Organisations handling classified government data

What changes with FIPS 140-3 compared to FIPS 140-2

The most significant difference is that FIPS 140-3 introduces hardware enforcement: FIPS requirements are applied directly by the YubiKey, not only by the software. The device refuses to create credentials until it is correctly configured and in FIPS Approved Mode. Once initialised in FIPS mode, the device cannot be removed from that mode without erasing all functions.

Important note for procurement: FIPS 140-2 is deprecated. Auditors recommend not deploying new installations with FIPS 140-2 certified devices. Existing FIPS 140-2 devices can continue to be used, but new deployments must have a valid, non-expired certification.

Watch out for the FIPS 140-2 → 140-3 transition

If your business needs FIPS, verify that the keys purchased are certified FIPS 140-3, not FIPS 140-2. Yubico obtained FIPS 140-3 validation for the YubiKey 5 FIPS Series in May 2026 (Certificate #5291). If you have stock of FIPS 140-2 keys, plan replacement for new deployments and future audits.

05 · Deployment

How to distribute security keys in a business

Choosing the model is only the first step. The success of a hardware key deployment depends on how enrolment, backup, recovery and lifecycle are managed. Yubico recommends registering at least two keys per employee.

The two-key rule

For each employee, register two keys: one primary (which the employee carries with them) and one backup (stored in a safe place). If the primary key is lost or damaged, the employee can use the backup key without going through a recovery process involving IT support.

Why it is essential: the account recovery process is a critical security point. If an attacker manages to manipulate IT support or the reset process, they can gain access even without the physical key. Having a backup key registered eliminates the need to resort to recovery in most cases.

Enterprise enrolment with attestation

Firmware 5.7.x introduces Enterprise Attestation: during FIDO2 registration, the Identity Provider can read the key’s serial number and other unique identifiers. This allows you to:

  • Verify that the key was issued by the business and is not a personal key
  • Associate the key with a business inventory
  • Block registration of unauthorised keys
  • Simplify asset tracking for large device fleets

Lifecycle management

Hardware keys are physical assets that require lifecycle management: issuance, distribution, replacement, revocation. For large-scale deployments, this means integrating key management into the onboarding workflow (joiner-mover-leaver) and maintaining an up-to-date inventory.

Costs at scale: for a business of 10,000 employees, equipping each person with two keys (primary + backup) involves an investment in hardware between $400,000 and $2.2 million, depending on the model chosen. This is why many businesses adopt selective deployment: hardware keys for privileged roles (admin, executive, regulated roles) and synchronised passkeys or other methods for the rest of the workforce.

Operational recommendation: start with a pilot on a small group (IT team, privileged roles, executives). Measure adoption rate, support load and UX issues. Then expand in waves. Do not roll out to the entire company on day one.
06 · Use scenarios

Which YubiKey for which type of business

This is not a ranking. It is a matrix to orient yourself based on your specific context.

Business profile Recommended model Why
Startup / SMB with cloud servicesSecurity Key C NFCOnly FIDO2 needed, contained cost
SMB with legacy VPN and smart cardsYubiKey 5 NFC or 5C NFCSupports PIV, OpenPGP and OTP in addition to FIDO2
Business with corporate iPhone/iPadYubiKey 5CiThe only model with Lightning connector
Modern laptops with USB-CYubiKey 5C NFC or 5C NanoUSB-C connector, NFC for smartphones
Large-scale enterprise deploymentYubiKey 5 NFC (USB-A)Maximum compatibility with adapters
Government, defence, regulated sectorsYubiKey 5 FIPS SeriesFIPS 140-3 certification, DoD PKI + FIDO2
Business with biometric focusYubiKey Bio SeriesFingerprint reader, FIDO2, passwordless
SmartStackHubPro Insight Roles, not rankings.

The Security Key is for those who use only modern cloud. The YubiKey 5 is for those who need complete coverage. The FIPS Series is for those operating in regulated environments. The Bio is for those who want biometric. The right question is: which protocols do I actually need, and which certification must I comply with?

07 · Common mistakes

The 5 most costly mistakes in hardware key deployment

These mistakes are not disastrous individually. They become relevant when repeated and compromise adoption or security.

01
Distributing a single key per employee

Yubico recommends two keys per employee: one primary and one backup. Without a backup, losing the primary key forces the employee to go through the recovery process, which is a critical security point and a support load. The backup key must be registered during onboarding and stored in a safe place.

02
Not configuring enrolment with attestation

Firmware 5.7.x supports Enterprise Attestation: during FIDO2 registration, the IdP can read the key’s serial number. Without this configuration, you cannot verify that the registered key is the one issued by the business. An employee could register a personal key, which the business cannot inventory or revoke.

03
Leaving weak fallback methods active

If your policy allows SMS, OTP via email or push notification as fallback methods, an attacker can force a downgrade and exploit the weaker method. Authentication is only as strong as its weakest link. The recommendation is to eliminate weak fallbacks and make the hardware path the only possible path for privileged roles.

04
Choosing FIPS 140-2 when FIPS 140-3 is required

FIPS 140-2 has been deprecated since May 2026. Auditors recommend not deploying new installations with FIPS 140-2 devices. If you need FIPS, verify that the keys purchased are certified FIPS 140-3 (Certificate #5291 for the YubiKey 5 FIPS Series).

05
Ignoring compatibility with devices in use

The choice between USB-A, USB-C and Lightning depends on the business’s devices. If laptops have USB-C, the USB-C version is more consistent. If there are corporate iPhone or iPad devices, a Lightning key is needed (only YubiKey 5Ci). Always verify compatibility before ordering in large quantities.

SmartStackHubPro Insight The most costly mistake is underestimating the operational load.

A hardware key deployment is not just a purchase: it is an operational project requiring enrolment, backup, lifecycle, support and recovery. Businesses that fail do so not because of the technical choice, but because of the lack of an operational plan. Start with a pilot, measure the load, then expand.

08 · Roadmap

The SmartStackHubPro roadmap to adopt hardware keys

A practical sequence to choose and distribute keys without inconclusive trials.

01
Define the security requirements

Which business applications must be protected? Do you need FIDO2, PIV, OpenPGP, OATH? Do you operate in a regulated sector requiring FIPS? The answers determine the YubiKey series to choose.

02
Verify compatibility with devices

Do laptops have USB-A or USB-C? Are there corporate iPhone or iPad devices (Lightning)? Do smartphones support NFC? The connector choice must be consistent with the devices in use.

03
Choose the model by profile

Security Key for cloud-only, YubiKey 5 for complete coverage, FIPS Series for regulated environments, Bio for biometric. There is no single model for all businesses.

04
Plan enrolment with two keys

For each employee: one primary key and one backup. The backup key must be registered during onboarding and stored in a safe place. Enrolment must be configured with Enterprise Attestation for inventory.

05
Test with a pilot

Choose a small group (IT, privileged roles) and test the deployment for 2-3 weeks. Measure adoption rate, support load, UX issues. Then expand in waves.

06
Measure and iterate

How many employees use the key regularly? How many need support? Is the abandonment rate acceptable? If adoption is low, the problem is the way it was introduced, not the technology.

SmartStackHubPro Insight Deployment is an operational project, not a purchase.

A successful deployment requires enrolment planning, lifecycle management, recovery support and adoption measurement. The technical choice is only the first step. The time spent planning the deployment is the most valuable.

10 · Sources

Official sources and references

The technical data and regulatory references cited in this article are based on institutional sources, research institutes and official manufacturer documentation. Always verify updated conditions on official websites before making decisions.

Show official sources
Institutional standards and guidelines
NIST — SP 800-63B-4: Digital Identity Guidelines csrc.nist.gov (official publication)
W3C — WebAuthn Level 3 Recommendation w3.org (WebAuthn L3)
FIDO Alliance — WebAuthn Level 3 is now a W3C Recommendation fidoalliance.org (official announcement)
FIDO Alliance — Guidance for U.S. Government Agency Deployment fidoalliance.org (government guidance)
ENISA — NIS2 Technical Implementation Guide enisa.europa.eu (NIS2 guidance)
FIDO Alliance — Response to ENISA Draft NIS2 Guidance fidoalliance.org (response to ENISA)
Academic research institutes
USENIX SOUPS 2025 — From TOTPs to Security Keys usenix.org (academic study)
USENIX SOUPS 2025 — Proceedings usenix.org (proceedings)
Official manufacturer documentation
Yubico — Compare Products yubico.com/store/compare
Yubico — YubiKey 5 FIPS Series FIPS 140-3 Validated yubico.com (FIPS certification)
Yubico — Ordering FIPS-Validated YubiKeys as an Enterprise Customer docs.yubico.com (ordering FIPS)
Technical data, certifications and regulatory references are updated as of September 2026 and must be verified directly on official websites before any operational decision.
11 · FAQ

Frequently asked questions about hardware security keys

The answers summarise the framework of the article. Product conditions can change.

What is a hardware security key and why is it safer than an authenticator app?

A hardware security key is a physical device that protects account access using public-key cryptography. Unlike authenticator apps (TOTP), which generate codes that can be intercepted by a phishing site, a hardware key is phishing-resistant by architecture: it authenticates the user only if the requesting domain exactly matches the registered one. An attacker replicating a login page cannot use the key to authenticate, because the key verifies the origin of the request. TOTP apps do not have this protection.

YubiKey 5 Series or Security Key Series: which to choose for a business?

The choice depends on the level of security and the type of business applications. The Security Key Series supports only FIDO2/WebAuthn and U2F: it is sufficient for most cloud accounts (Google Workspace, Microsoft 365, Okta, GitHub). The YubiKey 5 Series also supports PIV (smart card), OpenPGP, OATH-TOTP, Yubico OTP and static passwords: it is required if the business uses legacy VPNs with smart cards, digital signatures, SSH with OpenPGP, or environments that require smart card authentication. For a business that wants a complete and long-lasting solution, the YubiKey 5 Series is the most consistent choice.

What is the difference between FIDO2 and U2F?

U2F is the previous standard, designed only for two-factor authentication: it adds a second factor to a login with username and password. FIDO2 is the current standard and supports both two-factor authentication and passwordless authentication: with FIDO2, the key can completely replace the password. FIDO2 also supports resident credentials (device-bound passkeys), which allow login without a username. U2F is still supported for backward compatibility, but FIDO2 is the standard to prefer for new deployments. Note: on FIPS 140-3 devices, U2F is disabled and only FIDO2 is used.

What does FIPS 140-3 mean and when is it required?

FIPS 140-3 is the current United States government standard for cryptographic modules, aligned with the international standard ISO/IEC 19790:2012. It replaces FIPS 140-2, deprecated in May 2026. The YubiKey 5 FIPS Series is certified FIPS 140-3 Overall Level 2 with Physical Security Level 3, and is the only authenticator authorised by the US government to contain both DoD PKI credentials and FIDO2 passkeys on the same device. It is required for: federal agencies, defence contractors, businesses in regulated sectors (healthcare, finance), organisations that must comply with NIST SP 800-63B AAL3.

How many security keys are needed per employee?

Yubico recommends registering at least two keys per employee: one primary and one backup. If the primary key is lost or damaged, the employee can use the backup key without going through a recovery process that requires IT support intervention. The backup key should be stored in a safe place, separate from the primary key. For enterprise deployment, the standard practice is dual-key enrolment during onboarding.

Does YubiKey work with iPhone and Android?

Yes, but with differences. On iPhone, NFC connection works natively from iPhone 7 with iOS 13. For physical connection, iPhones use Lightning: the YubiKey 5Ci is the only model with a Lightning connector. On iPad, Lightning is the only type of physical connection supported; NFC is not available on current models. On Android, NFC connection works if the device has an NFC reader. For physical USB-C connection, you need a model with a USB-C connector. Some Android devices require enabling USB On-The-Go (OTG) in settings.

What happens if I lose my security key?

If you have registered a backup key, you can use it to access and register a new primary key. If you have lost the only registered key, you must go through the account recovery process of the identity provider (IdP). Most enterprise IdPs (Okta, Microsoft Entra ID, Google Workspace) offer a recovery process that requires identity verification through other methods. The recovery process is a critical security point: it must be configured with strict controls to prevent an attacker from exploiting it. The operational recommendation is to always have a backup key registered and stored in a safe place.

YubiKey 5 NFC or YubiKey 5C NFC: which to choose?

The main difference is the connector: the YubiKey 5 NFC has a USB-A connector, the YubiKey 5C NFC has a USB-C connector. The choice depends on the devices used in the business. If laptops have USB-C ports (most modern laptops), the 5C NFC version is the most consistent choice. If there are still laptops with USB-A or you want maximum compatibility with adapters, the 5 NFC version is more universal. Both support NFC for use on smartphones. The YubiKey 5Ci is the only one with a Lightning connector for iPhone and iPad.

SmartStackHubPro · Final Verdict

The best hardware key is the one the team actually uses, twice.

After comparing models, protocols and certifications, the answer is not “one is better than the others”. The right question is: what is my risk profile, which protocols do I need, and do I have a deployment plan?

For most businesses, the YubiKey 5 NFC or YubiKey 5C NFC is the most consistent choice: it covers all protocols, is certified FIDO L2 and IP68, and works with any modern and legacy service. For businesses with only cloud services, the Security Key Series is cheaper and sufficient. For regulated environments (government, defence, healthcare, finance), the YubiKey 5 FIPS Series certified FIPS 140-3 is the only compliant choice.

The operational truth is that hardware security is not a product, it is a process. Success depends not only on the choice of key, but on how enrolment, backup, lifecycle and support are managed. The two-key rule per employee is the single intervention that most significantly reduces operational risk: it eliminates the need for costly and vulnerable recovery processes.

Before choosing, therefore, do not ask yourself only “which key do I buy”. Ask yourself: do I have a deployment plan, have I configured attestation, have I eliminated weak fallbacks, and have I planned backup for each employee? The answer determines the success of the project.

Ready to protect your business accounts with hardware keys?