Best Hardware Security Keys (YubiKey) for Protecting Business Accounts
Operational guide to the best hardware security keys for business accounts: comparison of YubiKey 5, Security Key and FIPS Series, FIDO2 vs U2F differences, enterprise deployment and use cases.
For most businesses, the YubiKey 5 NFC or YubiKey 5C NFC is the most consistent choice: it supports all protocols (FIDO2, U2F, PIV, OpenPGP, OATH-TOTP, Yubico OTP) and covers both modern cloud applications and legacy systems. For those who need only FIDO2/WebAuthn, the Security Key Series is cheaper and sufficient. For regulated environments (government, defence, healthcare, finance), the YubiKey 5 FIPS Series certified FIPS 140-3 is the only compliant choice. Regardless of model, the operational rule is two keys per employee, one primary and one backup.
Passwords are no longer enough. Two-factor authentication with SMS is vulnerable to SIM swapping. Authenticator apps (TOTP) are better, but remain vulnerable to real-time phishing: an attacker can replicate a login page and ask for the code, which the user will provide believing they are on the right site. Hardware security keys eliminate this vulnerability by architecture: they authenticate the user only if the requesting domain exactly matches the registered one.
Yubico is the reference manufacturer in this category. Its keys are used in over 160 countries and are the de facto standard for phishing-resistant authentication in businesses. This guide analyses the different YubiKey series, the differences between FIDO2 and U2F, the FIPS certifications for regulated environments, and enterprise deployment practices.
The regulatory and security landscape has changed significantly between 2025 and 2026. NIST published the final version of SP 800-63B-4 in July 2025, which defines the technical requirements for the three Authentication Assurance Levels. W3C published WebAuthn Level 3 as an official Recommendation in August 2026, stabilising the standard on which passkeys and hardware keys are based. ENISA recognised passkeys as the strongest phishing-resistant MFA method in its technical guidance for NIS2 published in June 2025. And the FIDO Alliance published guidance for FIDO authentication deployment in US government agencies in March 2025.
If you are building a complete security architecture for your business, complete your reading with our comparison of ProtonVPN vs NordVPN for privacy and the guide on how to protect business data on public Wi-Fi.
Editorial and affiliate note
General information. The content of this article, including references to prices, features and certifications of the products mentioned, is published for informational and educational purposes. SmartStackHubPro.com does not provide legal, technical or cybersecurity advice. Product conditions change frequently: always verify updated information on the official websites of the respective manufacturers before making decisions.
Affiliate transparency. Some links in this article may be affiliate links. If you purchase through these links, SmartStackHubPro may receive a commission at no additional cost to you. This does not influence the editorial selection, which follows criteria of practical utility and consistency with the operational stack of international professionals.
Why passwords and TOTP apps are no longer enough
Business account breaches almost never happen through sophisticated technical attacks. They happen through phishing, social engineering and credential reuse. Hardware security keys are the only authentication method that resists these threats by architecture, not by configuration.
TOTP apps are vulnerable to phishing
A TOTP code generated by an app is valid for a short period, but can be intercepted in real time. An attacker replicating a login page can ask the user for the code and use it immediately. A hardware key does not have this problem: it authenticates only if the requesting domain exactly matches the registered one.
SMS is insecure by design
SIM swapping and mobile network interception make SMS inadequate for business authentication. NIST SP 800-63B-4 classifies SMS as “restricted” and recommends against using it for high-risk authentication. Hardware keys are the designated alternative for AAL3.
Reused passwords are a systemic risk
A single breach on a consumer service can compromise business access if the same password is reused. Hardware keys eliminate this dependency: even if the password is compromised, access requires the physical key.
A single compromised business account can cost hundreds of thousands of euros in stolen data, remediation, reputational damage and potential regulatory fines. The MGM Resorts incident of 2023 had an estimated impact of $100 million. The cost of equipping a team of 100 people with two YubiKeys each is a few thousand euros. The ROI of hardware security is one of the highest in enterprise IT.
FIDO2, U2F and WebAuthn: what they mean and which to use
When talking about hardware security keys, the terms FIDO2, U2F, WebAuthn and CTAP are often used interchangeably. They are not. Understanding the difference is essential to choose the right model and configure the deployment correctly.
U2F: the predecessor
U2F (Universal 2nd Factor) is the previous standard, designed only for two-factor authentication. It adds a second factor to a login with username and password: the user provides credentials and then touches the key to confirm. U2F does not support passwordless authentication: the password remains necessary. U2F is still supported for backward compatibility, but is considered superseded.
Important note: on YubiKey 5 FIPS Series devices with firmware 5.7.x and FIPS 140-3 certification, U2F is disabled. Only FIDO2 is used. This is a change introduced with FIPS 140-3: the U2F function is no longer available on these devices.
FIDO2 and WebAuthn: the current standard
FIDO2 is the current standard and supports both two-factor authentication and passwordless authentication. WebAuthn is the W3C specification that defines the interface between the browser and the authenticator (the key). CTAP is the protocol that defines the communication between the browser and the key itself. WebAuthn Level 3 became an official W3C Recommendation on 25 August 2026, definitively stabilising the standard.
With FIDO2, the key can completely replace the password. The user touches the key and authenticates, without typing anything. FIDO2 also supports resident credentials (also called device-bound passkeys), which allow login without even entering a username: the key remembers the credentials associated with the site. According to the FIDO Alliance guidance for US government deployment, device-bound passkeys can satisfy both AAL3 and AAL2, while synchronised passkeys are limited to AAL2.
How many resident credentials can a YubiKey hold?
The number of resident credentials (passkeys) a YubiKey can hold depends on the firmware and model. YubiKey 5 Series with firmware 5.7.x and later supports up to 100 device-bound passkeys, a significant increase from the 25 of previous firmware. This number is relevant for enterprise deployment: if each employee must register the key on dozens of business services, the capacity must be sufficient.
YubiKey 5 Series, Security Key Series, FIPS Series and Bio Series
Yubico produces four main families of keys. The choice depends on the level of security required, the protocols needed, and the regulated environments in which the business operates.
| Series | Supported protocols | Certifications | Ideal for |
|---|---|---|---|
| YubiKey 5 Series | FIDO2, U2F, PIV, OpenPGP, OATH-TOTP/HOTP, Yubico OTP, static passwords | FIDO L1/L2, IP68 | Most businesses: complete cloud + legacy coverage |
| Security Key Series | FIDO2, U2F | FIDO L1/L2 | Businesses using only modern cloud services (Google, Microsoft 365, Okta) |
| YubiKey 5 FIPS Series | FIDO2, PIV, OpenPGP, OATH (U2F disabled on 140-3) | FIPS 140-3 Level 2, Physical Security Level 3 | Government, defence, healthcare, finance, regulated environments |
| YubiKey Bio Series | FIDO2 | FIDO L1/L2 | Businesses wanting biometric authentication on FIDO2 |
YubiKey 5 Series: the Swiss army knife
The YubiKey 5 Series is the most versatile choice: it supports all protocols, including PIV (smart card), OpenPGP, OATH-TOTP, Yubico OTP and static passwords. This makes it suitable for both modern cloud authentication (FIDO2) and legacy systems requiring smart cards or OTP.
Main models: YubiKey 5 NFC (USB-A + NFC), YubiKey 5C NFC (USB-C + NFC), YubiKey 5 Nano (USB-A, ultra-compact form), YubiKey 5C Nano (USB-C, ultra-compact form), YubiKey 5Ci (USB-C + Lightning for iPhone/iPad).
Indicative 2026 prices: from around $58 for the YubiKey 5C NFC to around $85 for the YubiKey 5Ci.
Security Key Series: the essentials at a contained cost
The Security Key Series supports only FIDO2 and U2F. It has no PIV, OpenPGP, OATH-TOTP or Yubico OTP. It is sufficient for most cloud accounts (Google Workspace, Microsoft 365, Okta, GitHub, AWS), but does not cover legacy systems requiring smart cards or hardware OTP.
When to choose it: if your business uses exclusively modern cloud services with FIDO2 support, the Security Key Series is cheaper and more than sufficient. If you need to cover legacy VPNs, digital signatures or SSH with OpenPGP, you need the YubiKey 5 Series.
YubiKey Bio Series: biometric authentication on FIDO2
The YubiKey Bio Series adds a fingerprint reader to the key. Authentication happens with the fingerprint, with the option to use a PIN as backup. It is certified FIDO2 and supports services such as Bitwarden, Okta, Google and Microsoft.
When to choose it: if your business wants a passwordless experience with biometric verification and does not need legacy protocols (PIV, OpenPGP, OATH). The YubiKey Bio is supported by most modern FIDO2 services.
YubiKey 5 NFC or 5C NFC for most businesses
Complete coverage of all protocols, FIDO L2 and IP68 certifications, available in USB-A and USB-C.
FIPS 140-3: what it means and when it is required
FIPS 140-3 is the current United States government standard for cryptographic modules, aligned with the international standard ISO/IEC 19790:2012. It replaces FIPS 140-2, deprecated in May 2026. For businesses operating in regulated sectors or providing services to government entities, FIPS certification is often a contractual requirement.
YubiKey 5 FIPS Series: what it offers
The YubiKey 5 FIPS Series is certified FIPS 140-3 Overall Level 2 with Physical Security Level 3 (Certificate #5291). It is the only authenticator authorised by the US government to contain both DoD PKI credentials and FIDO2 passkeys on the same device.
Main features of firmware 5.7.4:
- Support for RSA-3072 and RSA-4096 keys, in addition to Ed25519 and X25519
- FIDO2, PIV and OpenPGP PINs with minimum 8 characters, complexity enabled by default
- U2F disabled: only FIDO2 is available
- Enterprise attestation: IdPs can read the key’s serial number during FIDO2 registration
- Support for 100 device-bound passkeys (up from 25)
- SCP11: secure channel based on asymmetric cryptography
- NFC disabled in transit to prevent tampering before deployment
Who needs FIPS 140-3
FIPS 140-3 certification is required for:
- US federal agencies and defence contractors. NIST has set 21 September 2026 as the deadline for new government systems that must use FIPS 140-3 validated cryptographic modules.
- Businesses in regulated sectors (healthcare with HIPAA, finance with PCI-DSS, energy with NERC CIP)
- Organisations that must comply with NIST SP 800-63B AAL3: AAL3 requires a hardware-based token resistant to verifier impersonation
- Organisations handling classified government data
What changes with FIPS 140-3 compared to FIPS 140-2
The most significant difference is that FIPS 140-3 introduces hardware enforcement: FIPS requirements are applied directly by the YubiKey, not only by the software. The device refuses to create credentials until it is correctly configured and in FIPS Approved Mode. Once initialised in FIPS mode, the device cannot be removed from that mode without erasing all functions.
Important note for procurement: FIPS 140-2 is deprecated. Auditors recommend not deploying new installations with FIPS 140-2 certified devices. Existing FIPS 140-2 devices can continue to be used, but new deployments must have a valid, non-expired certification.
If your business needs FIPS, verify that the keys purchased are certified FIPS 140-3, not FIPS 140-2. Yubico obtained FIPS 140-3 validation for the YubiKey 5 FIPS Series in May 2026 (Certificate #5291). If you have stock of FIPS 140-2 keys, plan replacement for new deployments and future audits.
How to distribute security keys in a business
Choosing the model is only the first step. The success of a hardware key deployment depends on how enrolment, backup, recovery and lifecycle are managed. Yubico recommends registering at least two keys per employee.
The two-key rule
For each employee, register two keys: one primary (which the employee carries with them) and one backup (stored in a safe place). If the primary key is lost or damaged, the employee can use the backup key without going through a recovery process involving IT support.
Why it is essential: the account recovery process is a critical security point. If an attacker manages to manipulate IT support or the reset process, they can gain access even without the physical key. Having a backup key registered eliminates the need to resort to recovery in most cases.
Enterprise enrolment with attestation
Firmware 5.7.x introduces Enterprise Attestation: during FIDO2 registration, the Identity Provider can read the key’s serial number and other unique identifiers. This allows you to:
- Verify that the key was issued by the business and is not a personal key
- Associate the key with a business inventory
- Block registration of unauthorised keys
- Simplify asset tracking for large device fleets
Lifecycle management
Hardware keys are physical assets that require lifecycle management: issuance, distribution, replacement, revocation. For large-scale deployments, this means integrating key management into the onboarding workflow (joiner-mover-leaver) and maintaining an up-to-date inventory.
Costs at scale: for a business of 10,000 employees, equipping each person with two keys (primary + backup) involves an investment in hardware between $400,000 and $2.2 million, depending on the model chosen. This is why many businesses adopt selective deployment: hardware keys for privileged roles (admin, executive, regulated roles) and synchronised passkeys or other methods for the rest of the workforce.
Which YubiKey for which type of business
This is not a ranking. It is a matrix to orient yourself based on your specific context.
| Business profile | Recommended model | Why |
|---|---|---|
| Startup / SMB with cloud services | Security Key C NFC | Only FIDO2 needed, contained cost |
| SMB with legacy VPN and smart cards | YubiKey 5 NFC or 5C NFC | Supports PIV, OpenPGP and OTP in addition to FIDO2 |
| Business with corporate iPhone/iPad | YubiKey 5Ci | The only model with Lightning connector |
| Modern laptops with USB-C | YubiKey 5C NFC or 5C Nano | USB-C connector, NFC for smartphones |
| Large-scale enterprise deployment | YubiKey 5 NFC (USB-A) | Maximum compatibility with adapters |
| Government, defence, regulated sectors | YubiKey 5 FIPS Series | FIPS 140-3 certification, DoD PKI + FIDO2 |
| Business with biometric focus | YubiKey Bio Series | Fingerprint reader, FIDO2, passwordless |
The Security Key is for those who use only modern cloud. The YubiKey 5 is for those who need complete coverage. The FIPS Series is for those operating in regulated environments. The Bio is for those who want biometric. The right question is: which protocols do I actually need, and which certification must I comply with?
The 5 most costly mistakes in hardware key deployment
These mistakes are not disastrous individually. They become relevant when repeated and compromise adoption or security.
Yubico recommends two keys per employee: one primary and one backup. Without a backup, losing the primary key forces the employee to go through the recovery process, which is a critical security point and a support load. The backup key must be registered during onboarding and stored in a safe place.
Firmware 5.7.x supports Enterprise Attestation: during FIDO2 registration, the IdP can read the key’s serial number. Without this configuration, you cannot verify that the registered key is the one issued by the business. An employee could register a personal key, which the business cannot inventory or revoke.
If your policy allows SMS, OTP via email or push notification as fallback methods, an attacker can force a downgrade and exploit the weaker method. Authentication is only as strong as its weakest link. The recommendation is to eliminate weak fallbacks and make the hardware path the only possible path for privileged roles.
FIPS 140-2 has been deprecated since May 2026. Auditors recommend not deploying new installations with FIPS 140-2 devices. If you need FIPS, verify that the keys purchased are certified FIPS 140-3 (Certificate #5291 for the YubiKey 5 FIPS Series).
The choice between USB-A, USB-C and Lightning depends on the business’s devices. If laptops have USB-C, the USB-C version is more consistent. If there are corporate iPhone or iPad devices, a Lightning key is needed (only YubiKey 5Ci). Always verify compatibility before ordering in large quantities.
A hardware key deployment is not just a purchase: it is an operational project requiring enrolment, backup, lifecycle, support and recovery. Businesses that fail do so not because of the technical choice, but because of the lack of an operational plan. Start with a pilot, measure the load, then expand.
The SmartStackHubPro roadmap to adopt hardware keys
A practical sequence to choose and distribute keys without inconclusive trials.
Which business applications must be protected? Do you need FIDO2, PIV, OpenPGP, OATH? Do you operate in a regulated sector requiring FIPS? The answers determine the YubiKey series to choose.
Do laptops have USB-A or USB-C? Are there corporate iPhone or iPad devices (Lightning)? Do smartphones support NFC? The connector choice must be consistent with the devices in use.
Security Key for cloud-only, YubiKey 5 for complete coverage, FIPS Series for regulated environments, Bio for biometric. There is no single model for all businesses.
For each employee: one primary key and one backup. The backup key must be registered during onboarding and stored in a safe place. Enrolment must be configured with Enterprise Attestation for inventory.
Choose a small group (IT, privileged roles) and test the deployment for 2-3 weeks. Measure adoption rate, support load, UX issues. Then expand in waves.
How many employees use the key regularly? How many need support? Is the abandonment rate acceptable? If adoption is low, the problem is the way it was introduced, not the technology.
A successful deployment requires enrolment planning, lifecycle management, recovery support and adoption measurement. The technical choice is only the first step. The time spent planning the deployment is the most valuable.
Official sources and references
The technical data and regulatory references cited in this article are based on institutional sources, research institutes and official manufacturer documentation. Always verify updated conditions on official websites before making decisions.
Show official sources
Frequently asked questions about hardware security keys
The answers summarise the framework of the article. Product conditions can change.
What is a hardware security key and why is it safer than an authenticator app?
A hardware security key is a physical device that protects account access using public-key cryptography. Unlike authenticator apps (TOTP), which generate codes that can be intercepted by a phishing site, a hardware key is phishing-resistant by architecture: it authenticates the user only if the requesting domain exactly matches the registered one. An attacker replicating a login page cannot use the key to authenticate, because the key verifies the origin of the request. TOTP apps do not have this protection.
YubiKey 5 Series or Security Key Series: which to choose for a business?
The choice depends on the level of security and the type of business applications. The Security Key Series supports only FIDO2/WebAuthn and U2F: it is sufficient for most cloud accounts (Google Workspace, Microsoft 365, Okta, GitHub). The YubiKey 5 Series also supports PIV (smart card), OpenPGP, OATH-TOTP, Yubico OTP and static passwords: it is required if the business uses legacy VPNs with smart cards, digital signatures, SSH with OpenPGP, or environments that require smart card authentication. For a business that wants a complete and long-lasting solution, the YubiKey 5 Series is the most consistent choice.
What is the difference between FIDO2 and U2F?
U2F is the previous standard, designed only for two-factor authentication: it adds a second factor to a login with username and password. FIDO2 is the current standard and supports both two-factor authentication and passwordless authentication: with FIDO2, the key can completely replace the password. FIDO2 also supports resident credentials (device-bound passkeys), which allow login without a username. U2F is still supported for backward compatibility, but FIDO2 is the standard to prefer for new deployments. Note: on FIPS 140-3 devices, U2F is disabled and only FIDO2 is used.
What does FIPS 140-3 mean and when is it required?
FIPS 140-3 is the current United States government standard for cryptographic modules, aligned with the international standard ISO/IEC 19790:2012. It replaces FIPS 140-2, deprecated in May 2026. The YubiKey 5 FIPS Series is certified FIPS 140-3 Overall Level 2 with Physical Security Level 3, and is the only authenticator authorised by the US government to contain both DoD PKI credentials and FIDO2 passkeys on the same device. It is required for: federal agencies, defence contractors, businesses in regulated sectors (healthcare, finance), organisations that must comply with NIST SP 800-63B AAL3.
How many security keys are needed per employee?
Yubico recommends registering at least two keys per employee: one primary and one backup. If the primary key is lost or damaged, the employee can use the backup key without going through a recovery process that requires IT support intervention. The backup key should be stored in a safe place, separate from the primary key. For enterprise deployment, the standard practice is dual-key enrolment during onboarding.
Does YubiKey work with iPhone and Android?
Yes, but with differences. On iPhone, NFC connection works natively from iPhone 7 with iOS 13. For physical connection, iPhones use Lightning: the YubiKey 5Ci is the only model with a Lightning connector. On iPad, Lightning is the only type of physical connection supported; NFC is not available on current models. On Android, NFC connection works if the device has an NFC reader. For physical USB-C connection, you need a model with a USB-C connector. Some Android devices require enabling USB On-The-Go (OTG) in settings.
What happens if I lose my security key?
If you have registered a backup key, you can use it to access and register a new primary key. If you have lost the only registered key, you must go through the account recovery process of the identity provider (IdP). Most enterprise IdPs (Okta, Microsoft Entra ID, Google Workspace) offer a recovery process that requires identity verification through other methods. The recovery process is a critical security point: it must be configured with strict controls to prevent an attacker from exploiting it. The operational recommendation is to always have a backup key registered and stored in a safe place.
YubiKey 5 NFC or YubiKey 5C NFC: which to choose?
The main difference is the connector: the YubiKey 5 NFC has a USB-A connector, the YubiKey 5C NFC has a USB-C connector. The choice depends on the devices used in the business. If laptops have USB-C ports (most modern laptops), the 5C NFC version is the most consistent choice. If there are still laptops with USB-A or you want maximum compatibility with adapters, the 5 NFC version is more universal. Both support NFC for use on smartphones. The YubiKey 5Ci is the only one with a Lightning connector for iPhone and iPad.
The best hardware key is the one the team actually uses, twice.
After comparing models, protocols and certifications, the answer is not “one is better than the others”. The right question is: what is my risk profile, which protocols do I need, and do I have a deployment plan?
For most businesses, the YubiKey 5 NFC or YubiKey 5C NFC is the most consistent choice: it covers all protocols, is certified FIDO L2 and IP68, and works with any modern and legacy service. For businesses with only cloud services, the Security Key Series is cheaper and sufficient. For regulated environments (government, defence, healthcare, finance), the YubiKey 5 FIPS Series certified FIPS 140-3 is the only compliant choice.
The operational truth is that hardware security is not a product, it is a process. Success depends not only on the choice of key, but on how enrolment, backup, lifecycle and support are managed. The two-key rule per employee is the single intervention that most significantly reduces operational risk: it eliminates the need for costly and vulnerable recovery processes.
Before choosing, therefore, do not ask yourself only “which key do I buy”. Ask yourself: do I have a deployment plan, have I configured attestation, have I eliminated weak fallbacks, and have I planned backup for each employee? The answer determines the success of the project.