Core Competencies
Yubico assists the federal government in its mission to deploy strong cybersecurity by providing highest-assurance multi-factor and passwordless authentication with the YubiKey, a FIPS 140-3 validated hardware security key that is an alternative to Personal Identity Verification (PIV) and Common Access Card (CAC). YubiKeys offer phishing-resistant MFA to meet the highest Authentication Assurance Level 3 requirements (AAL3) of NIST SP800-63B guidelines.
Why is YubiKey the right solution?
- Available on Department of Homeland Security, Continuous Diagnostics and Mitigation (CDM) as a preferred authenticator to meet OMB Memorandum M-19-17
- Meets all zero trust and phishing-resistant MFA AAL3 authenticator requirements as stated in President Biden’s Executive Order released May 12th, 2021 and OMB Memorandum M-22-09 released Jan 26th, 2022
- FIPS 140-3 validated: Meets Authentication Assurance Level 3 requirements (AAL3) of NIST SP800-63B (Certificate #3914)
- Primary and derived-PIV support with most of the major CMS/CA vendors that are in use across federal civilian and in conjunction with the GSA USAccess Program for credentialing of YubiKey for BYOD/BYOAD mobile devices
- Aligns to Identity pillar in CISA Zero Trust Maturity Model 2.0
- WebAuthn, FIDO, FIDO2, DFARS/NIST SP 800-171 and Cybersecurity Maturity Model Certification (CMMC) compliant. Usable with both GFE/personal laptops, desktops, smart phones and tablets
- Supported protocols: PIV, OTP, FIDO2/WebAuth, OpenPGP
- Secure United States manufacturing and supply chain processes for trustworthy components and delivery
- Strongest authentication: Non PIV eligible users, BYOD/ BYOAD & closed/air-gapped networks
- Unlike managing multiple certificates across mobile devices and PIV cards, a YubiKey can be used as a portable root of trust across multiple devices including mobile and BYOD/ BYOAD, minimizing CapEx and OpEx costs
- National Security Agency (NSA) Cybersecurity Information Guidance, Selecting Secure Multi-factor Authentication Solutions, October 2022: YubiKey listed in MFA evaluation guidance as an AAL3 capable authenticator
The total economic impact of YubiKeys

Strongest Security
Reduce risk by 99.9%

High Return
Experience ROI of 265%

More Value
Reduce support tickets by 75%

Faster
Decrease time to authenticate by 80%
In a commissioned study conducted on behalf of Yubico, Forrester Consulting interviewed security leaders from five enterprises using YubiKeys and found that for the composite organization, YubiKeys slashed exposure to security breaches from phishing and credential thefts by 99.9%. Further, YubiKeys reduced administrative overhead while providing a flexible, dependable user experience.
Past Performance

U.S. Government: Widely deployed in the U.S. Government with over 150 unique implementations
Federal agencies including the U.S. Department of Energy, U.S. Department of Justice, U.S. Department of Commerce, U.S. Department of State, and U.S. Department of Health and Human Services are utilizing YubiKeys for phishing-resistant MFA
Industry: Many of the world’s largest technology companies and financial institutions use YubiKeys • Google reduced account takeovers to zero with YubiKeys, used by over 114,000 employees • 4 of the top 10 U.S. banks use YubiKeys. The nation’s fifth-largest consumer bank expanded YubiKeys from mobile-restricted call centers to over 100,000 employees • Facebook eliminated targeted attacks and expanded YubiKeys from engineering to over 50,000 employees
Technology Partners: Yubico works closely with technology partners to fuel growth, innovation and results that deliver strong authentication solutions and standards for our mutual customers:
Differentiators
- Multiple authentication protocols on a single key—PIV, OTP, FIDO U2F, FIDO2/WebAuthn
- FIPS 140-3 validated strong PIV alternative with a low total cost of ownership. YubiKeys are easier to deploy, especially for remote workers—including secure logistics/shipping of YubiKeys directly to employees
- The YubiKey is a device-bound passkey that offers the highest security assurance and provides agencies with trusted credential lifecycle management and attestation abilities needed for the strongest AAL3 security
- Unlike mobile-based authenticators, YubiKeys are purposebuilt for security and don’t require Government Furnished Equipment (GFE) or a network connection.
Getting Started
- Bailment agreement can be established to obtain Not for Resale (NFR) YubiKeys for proof of concept (POC) programs. Yubico offers solutions engineering support for architecture design and review, and IDP configuration guidance through the POC
- Once ready to purchase, Yubico is focused on helping agencies easily access security products and services in a flexible and cost-effective way to heighten security:
- With YubiKey as a Service, agencies benefit from simple and scalable global deployments of YubiKeys for their workforce, supply chain, and end customers. YubiKey as a Service offers customers a choice of form factors, replacement stock, and priority customer support, all for less than the price of a cup of coffee per month.
- Customers also have access to turnkey Enrollment and Delivery services that help IT get users quickly onboarded with YubiKeys to fast track to phishingresistance and then get YubiKeys to end users across the world, including corporate and residential addresses. Users can even experience self-service ordering of YubiKeys, giving them the freedom to have the keys shipped to their preferred address anytime they need.
- YubiKey as a Service customers receive continual enhancements to available and new services assuring a smart and future-proofed security investment.
Company Information
Yubico puts an end to account takeovers for businesses, governments and individuals. The YubiKey—the world’s #1 hardware security key is the most secure, easy-to-use, and affordable multi-factor authentication, and works with hundreds of applications and services including leading identity access management solutions such as Microsoft, Okta, Ping, and Duo.
YubiKeys are available for procurement through multiple convenient channels:
- Address: Yubico Inc. 5201 Great America Pkwy #122, Santa Clara, CA 95054
- Phone: 844-205-6787 (toll free), 650-285-0088
- Purchase via GSA or SEWP V contract
- Carahsoft Technology Corporation = GSA Multiple Award Schedule Contract # 47QSWA18D008F
- Immix = GSA Contract # GS-35F-0511T / SEWP V NNG15SC16B (Category A, Group A) & NNG15SC39B (Category B, Group D)
- DUNS: 046832835, CAGE Code: 6UUE2, NAICS Code: 423430
