Microsoft retires SMS and voice MFA on 1 February 2027. What actually qualifies

IronSightsStore
YubiKey 5 NFC FIPS (140-3), product photo

Yubico

YubiKey 5 NFC FIPS (140-3)

USB-A · NFC · Firmware 5.7

The FIPS 140-3 validated YubiKey 5 NFC: same USB-A and NFC hardware key as the standard model, with the certification regulated buyers need.

$150.95incl. GST
In stock, ships today if ordered by 12pm AEST
Postage
$9.95, free over $1,000
Delivery
2 to 6 business days
Returns
30 days, plus ACL rights
Invoice
Tax invoice on dispatch

“We engaged IronSights to help secure our Microsoft 365 environment, and the results have been outstanding. From start to finish, the process was handled with professionalism, clear communication, and deep technical expertise. The assessment gave us clarity on our risks and a practical path forward.”

Andrew, Technical Architect & CTOTechnology ConsultancyA client whose Microsoft 365 we secure

Buying for a team? We advise on which key fits and run the rollout, enrolment and Conditional Access included. Talk to us.

Good fit if

  • Government and IRAP-scoped environments that must cite FIPS 140-3
  • Regulated SMBs whose framework or contract names a validated authenticator
  • Desk fleets still running USB-A ports
  • Teams standardising phishing-resistant MFA on Microsoft 365 / Entra ID

Look elsewhere if

  • Buyers with no FIPS mandate (the standard 5 NFC is identical hardware for less)
  • Fleets standardised on USB-C (choose the USB-C FIPS variant instead)
  • Anyone who only needs everyday MFA without a compliance line item

The YubiKey 5 NFC FIPS is the FIPS-validated sibling of the standard 5 NFC. Under the hood it is the same hardware key; what you are paying for is the certification. It carries FIPS 140-3 validation, the current US federal standard that replaces the 140-2 generation now being retired. If your controls, contracts or auditors call for a validated authenticator, this is the version that satisfies the line item.

Everything else matches the non-FIPS key. On firmware 5.7 it speaks the full range of protocols: FIDO2/WebAuthn for passkeys, FIDO U2F, PIV smart card, OATH-TOTP and OATH-HOTP, OpenPGP, YubiKey OTP, static password, and HMAC-SHA1 challenge-response. That breadth means one key can cover phishing-resistant sign-in to Microsoft 365 and Entra ID today and still handle older smart-card or OTP systems you have not retired yet.

The form factor is a keychain-sized key with a USB-A connector plus NFC, so it plugs into an older desktop fleet and also taps against a phone. There is no battery and there are no moving parts, and it is crush- and water-resistant, which matters when a key lives on a lanyard or in a pocket for years.

Our take: buy this when a FIPS requirement is genuinely on the paperwork. Regulated buyers, government and IRAP-scoped environments, and anyone whose framework names FIPS 140-3 need the validated part. The 140-2 retirement is a good reason to specify 140-3 now rather than inherit a soon-to-be-legacy certification.

If you have no such requirement, the standard YubiKey 5 NFC is the same hardware with less procurement friction, so do not pay for a certification you will never cite. And if your fleet has moved to USB-C, choose the USB-C member of the FIPS series rather than reaching for adapters.

Specifications

Certification
FIPS 140-3 validated
Firmware
5.7
Connector
USB-A
Wireless
NFC (tap to phone)
Protocols
FIDO2/WebAuthn, FIDO U2F, PIV smart card, OATH-TOTP/HOTP, OpenPGP, YubiKey OTP, static password, HMAC-SHA1 challenge-response
Power
No battery, no moving parts
Durability
Crush- and water-resistant
Form factor
Keychain-sized

In the YubiKey 5 FIPS 140-3 Series

Same firmware and the same protocols across the range. What changes is the connector and whether it taps a phone.