Microsoft retires SMS and voice MFA on 1 February 2027. What actually qualifies

IronSightsStore
YubiKey 5C FIPS (140-3), product photo

Yubico

YubiKey 5C FIPS (140-3)

USB-C · no NFC · Firmware 5.7

The FIPS 140-3 validated YubiKey 5C. Same multi-protocol key as the standard 5C, with the certification regulated and government buyers need.

$162.95incl. GST
In stock, ships today if ordered by 12pm AEST
Postage
$9.95, free over $1,000
Delivery
2 to 6 business days
Returns
30 days, plus ACL rights
Invoice
Tax invoice on dispatch

“We engaged IronSights to help secure our Microsoft 365 environment, and the results have been outstanding. From start to finish, the process was handled with professionalism, clear communication, and deep technical expertise. The assessment gave us clarity on our risks and a practical path forward.”

Andrew, Technical Architect & CTOTechnology ConsultancyA client whose Microsoft 365 we secure

Buying for a team? We advise on which key fits and run the rollout, enrolment and Conditional Access included. Talk to us.

Good fit if

  • Regulated or government buyers whose framework or tender specifies a FIPS 140-3 authenticator
  • Teams that need an auditable, phishing-resistant key for Microsoft 365 and Entra ID
  • Laptop users who plug a key in rather than tap a phone

Look elsewhere if

  • Anyone not actually required to hold a FIPS certificate (the standard 5C does the same job for less)
  • People who need to tap a phone to sign in (no NFC here, choose an NFC model)
  • Devices that only have USB-A ports

The YubiKey 5C FIPS is the certified member of the YubiKey 5 FIPS Series, built on firmware 5.7. Physically and functionally it is the same key as the standard 5C. The difference sits entirely on the paperwork. It carries FIPS 140-3 validation, the current US federal standard, which supersedes the older 140-2 generation now being retired.

That validation is the only reason to choose this over the non-FIPS version. If a control framework, a government tender, an IRAP assessment, or an auditor specifically asks for a FIPS-validated authenticator, this is the key that satisfies the requirement. If no one is asking for the certificate, you are paying for a line item you will never be checked on, and the standard 5C does exactly the same job.

Underneath, it is a full multi-protocol security key. It handles FIDO2 and WebAuthn passkeys, FIDO U2F, PIV smart card, OATH-TOTP and OATH-HOTP one-time codes, OpenPGP, YubiKey OTP, static passwords, and HMAC-SHA1 challenge-response. For most Australian teams that means phishing-resistant sign-in to Microsoft 365 and Entra ID, with the same key covering older systems that still lean on OTP or smart-card login.

The form factor is deliberately plain: a USB-C connector, standard keychain size, and no NFC. It suits people working from a modern laptop who plug the key in rather than tap a phone. If you need to authenticate on a mobile by tapping, choose an NFC model instead. There is no battery and nothing that moves, and it is built to survive being crushed or getting wet on a keyring.

Our take: buy this when the certification is a genuine requirement, not by default. Order at least two per person so everyone has a registered spare, and confirm your identity provider accepts FIPS keys before you standardise on them. For everyone else, the non-FIPS 5C is the sensible choice.

Specifications

Certification
FIPS 140-3 validated
Series
YubiKey 5 FIPS Series
Firmware
5.7
Connector
USB-C
NFC
None
Protocols
FIDO2/WebAuthn, FIDO U2F, PIV, OATH-TOTP/HOTP, OpenPGP, YubiKey OTP, static password, HMAC-SHA1 challenge-response
Build
Crush- and water-resistant; no battery, no moving parts
Form factor
Standard keychain size

In the YubiKey 5 FIPS 140-3 Series

Same firmware and the same protocols across the range. What changes is the connector and whether it taps a phone.