Microsoft retires SMS and voice MFA on 1 February 2027. What actually qualifies

IronSightsStore
YubiKey 5C Nano FIPS (140-3), product photo

Yubico

YubiKey 5C Nano FIPS (140-3)

USB-C · no NFC · Firmware 5.7

The FIPS 140-3 validated YubiKey 5C Nano: a tiny USB-C security key for regulated and government buyers who need the certification on the paperwork.

$167.95incl. GST
In stock, ships today if ordered by 12pm AEST
Postage
$9.95, free over $1,000
Delivery
2 to 6 business days
Returns
30 days, plus ACL rights
Invoice
Tax invoice on dispatch

“We engaged IronSights to help secure our Microsoft 365 environment, and the results have been outstanding. From start to finish, the process was handled with professionalism, clear communication, and deep technical expertise. The assessment gave us clarity on our risks and a practical path forward.”

Andrew, Technical Architect & CTOTechnology ConsultancyA client whose Microsoft 365 we secure

Buying for a team? We advise on which key fits and run the rollout, enrolment and Conditional Access included. Talk to us.

Good fit if

  • Regulated or government buyers who need FIPS 140-3 on procurement paperwork
  • Fixed workstations or single-desk laptops where the key stays in permanently
  • Passwordless and phishing-resistant sign-in to Microsoft 365 and Entra ID
  • Teams using PIV smart-card certificates or OpenPGP alongside FIDO2 passkeys

Look elsewhere if

  • Anyone without a FIPS compliance requirement: the standard 5C Nano is identical and cheaper
  • People who need to tap a phone or reader, as there is no NFC
  • Users who carry one key between several machines (the nano is made to stay put)
  • Devices without a spare USB-C port

The 5C Nano FIPS is the certified version of YubiKey's smallest USB-C key. The hardware is the same as the standard YubiKey 5 Series, with the same protocols and the same firmware 5.7, but this one carries FIPS 140-3 validation, the current US federal standard that replaces the 140-2 generation now being retired. If you don't have a compliance reason to need that certificate, the ordinary 5C Nano does exactly the same job. The FIPS validation is the whole point of paying for this one.

That certification is what regulated and government buyers put on the paperwork. If a procurement requirement, a security control, or an auditor asks for a FIPS 140-3 validated authenticator, this satisfies it where the standard key, functionally identical, will not. For everyone else it is an unnecessary line item.

Underneath, it is a full multi-protocol security key. It handles FIDO2/WebAuthn passkeys and FIDO U2F for phishing-resistant sign-in, PIV smart-card certificates, OATH-TOTP and OATH-HOTP one-time codes, OpenPGP, YubiKey OTP, a static password slot, and HMAC-SHA1 challenge-response. That covers passwordless and phishing-resistant MFA into Microsoft 365 and Entra ID, and the strong-authentication expectations in the Essential Eight.

The nano form factor is the deciding factor. It sits almost flush in a USB-C port and is meant to be left in permanently, which suits a fixed workstation or a laptop that lives on one desk. There is no NFC, so you cannot tap it against a phone, and prising a near-flush key in and out of a shared machine is awkward. It has no battery and no moving parts, and is crush- and water-resistant.

Buy it where the FIPS requirement is real and the key stays put. If you move between devices, need NFC, or have no certification mandate, a different key will serve you better for the same money.

Specifications

Certification
FIPS 140-3 validated (YubiKey 5 FIPS Series)
Firmware
5.7
Connector
USB-C
Form factor
Nano, sits near-flush and is designed to stay in the port
NFC
None
Protocols
FIDO2/WebAuthn, FIDO U2F, PIV, OATH-TOTP, OATH-HOTP, OpenPGP, YubiKey OTP, static password, HMAC-SHA1 challenge-response
Build
No battery, no moving parts; crush- and water-resistant

In the YubiKey 5 FIPS 140-3 Series

Same firmware and the same protocols across the range. What changes is the connector and whether it taps a phone.