Microsoft retires SMS and voice MFA on 1 February 2027. What actually qualifies

IronSightsStore
YubiKey 5Ci FIPS (140-3), product photo

Yubico

YubiKey 5Ci FIPS (140-3)

USB-C + Lightning · no NFC · Firmware 5.7

A FIPS 140-3 validated security key with both USB-C and Lightning connectors, for regulated buyers still carrying an older iPhone or iPad.

$196.95incl. GST
On back order, ships in about 7 business days

On back order — ships in about 7 business days

We order it in from our distributor as soon as you buy. We charge today and confirm your order straight away; if that timing ever slips we will tell you, and you can cancel for a full refund any time before it ships.

Need it urgently? Get in touch and we will chase priority stock.

Postage
$9.95, free over $1,000
Delivery
2 to 6 business days
Returns
30 days, plus ACL rights
Invoice
Tax invoice on dispatch

“We engaged IronSights to help secure our Microsoft 365 environment, and the results have been outstanding. From start to finish, the process was handled with professionalism, clear communication, and deep technical expertise. The assessment gave us clarity on our risks and a practical path forward.”

Andrew, Technical Architect & CTOTechnology ConsultancyA client whose Microsoft 365 we secure

Buying for a team? We advise on which key fits and run the rollout, enrolment and Conditional Access included. Talk to us.

Good fit if

  • Regulated or government buyers whose paperwork requires a FIPS-validated authenticator
  • People working on a USB-C computer who still carry a Lightning iPhone or iPad
  • Teams standardising MFA for Microsoft 365 / Entra ID under the Essential Eight
  • Anyone needing one certified key across laptop and older Apple device

Look elsewhere if

  • Fleets already fully on USB-C iPhones, where the Lightning end is dead weight
  • Buyers with no FIPS mandate (the standard 5Ci is identical hardware for less)
  • Anyone expecting NFC tap-to-authenticate on a phone (there is none)

The 5Ci FIPS is the same hardware as the standard YubiKey 5Ci, with one difference that matters on paper: it is validated to FIPS 140-3, the current US federal cryptographic standard. That validation is the whole reason to buy this version. If a contract, a framework, or an auditor requires a FIPS-validated authenticator, this is the box that ticks it. FIPS 140-2, the earlier generation, is being retired, so 140-3 is what to specify on new procurement.

Underneath the certification it is a full multi-protocol key on firmware 5.7: FIDO2/WebAuthn passkeys, FIDO U2F, PIV smart card, OATH-TOTP and OATH-HOTP, OpenPGP, YubiKey OTP, static password, and HMAC-SHA1 challenge-response. In practice that covers phishing-resistant sign-in to Microsoft 365 and Entra ID, and it satisfies the Essential Eight multi-factor control without staff typing a code.

The connector is the reason to choose the 5Ci over the rest of the range. One end is USB-C, the other is Lightning, which suits someone who works on a USB-C laptop but still carries an older Lightning iPhone or iPad and wants a single validated key for both. There is no NFC and no battery, so you plug the key in rather than tapping it against a phone.

It is crush- and water-resistant with no moving parts, built to live on a keyring for years. Be clear-eyed about the trade-off, though: Lightning is being phased out. If your phones have already moved to USB-C, you do not need the dual connector, and a plain USB-C key will cost less. Choose the FIPS variant only when the paperwork demands it, not by default.

Rolling it out means registering each key against your directory, whether that is Entra ID, Google Workspace, or another identity provider. Register a second key per person as a backup at the same time, because a single lost key means a lockout.

Specifications

Certification
FIPS 140-3 validated (replaces the retiring 140-2)
Series
YubiKey 5 FIPS Series
Firmware
5.7
Connectors
Dual: USB-C and Lightning
NFC
None
Power
No battery, no moving parts
Durability
Crush- and water-resistant
Protocols
FIDO2/WebAuthn, FIDO U2F, PIV, OATH-TOTP/HOTP, OpenPGP, YubiKey OTP, static password, HMAC-SHA1

In the YubiKey 5 FIPS 140-3 Series

Same firmware and the same protocols across the range. What changes is the connector and whether it taps a phone.