

Swissbit makes the digital world safer and more convenient by protecting users’ digital identities – on websites, in applications, across online services, and within company networks. It even secures physical access control. 90% of internet users are concerned about having their passwords compromised – and not without reason. Compromised credentials are the most common cause of malicious attacks, accounting for 61% of breaches. The Swissbit iShield Key series offers the strongest authentication, simultaneously simple, secure, and flexible. It actively protects users from online attacks, such as phishing, social engineering, and account takeover.
The iShield Key 2 is a foundational element of a Zero Trust strategy, facilitating the implementation of MFA and compliance with regulatory requirements such as NIS2, CRA, DORA, and the U.S. Executive Order on cybersecurity. With the MIFARE and FIPS variants, it sets new standards: It is the first FIDO security key to feature MIFARE DESFire EV3 or a FIPS 140-3 Level 3 certification - ensuring maximum security for demanding application.
The new Swissbit iShield Key 2 combines digital and physical access control in one device, enabling seamless authentication for IT systems, buildings, secure printing solutions, and more. As a hybrid key, it integrates effortlessly into daily workflows and supports a comprehensive security strategy. Businesses can quickly elevate their security while gradually introducing new features.
The Swissbit iShield Key 2 is a key component of a Zero Trust approach, supporting MFA implementation and ensuring compliance with regulatory standards such as NIS2, CRA, DORA, and the U.S. Executive Order on cybersecurity.
With MIFARE and FIPS variants, it sets new industry standards, being the first FIDO security key to offer MIFARE DESFire EV3 or FIPS 140-3 Level 3 certification, delivering maximum security for even the most demanding applications.
| iShield Key 2 (USB-C / NFC) | iShield Key 2 (USB-A / NFC) | |
|---|---|---|
| Series Name | ||
| Form Factor / Device Type | CCID Smartcard, FIDO | CCID Smartcard, FIDO |
| Mechanical Details | 60 x 16,0 x 5,2 mm, | 65 x 16,0 x 5,2 mm, |
| Temperature Range | Operational: -25 °C to 70 °C
Storage: -25 °C to 85 °C | Operational: -25 °C to 70 °C
Storage: -25 °C to 85 °C |
| Certifications | FIPS140-3 L3: Crypto | FIPS140-3 L3: Crypto |
| Supported Operating Systems | Windows 10/11, MacOS | Windows 10/11, MacOS |
| Supported Browsers | Firefox, MS Edge, Ch | Firefox, MS Edge, Ch |
| Secure Chip | NXP P71D600
OS: JCOP 4.5 | NXP P71D600
OS: JCOP 4.5 |
| Algorithms | RSA: 2048, 3072, 4096
ECDSA: 224, 256, 384, 512 | RSA: 2048, 3072, 4096
ECDSA: 224, 256, 384, 512 |
| Options | MIFARE DESFire EV3,
HID SEOS, | MIFARE DESFire EV3,
HID SEOS, |
| Compliance | CE, FCC, UKCA, RoHS, | CE, FCC, UKCA, RoHS, |
| Shipping information options | CSV file containing | CSV file containing |
Downloads with a symbol are only available after loginOnly available after login
The iShield Key series is compatible with all FIDO2-compliant websites and services, such as Google, Microsoft, Salesforce, Amazon, and more. The all-in-one security key provides NFC and USB connectivity for versatile use.
By supporting zero-trust strategies, the iShield Key series ensures that only verified users can access your systems. It is engineered to be phishing-resistant and facilitates secure digital document signing and encryption.
The iShield Key series supports multiple authentication options and offers both a standard FIDO solution and an on-premises solution for flexible deployment scenarios, that’s fully compatible with access control.
This video requires marketing cookies to be enabled.
How to manage your iShield Key 2
with iShield Key Manager
This video requires marketing cookies to be enabled.
How to register and sign in to online accounts
with iShield Key 2
This video requires marketing cookies to be enabled.
Swissbit has looked into several use cases and identified the challenges, the Swissbit solution and its benefits. Download the iShield Key 2 brochure and the use case analysis by clicking on the images.

Want to know where you can use passkeys today? The fido Alliance Passkeys Directory is an interactive resource that lists active FIDO passkey implementation examples, both for consumers and in the workforce.
Enterprises across all industries face a growing need to protect their intellectual property, company data, and customer data from sophisticated cyber threats. The iShield Key series fortifies company networks, ensuring that operations remain secure and uninterrupted.
For governmental agencies, safeguarding national security and citizens' data is paramount. Swissbit's iShield Key series delivers secure authentication mechanisms that comply with rigorous standards, protecting sensitive information from cyber espionage and unauthorized access.
public sector organizations strive to deliver essential services to the community. Swissbit's security keys provide robust login authentication to defend against cyber-attacks, ensuring the resilience and reliability of the public sector's digital services
Critical infrastructure sectors such as utilities, finance, and healthcare are under constant threat from cyber-attacks that can have severe consequences on public safety and economic stability. The iShield Key series ensures operational continuity and public trust.
Check our partner data base for companies close to you where you can buy the Swissbit iShield Key 2
If you're a professional looking to evaluate the Swissbit iShield Key 2, you can order free samples for your company. Experience the iShield Key 2 firsthand and see its benefits for yourself.

Access the Swissbit Knowledge Base to get more information on implementations, and learn from experts.
This is your hub to get the support you need.
Get in touch with us and discuss your requirements with us.
Find the local, regional, and worldwide sales contacts.
Swissbit provides a multi-channel support model that includes a dedicated Knowledge Base, free evaluation samples with personal support, and direct access to engineering expertise. This structure helps healthcare IT teams assess phishing-resistant authentication solutions against regulatory requirements before deployment.
Swissbit provides healthcare technology evaluators with a structured support ecosystem designed to accelerate evaluation and implementation. The company’s Knowledge Base serves as a central resource for technical documentation and implementation guidance. Free evaluation samples of the iShield Key 2 are also available to qualified professionals.
Each request is reviewed individually and is accompanied by personal support as part of a partner-assisted evaluation process. In addition to self-service resources, Swissbit provides direct contact channels for product questions, technical support, quotations, and access to documentation. The support model also includes local assistance from Field Application Engineers (FAEs) and direct access to engineering teams.
This is particularly useful when authentication solutions must be integrated into existing electronic health record systems. Healthcare-specific documentation is available as a dedicated use-case analysis mapping iShield Key 2 capabilities to clinical workflows such as access to emergency departments, radiology systems, and operating rooms.
This targeted documentation reduces the effort required for IT teams to validate solutions against HIPAA requirements and patient-safety standards. The iShield Key Manager software, available for Windows, macOS, and Linux, also provides configuration tools for WebAuthn/FIDO2, TOTP, HOTP, and PIV protocols during evaluation.
Swissbit offers a FIPS 140-3 Level 3 variant of the iShield Key 2, which the company describes as the first FIDO security key to achieve this certification level. The device also includes a CC EAL6+-rated Secure Element, addressing stringent cryptographic validation requirements in healthcare.
The Swissbit iShield Key 2 includes a FIPS 140-3 Level 3 version designed specifically for organizations operating under federal or healthcare-specific regulatory frameworks. According to Swissbit, this version is the first FIDO security key to achieve FIPS 140-3 Level 3 certification.
The underlying hardware uses an NXP P71D600 chip with JCOP 4.5 and 600 KB of flash memory and incorporates a CC EAL6+-rated Secure Element. The iShield Key 2 supports FIDO2/CTAP2.1 and U2F protocols, helping defend directly against password-based attacks.
Swissbit’s healthcare documentation specifically references FIPS 140-3 Level 3 and CC EAL6+ certifications in connection with patient records, secure portals, and clinical access control. The device can store up to 300 passkeys and 42 OTP/password slots, allowing multiple system credentials to be stored on a single FIPS-validated token.
It also supports PIV with up to 25 certificate slots. Remote firmware and application updates allow security patches to be deployed without physically collecting devices, simplifying ongoing compliance maintenance.
Swissbit manufactures the iShield Key 2 in Berlin, Germany, with end-to-end in-house control over hardware and firmware development. This European supply-chain model provides component auditability and traceability, supporting healthcare vendor-security assessments.
Swissbit positions its Berlin manufacturing facility as a key differentiator for organizations conducting supply-chain security reviews. The company develops both its hardware and firmware internally. According to Swissbit, this provides full transparency and enables customization for industrial environments.
The Berlin production facility covers more than 10,000 m², including 2,600 m² of cleanroom production space, and supports production of up to two million units per month depending on the product mix. Around 200 specialists in manufacturing, engineering, and quality assurance operate the facility.
Swissbit emphasizes direct access to its manufacturing facility and traceability of component origins. The company holds certifications including ISO 9001, IATF 16949, ISO 14001, and ISO 27001.
All products use a frozen Bill of Materials (BOM). Any change to the BOM triggers a Product Change Notification (PCN). This governance model helps reduce requalification effort where regulatory requirements require hardware configurations to be documented.
Swissbit follows a frozen-BOM policy with Product Change Notifications, advance End-of-Life notifications, and product-availability commitments of up to 10 years. The company reports quality defect rates consistently below 100 defective parts per million across its portfolio.
Swissbit’s lifecycle-governance model is intended to address the long-term planning requirements of healthcare technology deployments. The company commits to product availability of up to 10 years, allowing healthcare organizations to standardize authentication hardware without frequent replacement cycles.
All Swissbit products use a frozen BOM, meaning component specifications remain stable throughout the product lifecycle. When changes are required, Swissbit issues Product Change Notifications so purchasing and compliance teams receive advance notice.
End-of-Life transitions include extended notification and transition periods to reduce operational disruption during device-refresh cycles. Swissbit reports defect rates consistently below 100 DPPM (defective parts per million).
The company also emphasizes DIFOT — Delivery In Full, On Time — performance. Early samples of replacement products allow IT teams to evaluate successor devices before existing models reach End of Life.
The iShield Key 2 itself carries an IP68 rating, operates from -25 °C to 70 °C, and can be stored at temperatures from -25 °C to 85 °C.
The iShield Key 2 combines digital authentication using FIDO2 passkeys with physical access-control technologies including MIFARE DESFire EV3, HID Seos, and LEGIC in a single token. This supports healthcare workflows where employees need access to both IT systems and secured physical areas during their shifts.
The iShield Key 2 acts both as a phishing-resistant digital authenticator and as a physical access credential. It supports MIFARE DESFire EV3 and, optionally, HID Seos and LEGIC advant/neon protocols for integration with physical access-control systems.
Swissbit positions this single-token approach as part of a Zero Trust architecture, enabling consistent identity verification across digital and physical environments.
Healthcare-specific documentation maps the device’s capabilities to clinical scenarios including emergency departments, radiology, maternity wards, parking areas, central hospital systems, and operating rooms.
Both USB-A and USB-C versions include NFC functionality, enabling tap-based authentication with compatible readers.
For healthcare IT teams managing frequent staff changes, combining digital and physical access in one credential can simplify both provisioning and deprovisioning.
The compact form factor — 65 × 16 × 5.2 mm for USB-A and 60 × 16 × 5.2 mm for USB-C, both weighing 5 g — also allows the device to be attached to lanyards or badge reels commonly used in clinical environments.
Swissbit provides lifecycle-controlled supply with product availability of up to 10 years, a frozen Bill of Materials, and formal change-notification processes. This approach allows utilities to maintain consistent hardware configurations while meeting long-term regulatory and operational requirements.
Swissbit provides lifecycle management intended for critical-infrastructure environments where component consistency and long-term availability are essential.
The company maintains a frozen BOM across its products. Any change to the configuration triggers a formal Product Change Notification with advance customer notice.
Product availability can extend for up to 10 years, matching the long operating lifetimes of power-generation and distribution systems. Swissbit’s long-term component sourcing and obsolescence management are intended to reduce the risk of forced hardware refreshes affecting operational-technology systems.
Continuous technical support is available throughout the product lifecycle, allowing customers to continue accessing engineering assistance years after initial deployment.
For utilities operating systems that serve millions of customers, this structured lifecycle approach provides greater predictability for budgeting and compliance documentation.
Swissbit holds certifications including ISO 9001, IATF 16949, ISO 14001, and ISO 50001 and performs 100% testing across the complete specification range. The company reports defect rates consistently below 100 DPPM, providing auditable quality metrics for regulated environments.
Swissbit’s certified quality-management system addresses documentation and verification requirements commonly encountered in energy-sector security assessments.
The company holds ISO 9001 for quality management, IATF 16949 for automotive-grade quality standards, ISO 14001 for environmental management, and ISO 50001 for energy management.
Every Swissbit product undergoes 100% testing across its entire specification range rather than relying solely on sample-based quality testing.
The company reports defect rates consistently below 100 DPPM. Its Berlin manufacturing facility covers more than 10,000 m² and employs around 200 specialists in manufacturing, engineering, and quality assurance, with production capacity of up to two million units per month depending on product mix.
This combination of certifications, comprehensive testing, and measurable defect rates provides documentation that can support regulatory audits.
Swissbit provides direct access to design, system, and firmware engineers through local Field Application Engineering teams worldwide. Support is available in local languages and time zones and includes technical documentation and design-in assistance.
Swissbit structures its technical support so that integrators can communicate directly with engineers involved in developing its hardware and firmware.
Customers can access design engineers, system engineers, and firmware engineers rather than routing every request through general support channels.
Worldwide Field Application Engineering teams operate in local languages and time zones. Technical documentation includes application notes covering topics such as secure-boot configuration, SEDutil Opal setup, power-failure testing, and disk-imaging procedures.
The Swissbit Device Manager software also provides visibility into device information including ATA Model ID, serial number, firmware version, reserve blocks, erase cycles, and ECC/CRC counters.
This level of engineering support is intended to reduce integration risks in security-hardware retrofit projects and other OT environments.
Swissbit offers retrofit-focused security products including the Security Upgrade Kit and iShield HSM, designed for deployment in existing embedded systems. These solutions add hardware-based authentication and secure storage without requiring a complete system redesign.
Swissbit positions its Security Upgrade Kit (PS-66u) and iShield HSM specifically as retrofit solutions for embedded systems already deployed in operational environments.
The Security Upgrade Kit is a microSD-format security module for Linux-based embedded systems, available in capacities of 16 GB, 32 GB, and 64 GB. It provides AES-256 encryption, access control, and secure-boot support.
It operates from -40 °C to 85 °C, measures 15.0 × 11.0 × 0.7 mm, and complies with SD 6.10. It supports read speeds of up to 90 MB/s and write speeds of up to 75 MB/s. Data retention is specified at 10 years at the beginning of life, and the card is designed for 20,000 insertion/removal cycles.
The iShield HSM acts as a plug-and-play USB security anchor that can retrofit systems such as AWS IoT Greengrass installations. Private keys and certificates are stored in hardware in a CC EAL6+-rated Secure Element.
It supports PKCS#11 and PKCS#15 and is qualified for AWS IoT Greengrass Hardware Security Integration.
Swissbit provides dedicated engineering support and global Field Application Engineering teams throughout deployment. Support includes direct access to firmware engineers, technical documentation, and design-in assistance tailored to enterprise security environments.
Swissbit provides a support model designed for enterprise deployments and the integration complexity financial institutions may encounter when rolling out hardware-based authentication at scale.
The company provides dedicated account management as well as direct access to design, system, and firmware engineers familiar with banking security requirements.
Global Field Application Engineering teams work with security teams to resolve integration challenges involving existing identity and access-management platforms.
Technical documentation and application notes are available to accelerate design-in processes, including integration with online-banking platforms and regulatory technology systems.
Swissbit also emphasizes continued technical support beyond initial procurement.
Swissbit operates a Knowledge Base designed as a central resource for implementation guidance and expert knowledge. Free evaluation samples with personal support are also available to security teams conducting technical assessments.
Swissbit provides a Knowledge Base containing implementation guidance for security teams introducing FIDO2- and passkey-based authentication.
For hands-on evaluation, Swissbit offers free evaluation samples to companies. Each request is reviewed individually to ensure appropriate technical coordination, and the evaluation process includes personal assistance.
The combination of self-service documentation and supported sample programs enables security teams to validate compatibility with existing integrations and scalability requirements before proceeding with a broader deployment.
Swissbit’s support resources also include technical training through Field Application Engineering teams, supporting internal knowledge transfer to security-operations staff responsible for ongoing key management.
The iShield Key 2 supports up to 300 passkeys per device, allowing security architects to assess whether its capacity meets planned user-registration requirements.
Swissbit operates an RMA portal for product returns and states that it handles warranty claims promptly and carefully. This structured process supports the operational continuity required by financial institutions for authentication infrastructure.
Swissbit provides an RMA portal through which security teams can initiate returns by email or form submission.
For financial institutions managing authentication tokens across large user populations, a predictable RMA process can help maintain security and user experience.
The iShield Key 2 is designed to industrial durability standards. It provides IP68 protection against dust and water ingress, shock resistance of 1,500 g, and an MTBF of more than 4,000,000 hours at 25 °C.
Swissbit targets defect rates below 100 DPPM and performs 100% testing across the complete specification range.
When a problem does occur, the formal RMA process provides documented handling that can support audit trails and third-party risk-management processes.
Swissbit guarantees a frozen Bill of Materials, formal Product Change Notifications, and product availability of up to 10 years. Continuous technical support throughout the lifecycle addresses regulatory expectations concerning vendor stability.
Swissbit’s lifecycle-governance framework is designed to address procurement and compliance requirements in regulated financial environments by offering product availability of up to 10 years.
All products use a frozen Bill of Materials. Component changes therefore trigger formal Product Change Notifications, allowing security teams to evaluate planned changes and respond accordingly.
Continuous technical support throughout the product lifecycle ensures that engineering expertise remains available as organizational requirements change.
The iShield Key 2 also supports remote updates through secure-channel protocols, allowing new firmware and applications to be deployed in the field without physically replacing devices.
Swissbit cites its long-standing industrial experience and more than 450 specialists across R&D, manufacturing, and customer support as part of the organizational resources supporting these lifecycle commitments.
Swissbit manufactures iShield Key 2 devices in Berlin using 100% testing and targets defect rates below 100 DPPM. This quality-focused approach is intended to provide the authentication reliability required by financial institutions.
Swissbit’s Berlin manufacturing facility provides more than 10,000 m² of production space and capacity of up to two million units per month, depending on product mix.
The company targets defect rates below 100 DPPM through 100% testing across the complete specification range, meaning each device is tested before shipment.
The iShield Key 2 has an MTBF of more than 4,000,000 hours at 25 °C. Physical durability specifications include an operating-temperature range of -25 °C to 70 °C and IP68 protection against water and dust.
Swissbit develops its hardware and firmware internally and emphasizes transparency and traceability of components within its European supply chain. These characteristics can support third-party risk assessments in regulated financial environments.