Zero Assumptions · Week 4 of 25
Your FIDO2 token passed the certification test. That means it's secure.
FIDO2 certification validates protocol compliance. It does not validate firmware integrity, chip supply chain, or where your authentication data goes after it leaves the device.
|
The decision to deploy hardware security keys is the right one. Where most organisations go wrong is treating that decision as finished once they have a FIDO2-certified product in hand. FIDO2 certification tells you one specific thing: the device correctly implements the FIDO2 protocol. It tells you nothing else.
The assumption in most enterprise procurement processes: if it's on the FIDO Alliance certified products list, it meets our security standard.
The reality: FIDO2 certification is a protocol compliance test. The chip supply chain, firmware integrity, and data residency of the manufacturer are entirely separate risks — and for regulated industries, they are material ones.
|
EAL5+
The Common Criteria Evaluation Assurance Level required for the secure element chips in high-assurance hardware tokens — a significantly higher bar than FIDO2 certification, which imposes no chip-level security requirement whatsoever.
Source: Common Criteria Recognition Arrangement (CCRA); ANSSI Security Visa programme
|
What the certification hierarchy actually covers
Understanding what each certification validates — and what it leaves uncovered — is the foundation of an informed procurement decision. Most organisations conflate them.
| Certification |
What it validates |
Supply chain? |
| FIDO2 |
Protocol implementation only |
✗ No |
| CC EAL4+ |
Security function testing against a defined threat model |
✗ No |
| CC EAL5+ |
Side-channel & physical attack resistance |
✗ Partial |
| CC EAL6+ |
Formal verification; highest smart card assurance — Feitian FT-JCOS |
✓ Partial |
| ANSSI Visa |
Design, implementation & EU supply chain — NeoWave |
✓ Yes |
| FIPS 140-3 L3 |
Physical tamper evidence — US federal standard |
✗ No |
The supply chain risk is not theoretical. Firmware manipulation at the manufacturing stage — inserting a persistent backdoor before a device ships — is a documented class of nation-state attack. CISA, NCSC, and ENISA have all published guidance on hardware supply chain integrity as a critical infrastructure concern.
For organisations in defence, critical infrastructure, financial services, and regulated healthcare: deploying tokens manufactured in jurisdictions with adversarial intelligence relationships introduces a risk that no software control can remediate after the fact.
|
This week from Ciptor
Our partner Feitian has just completed a chip-level post-quantum cryptography upgrade across its full FIDO and PKI product lines — adding a dedicated PQC hardware co-processor with native ML-KEM and ML-DSA support, now certified to CC EAL6+. The most forward-compatible enterprise authentication hardware available at scale today. Read the full breakdown →
|
|
The blueprint — tiered procurement by risk profile
Sovereign-first (NeoWave): Privileged users, executives, defence supply chain, classified data environments — where EU-origin supply chain and ANSSI certification are non-negotiable.
PQC-ready enterprise (Feitian EAL6+): Broader workforce deployment where the primary requirements are cryptographic assurance depth and long-term quantum readiness at scale.
The critical point: this should be an explicit decision made with full awareness of each device's supply chain risk profile — not an implicit one made by defaulting to the lowest-cost FIDO2-compatible option.
|
|
Series recap — where we are
Week 1 — The endpoint illusion: Your EDR is blind for 2–4 days. Remove the credential as a target.
Week 2 — Network-delivered codes: AiTM toolkits intercept your OTP. FIDO2 origin binding eliminates the attack.
Week 3 — The helpdesk open door: Deepfakes defeat KBA and Zoom checks. Cryptographic recovery closes the gap.
Week 4 — Sovereign hardware risk: FIDO2 certification ≠ secure supply chain. Know what you're actually buying.
Week 5 (next): Your cloud SSO is hardened. Your on-premises legacy systems are not. Attackers target the seam between them.
|
Coming up next week
Week 5 — The hybrid infrastructure blindspot
Your cloud SSO is hardened. Your on-premises Active Directory is not. Attackers target the seam — specifically Kerberos Golden Ticket paths that bypass every cloud MFA policy you've deployed.
Week 6 — Risk assessment integration
Annual compliance checklists tell you what your posture was. Continuous identity risk tracking tells you what it is right now — and where it's drifting.
|
Free passwordless audit
Do you know what certifications your current hardware tokens actually hold?
In a free 30-minute passwordless audit we'll review your hardware authentication stack, map your current certifications against your risk profile, and tell you whether your deployment matches the assurance level your environment actually requires.
No sales deck. No follow-up unless you ask.
|
A hardware security key is only as trustworthy as the integrity of the chip inside it. FIDO2 tells you the key works correctly. It does not tell you the key works exclusively for you.
Mikael Rodin
Managing Director, Ciptor
P.S. Evaluating hardware token procurement for 2026? Book a free audit — we'll map your specific deployment context against the certification table above and tell you exactly which tier matches your risk profile.
New to the series? Start at ciptor.com/zero-assumptions/zero-assumptions-vol-1/