Zero Assumptions #4: Your FIDO2 token passed the test. That doesn't mean it's safe.


Zero Assumptions · Week 4 of 25

Your FIDO2 token passed the certification test.
That means it's secure.

FIDO2 certification validates protocol compliance. It does not validate firmware integrity, chip supply chain, or where your authentication data goes after it leaves the device.

The decision to deploy hardware security keys is the right one. Where most organisations go wrong is treating that decision as finished once they have a FIDO2-certified product in hand. FIDO2 certification tells you one specific thing: the device correctly implements the FIDO2 protocol. It tells you nothing else.

The assumption in most enterprise procurement processes: if it's on the FIDO Alliance certified products list, it meets our security standard.

The reality: FIDO2 certification is a protocol compliance test. The chip supply chain, firmware integrity, and data residency of the manufacturer are entirely separate risks — and for regulated industries, they are material ones.

EAL5+

The Common Criteria Evaluation Assurance Level required for the secure element chips in high-assurance hardware tokens — a significantly higher bar than FIDO2 certification, which imposes no chip-level security requirement whatsoever.

Source: Common Criteria Recognition Arrangement (CCRA); ANSSI Security Visa programme

What the certification hierarchy actually covers

Understanding what each certification validates — and what it leaves uncovered — is the foundation of an informed procurement decision. Most organisations conflate them.

Certification What it validates Supply chain?
FIDO2 Protocol implementation only ✗ No
CC EAL4+ Security function testing against a defined threat model ✗ No
CC EAL5+ Side-channel & physical attack resistance ✗ Partial
CC EAL6+ Formal verification; highest smart card assurance — Feitian FT-JCOS ✓ Partial
ANSSI Visa Design, implementation & EU supply chain — NeoWave ✓ Yes
FIPS 140-3 L3 Physical tamper evidence — US federal standard ✗ No

The supply chain risk is not theoretical. Firmware manipulation at the manufacturing stage — inserting a persistent backdoor before a device ships — is a documented class of nation-state attack. CISA, NCSC, and ENISA have all published guidance on hardware supply chain integrity as a critical infrastructure concern.

For organisations in defence, critical infrastructure, financial services, and regulated healthcare: deploying tokens manufactured in jurisdictions with adversarial intelligence relationships introduces a risk that no software control can remediate after the fact.

This week from Ciptor

Our partner Feitian has just completed a chip-level post-quantum cryptography upgrade across its full FIDO and PKI product lines — adding a dedicated PQC hardware co-processor with native ML-KEM and ML-DSA support, now certified to CC EAL6+. The most forward-compatible enterprise authentication hardware available at scale today. Read the full breakdown →

The blueprint — tiered procurement by risk profile

Sovereign-first (NeoWave): Privileged users, executives, defence supply chain, classified data environments — where EU-origin supply chain and ANSSI certification are non-negotiable.

PQC-ready enterprise (Feitian EAL6+): Broader workforce deployment where the primary requirements are cryptographic assurance depth and long-term quantum readiness at scale.

The critical point: this should be an explicit decision made with full awareness of each device's supply chain risk profile — not an implicit one made by defaulting to the lowest-cost FIDO2-compatible option.

Series recap — where we are

Week 1 — The endpoint illusion: Your EDR is blind for 2–4 days. Remove the credential as a target.
Week 2 — Network-delivered codes: AiTM toolkits intercept your OTP. FIDO2 origin binding eliminates the attack.
Week 3 — The helpdesk open door: Deepfakes defeat KBA and Zoom checks. Cryptographic recovery closes the gap.
Week 4 — Sovereign hardware risk: FIDO2 certification ≠ secure supply chain. Know what you're actually buying.
Week 5 (next): Your cloud SSO is hardened. Your on-premises legacy systems are not. Attackers target the seam between them.

Coming up next week

Week 5 — The hybrid infrastructure blindspot
Your cloud SSO is hardened. Your on-premises Active Directory is not. Attackers target the seam — specifically Kerberos Golden Ticket paths that bypass every cloud MFA policy you've deployed.

Week 6 — Risk assessment integration
Annual compliance checklists tell you what your posture was. Continuous identity risk tracking tells you what it is right now — and where it's drifting.

Free passwordless audit

Do you know what certifications your current hardware tokens actually hold?

In a free 30-minute passwordless audit we'll review your hardware authentication stack, map your current certifications against your risk profile, and tell you whether your deployment matches the assurance level your environment actually requires.

No sales deck. No follow-up unless you ask.

A hardware security key is only as trustworthy as the integrity of the chip inside it. FIDO2 tells you the key works correctly. It does not tell you the key works exclusively for you.

Mikael Rodin
Managing Director, Ciptor

P.S. Evaluating hardware token procurement for 2026? Book a free audit — we'll map your specific deployment context against the certification table above and tell you exactly which tier matches your risk profile.

New to the series? Start at ciptor.com/zero-assumptions/zero-assumptions-vol-1/

Kungsporten 4A, 427 50 Billdal, Sweden
Unsubscribe · Preferences

Ciptor

The 2026 threat landscape doesn't care about your 2024 budget. It only cares about your vulnerabilities. Join 10,000+ infrastructure leaders securing the future.

Read more from Ciptor

Zero Assumptions · Week 9 of 25 · Pillar 2: Software stack & contextual risk Your SIEM fired an alert at 09:14.Your EDR caught the same attack at 09:24. Two tools. Same attacker. Ten minutes apart. Neither told the other. Your analyst saw two separate alerts in two separate consoles and triaged them as two separate incidents. The attacker had already moved. In weeks 6, 7, and 8 we covered the operational gaps between assessment cycles, session windows, and board oversight. This week we move...

Zero Assumptions · Week 8 of 25 · Pillar 2: Software stack & contextual risk Your board approved the security budget.That means they've fulfilled their NIS2 obligation. NIS2 Article 20 does not ask your board to approve a budget. It requires management bodies to oversee, be trained in, and be personally liable for your organisation's cybersecurity risk management. Most boards have done none of these things. Most CISOs have not told them. In every previous volume of this series, the assumption...

Zero Assumptions · Week 7 of 25 · Pillar 2: Software stack & contextual risk Your morning login was legitimate.So the session running at 17:00 must be too. Session tokens are hijacked, not phished. Once an attacker has your token, they don't need your password, your MFA, or your hardware key. They already passed authentication. The question is whether your SOC finds them before they find what they came for. Last week we covered identity drift — the entitlement state that diverges from policy...