Nitrokey · Security key
USB-A variant of the Nitrokey 3 with NFC. Same EAL 6+ secure element and open-source firmware as the 3C. For legacy hardware without USB-C or as a backup key.
$69
EU equivalent: €47 incl. VAT · nitrokey.comIn stock · ships in 1 business day
QUANTITY
Why the Nitrokey 3A NFC
What this security key does that alternatives don't.
USB-A for legacy hardware
Many enterprise environments still use USB-A only. The 3A NFC is the right key when you can't use USB-C adapters — servers, older workstations, kiosks.
Pair with 3C as backup
Best practice is always two hardware keys enrolled. Pair a 3C NFC (USB-C, carry daily) with a 3A NFC (USB-A, stored in a safe) for full redundancy.
EAL 6+ and open source
Same secure element and firmware as the 3C. The only difference is the connector. All protocols and certifications are identical.
Specifications
Full technical details.
Compliance framework mapping
Controls this product satisfies across 7 frameworks.
Multi-factor authentication — hardware-bound
Phishing-resistant MFA using hardware security keys. Software TOTP and SMS are explicitly excluded from "phishing-resistant" in NIST 800-63B and most modern framework guidance.
Cryptographic key management
Hardware-bound key generation and storage. Private keys generated and stored inside a certified secure element (EAL 6+) and are non-exportable by design.
Supply chain risk — hardware and firmware
Open-source firmware is publicly auditable and reproducibly built. EU jurisdiction hardware is not subject to US National Security Letters. Directly addresses hardware supply chain risk in CMMC and NIS2.
Compared to
Honest comparisons against the most likely alternatives.
vs Nitrokey 3C NFC
Identical security. USB-A vs USB-C connector is the only difference. Choose based on your port availability.
vs YubiKey 5 NFC ($55)
Same connector. Nitrokey 3A is EAL 6+ vs YubiKey's EAL 5, open-source firmware vs closed, and adds OpenPGP 3.4 and password manager.
Shipping & returns
What to expect after you order.
Shipping
Ships from our Tennessee 3PL. 2-day FedEx to most US addresses, expedited options at checkout. Signature required. Business day processing — orders placed before 2pm ET ship same day.
Returns & RMA
30-day return window for unopened units. Defective units handled under Nitrokey's 2-year warranty — we manage the US-side RMA so you don't ship to Berlin.
Purchase orders
Net-30 terms available for approved organizations. W-9 on file. Generate a quote from the stack builder or email sales@securitygadgets.shop with your PO requirements.
Authorized reseller
We are an official Nitrokey authorized reseller. Full manufacturer warranty applies. Identical hardware and firmware to buying direct from nitrokey.com — with US inventory and support.
Related products