
Nitrokey · Security key
EAL 6+ certified secure element, open-source firmware. FIDO2/WebAuthn, OpenPGP, OTP, PIV smart card. USB-C + NFC. The open-source alternative to YubiKey.
$80
EU equivalent: €65 incl. VAT · nitrokey.comShips direct from Nitrokey (Germany) · typically 5–10 business days
Vegas batch closed — buy direct on Nitrokey, or get notified when the next bulk batch opens.
The Vegas batch has closed. Need it now? Buy direct on Nitrokey. Rather wait for the next bulk run — group pricing, PO/invoicing, and event pickup? Tell us what you’d order and we’ll email you the moment it opens. No commitment; enough interest is what schedules the next batch.
No battery
No battery. Ships by any service with no dangerous-goods restrictions.
What to build with it
ciso.diy build guides name this exact machine in their build sheet. The hardware is the easy half — these are the documents that tell you what to put on it and how to keep it honest.
The Operator Node — DIY Build GuideTurn this machine into the box a security program runs on: the living risk register, the ISMS and the evidence vault, off production, reachable only over a zero-trust mesh, on your own keys. Six build steps with the commands, plus a fillable build-day runbook.SOC in a Box — the Pillar 04 hardware buildThe detection and monitoring stack landed on one machine you hold — the hardware half of the AI-SOC pillar, with the sizing, the layout and the trade-offs written down.The 2026 AI Risk RegisterIts Tier 2 build sheet is an air-gapped Register Node: a completed AI risk register is a manifest of every AI system you run and every credential scope your agents hold, which is a good argument for it living on hardware with no inbound path. The whole program as build guides →Why the Nitrokey 3C NFC
What this security key does that alternatives don't.
EAL 6+ certified secure element
OpenPGP key material is held in an NXP SE050 secure element certified to Common Criteria EAL 6+ — the assurance class used for government smart cards.
Fully open-source firmware
All firmware source code is public. No hidden backdoors, no closed attestation keys. The security community can and does audit it.
EU jurisdiction
German company, German law. For principals who prefer hardware not subject to US National Security Letters or FISA court gag orders.
Specifications
Full technical details.
Compliance framework mapping
Controls this product satisfies across 12 frameworks.
Multi-factor authentication — hardware-bound
Phishing-resistant MFA using hardware security keys. Software TOTP and SMS are explicitly excluded from "phishing-resistant" in NIST 800-63B and most modern framework guidance.
Cryptographic key management
Hardware-bound key generation and storage. Private keys generated and stored inside a certified secure element (EAL 6+) and are non-exportable by design — for login credentials (Nitrokey) and crypto-asset custody (Ledger) alike.
Supply chain risk — hardware and firmware
Open-source firmware is publicly auditable and reproducibly built. EU jurisdiction hardware is not subject to US National Security Letters. Directly addresses hardware supply chain risk in CMMC and NIS2.
Compared to
Honest comparisons against the most likely alternatives.
vs YubiKey 5C NFC ($55)
Both use an EAL 6+ certified secure element — certification is a wash. The real difference: YubiKey firmware is closed source, Nitrokey is fully open and auditable, and Nitrokey adds OpenPGP 3.4 and a password manager. YubiKey wins on FIPS validation and ecosystem breadth.
vs Google Titan Security Key
Titan is FIDO2-only. Nitrokey 3 adds OpenPGP, PIV smart card, OTP, and a password manager. Titan firmware is closed.
vs software 2FA (TOTP apps)
TOTP apps live on a phone that can be compromised. Hardware keys are phishing-resistant by design — the secret never leaves the device.
Shipping & returns
What to expect after you order.
Shipping
Ships from our Tennessee 3PL. 2-day FedEx to most US addresses, expedited options at checkout. Signature required. Business day processing — orders placed before 2pm ET ship same day.
Returns & RMA
30-day return window for unopened units. Defective units handled under Nitrokey's 2-year warranty — we manage the US-side RMA so you don't ship to Berlin.
Purchase orders
Net-30 terms available for approved organizations. W-9 on file. Generate a quote from the stack builder or email sales@securitygadgets.shop with your PO requirements.
Authorized reseller
We are an official Nitrokey authorized reseller. Full manufacturer warranty applies. Identical hardware and firmware to buying direct from nitrokey.com — with US inventory and support.
Comparing with YubiKey?
See the full YubiKey lineup on Amazon — and the honest side-by-side of where each key actually wins →
Related products