Ukraine solidarity. Service offered free to Ukrainian businesses for as long as the war lasts. Request free access
Security, recommended hardware

Recommended hardware keys.

A hardware FIDO2 key remains the strongest form of second factor and vault unlock. We highlight European manufacturers, aligned with ARDNTECH's sovereign positioning, and set out the known reservations for the others.

Reassurance document, revised on 01/08/2026, updated with every major change to the manufacturer catalogue.

Assessment criteria. For each model, we examine four elements: the publisher's country and applicable jurisdiction, the openness of the code (firmware and hardware), exposure to the CLOUD Act or other extraterritorial laws, and the maturity of the community programme. All the keys mentioned are WebAuthn / FIDO2 compatible and work immediately with ARDNTECH.

The aim is not to disparage any brand but to propose a hierarchy consistent with ARDNTECH's sovereign promise. Organisations already equipped can continue to use their existing keys: the entire range below interoperates.

01 / Primary recommendation

Nitrokey 3 , Berlin, Germany.

Our primary recommendation for new organisations. Fully open source hardware and firmware, mature range and active community programme.

Why this key comes first

  • Open source Trussed firmware, written in Rust, shared with SoloKey. The public auditability of the embedded code removes any grey area about the behaviour of the secure component.
  • Open source hardware: published electronic schematics, free design. An organisation can, in theory, have the key manufactured by a trusted third party.
  • German jurisdiction, GDPR-aligned, with no exposure to the CLOUD Act or FISA. The publishing company is based in Berlin.
  • WebAuthn PRF supported since firmware 1.5, which makes the key compatible with unlocking the ARDNTECH vault without re-entering the master password.
  • Active community programme: open documentation, public bug trackers, regular release cadence.

View the Nitrokey catalogue

02 / Open source alternative

SoloKey v2 , Berlin, Germany.

A European alternative with a profile very similar to Nitrokey, with more distributed governance and an editorial emphasis on open source radicalism.

Profile and differences with Nitrokey

  • 100% open source end to end, Trussed firmware shared with Nitrokey. The two projects have historically been close and contribute to the same technical foundation.
  • Distributed governance, active community, smaller team. The release pace is less commercial and more community-driven.
  • German jurisdiction, equivalent European sovereign positioning.
  • Preferred use case: for organisations that want an even more minimalist dedicated supplier, or that wish to diversify between two European players sharing the same foundation.

View the SoloKey catalogue

03 / Swiss alternative

Token2 Release 2 , Vevey, Switzerland.

An independent Swiss publisher, with a more modest range but of interest to organisations that favour Swiss jurisdiction or are looking for a smart card format.

Profile and positioning

  • Swiss jurisdiction, outside the EU but with GDPR adequacy equivalence. No CLOUD Act exposure.
  • FIDO2 and smart cards. A shorter catalogue than Nitrokey, but it includes specific formats (contactless cards) useful for certain physical enterprise uses.
  • Proven product maturity, decent documentation coverage, but a smaller community than the two Berlin options.
  • Preferred use case: supplier diversification or a requirement to align with a Swiss group policy.

View the Token2 catalogue

04 / Compatible, with a reservation

YubiKey 5 , United States.

The historical de facto standard for consumer FIDO2. Works with ARDNTECH without technical reservation. We explicitly document the legal reservation that justifies its position on this page.

Sovereign reservation

Yubico is a US company, subject to the CLOUD Act and more broadly to federal extraterritorial laws. The hardware key itself remains a local component and FIDO2 cryptography works offline; however, the software ecosystem, the management services and the supply chain fall under an extra-European jurisdiction. For ARDNTECH, whose differentiator is precisely full European sovereignty, recommending YubiKey as the first choice would create an editorial inconsistency.

Cases where it remains relevant

  • Organisations that have already invested in a YubiKey fleet and the associated ecosystem (YubiEnterprise, YubiHSM). No reason to throw away working keys: they work as they are with ARDNTECH.
  • A need for a FIPS 140-3 certified or PIV-compatible key and an inability to find the equivalent in the European range at the time of purchase.
  • Group policy requiring purchase from an internationally referenced manufacturer catalogue.

View the YubiKey catalogue

Comparative summary

An overview of the four options across the criteria that weigh in the sovereign decision.

Key Jurisdiction Open hardware Open firmware CLOUD Act Position
Nitrokey 3 Germany Yes Yes (Trussed) No Recommended
SoloKey v2 Germany Yes Yes (Trussed) No Open source alternative
Token2 Release 2 Switzerland Partial Partial No Swiss alternative
YubiKey 5 United States No No Exposed Compatible, with a reservation

Need advice on your fleet?

If you are assessing the deployment of FIDO2 keys across an entire organisation and a trade-off between the options above is holding you back, write to us. We support organisations in the ARDNTECH qualification phase on this choice free of charge.