The Standard and Nano have been FIPS 140-2 certified to Level 1. Will the Yubico be seeking similar certification for the NEO and if so, what level of certification do to anticipate it receiving? In particular, do you anticipate that it could meet the requirements of NIST SP 800-63-1 Level 4?
Quote:
Level 4 – Level 4 is intended to provide the highest practical remote network authentication assurance. Level 4 authentication is based on proof of possession of a key through a cryptographic protocol. At this level, in-person identity proofing is required. Level 4 is similar to Level 3 except that only “hard” cryptographic tokens are allowed. The token is required to be a hardware cryptographic module validated at Federal Information Processing Standard (FIPS) 140-2 Level 2 or higher overall with at least FIPS 140-2 Level 3 physical security. Level 4 token requirements can be met by using the PIV authentication key of a FIPS 201 compliant Personal Identity Verification (PIV) Card.