PIV and PKI Smart Cards: A Buyer’s Guide to FIPS 201-3 Compliant Credentials

You are procuring credentials for a federal agency, a state ID program, or an enterprise that must interoperate with government systems. Someone hands you a quote for “smart cards,” but the fine print never says whether they are actually PIV-compliant. This guide walks B2B buyers through what a PIV/PKI credential is, the FIPS 201-3 standard behind it, how to choose the right interface and card operating system, and exactly what to write into your RFQ so you do not end up with expensive plastic that fails acceptance.

What a PIV Credential Actually Is — and Why PKI Lives Inside It

A PIV-grade smart card shown beside ordinary plastic cards, illustrating that a PIV credential is not commodity plastic
A PIV card is a commissioned credential, not a shelf product — the PKI inside is what makes it trustworthy.

A PIV card is a smart card that carries a federal identity credential: the holder’s photo, name, agency, and a set of cryptographic keys bound to that identity. The “PIV” part is the physical and logical profile; the “PKI” part is what makes it trustworthy. Inside the secure element sit one or more key pairs — for example an asymmetric PIV authentication key, a digital-signature key, and a key-management key — plus an X.509 certificate chain issued by a trusted certificate authority. None of those private keys can be exported; that is the entire point. When an employee taps the card at a reader, the chip proves “this is me” using a challenge-response handshake, not a shared secret that can be copied or cloned.

For a B2B buyer, the practical takeaway is simple: a PIV card is not a product you buy off a shelf — it is a credential you commission, with certificates issued into a managed public-key infrastructure. If a supplier talks only about the plastic and never about the certificate authority, the applet, and the key custody, stop the conversation. Our smart card key-management guide lists the clauses you should demand before any purchase order is released.

FIPS 201-3: The Standard That Makes a Card “PIV”

A secure smart card production line representing the FIPS 201-3 manufacturing and quality controls behind PIV cards
FIPS 201-3 is enforced through certified manufacturing, testing, and an approved-products listing — not just artwork.

PIV is defined by NIST Federal Information Processing Standard 201-3 (FIPS 201-3), the current revision that specifies the card’s physical characteristics, the data model, the interfaces, and the mandatory security controls. FIPS 201-3 is the baseline that turns a generic smart card into a federally interoperable PIV credential. Companion documents matter just as much for buyers: NIST SP 800-116 Revision 1 tells agencies how to use PIV credentials for access, and NIST SP 800-78-4 pins down the approved cryptographic algorithms and key sizes.

For federal acceptance, the card and its components must appear on the GSA FIPS 201 Approved Products List (APL), maintained on the government’s FICAM resources site. A card that is not on the Approved Products List will not pass a federal PIV acceptance test, no matter how good it looks in a sample. Specifying “FIPS 201-3 compliant, APL-listed” in your RFQ is the single line that separates a credential from a novelty.

Contact, Contactless, or Dual-Interface — What to Specify

A contactless smart card emphasising the durability and interface choice for PIV credentials
Dual-interface PIV cards serve both doors (contactless) and desktops (contact) from one credential.

PIV cards can expose the chip through a contact plate (ISO/IEC 7816), a contactless antenna (ISO/IEC 14443), or both. For nearly all new programs, dual-interface is the default: the contact interface covers high-assurance desktop logon and personalization, while the contactless interface drives doors, turnstiles, and quick tap-in.

The reader estate decides the minimum. If your buildings still run legacy Wiegand, a PIV card alone will not help until the panels move to a secure, bidirectional protocol — a point we cover in our OSDP vs Wiegand access-control guide. Match the card interface to a reader standard you have actually deployed or budgeted for, not to a brochure. Our dual-interface smart card explainer details the manufacturing and cost trade-offs of routing one chip to two interfaces.

The Card Operating System Matters — Java Card and GlobalPlatform

Close-up of the chip inside a smart card where the Java Card OS and PIV applets run
The secure element runs a card OS; Java Card and GlobalPlatform keep the credential updatable after issue.

Under the badge artwork sits a card operating system (COS) and, usually, a GlobalPlatform-compliant secure element. Java Card lets issuers load and update applets — the small programs that implement PIV authentication, digital signature, and cardholder unique identifier (CHUID) functions — after the card has been manufactured. GlobalPlatform, described by the GlobalPlatform specifications, defines how those applets are securely installed and isolated in their own security domains.

For a buyer this is a procurement clause, not trivia: if the COS is proprietary or closed, you may be locked to one personalization bureau for the life of the program. Require “Java Card 3.0.x / GlobalPlatform 2.3.x (or later)” in the spec so you retain the freedom to rotate applets, patch, and re-personalize as standards evolve. Our smart card chip-selection guide shows how to map memory, interface, and certifications to the real application.

What to Put in Your RFQ — A PIV Procurement Checklist

Bulk smart cards on a pallet, a reminder to specify PIV compliance rather than buy on unit price
Buying on unit price alone is how programs end up with non-PIV-ready stock.

Turn vague “supply PIV cards” into a bid-comparable specification. At minimum your RFQ should state:

  • FIPS 201-3 compliance, with the specific card and secure element named on the GSA Approved Products List.
  • Interface: dual-interface (contact + contactless 13.56 MHz, ISO/IEC 14443), or justify a single interface.
  • Card body: PC or composite PETG/PVC, ISO/IEC 7810 ID-1, 0.76 mm nominal — see our ISO 7810 dimensions guide.
  • COS/applets: Java Card + GlobalPlatform, PIV applet supporting authentication, digital signature, and key management.
  • Key custody and personalization: who issues certificates, how keys are diversified, and whether SAM/HSM or a secure channel is used — our key-management guide lists the ten clauses to demand.
  • Visual security: UV, microtext, or hologram overlay appropriate to the threat model; encoding per our card-encoding spec guide.
  • Acceptance testing: sample size, AQL, and a test report mapped to ISO/IEC 10373.

The Costly Mistake — Buying “Smart Cards” That Aren’t PIV-Ready

A stalled smart card rollout, the classic result of buying non-PIV-ready cards
The classic failure: cards arrive, readers reject them, and the original spend is written off.

The most common failure we see is an agency or contractor ordering “smart cards” on unit price, then discovering at deployment that the chips are MIFARE-only, the COS is closed, or the secure element is absent from the APL. A non-PIV-ready card cannot be upgraded by software — the missing silicon and missing certificate chain mean a full re-issue, with the original spend written off.

Three red flags to catch before purchase: (1) the quote lists no FIPS 201-3 or APL reference; (2) the supplier cannot name the secure element or COS; (3) delivery is offered without a certificate-enrollment path. Insist on a golden sample that is electrically tested on your own readers before the production PO releases.

Buyer Questions About PIV Smart Cards

Government identity cards and a biometric e-passport data page representing PIV-grade credentials
PIV credentials span federal, state, and interoperable partner programs — all built on FIPS 201-3.
  • Is PIV-I different from PIV? PIV-I (Personal Identity Verification – Interoperable) extends the credential to non-federal partners who cannot meet full PIV vetting; it shares the same card structure but a different identity-proofing path. Both follow FIPS 201-3.
  • Can a PIV card also do physical access and PC logon? Yes — that is the point of dual-interface plus the PIV authentication and digital-signature keys. Convergence is standard for modern programs.
  • Do I need a contactless interface? For door and turnstile access, yes. The contact interface remains essential for high-assurance desktop logon and initial personalization.
  • How long are PIV certificates valid? Typically tied to the credential term (often up to six years for the card), with certificates re-issued on a shorter cycle.

Ready to scope a FIPS 201-3 compliant card program? GENUINE supplies PIV-ready smart cards, dual-interface bodies, and secure personalization. Request a golden sample and a factory quote before you commit volume — it is the surest way to avoid a non-compliant re-issue.

Table of Contents

This is the heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Scroll to Top
Request A Qute