Certifications, standards posture, and trust documents.
This page lists the certification AmbiSecure technology has achieved, the standards we build against, certifications that are targeted for upcoming product tiers, and the trust documents we maintain. We are conservative in what we claim — if a certificate is held under a customer’s brand, or is in flight rather than awarded, we say so.
Last reviewed: 2026-05-09. For the most up-to-date status of any specific certification, talk to our engineering team.
What we are actively certified for
Listed verbatim from public AmbiSecure communications. Independently verifiable via the relevant standards body where applicable.
| FIDO Level 1 — customer-branded implementation |
Certification: FIDO Level 1.
Scope: a customer-branded implementation built on AmbiSecure technology.
Status: Certified.
AmbiSecure technology has been certified to FIDO Level 1 through a customer implementation marketed under the customer’s brand. The certificate is held under that customer’s brand and covers the certified implementation only. Clarification: this does not represent blanket certification of every AmbiSecure-branded product, and AmbiSecure does not hold a directly listed FIDO certification under its own brand. FIDO Certified products and their levels are independently verifiable at fidoalliance.org/certification/fido-certified-products/. Status: Active. Certificate details supplied on request, then independently verifiable on the FIDO Alliance site. |
|---|---|
| FIDO Alliance membership |
AmbiSecure (Ambimat Electronics) participates in the FIDO Alliance ecosystem and ships products under the FIDO U2F (CTAP1) and FIDO2 (CTAP2 / WebAuthn) protocols.
Status: Active. |
Conformance marks and trust references
The FIDO Level 1 certification reached through a customer-branded implementation built on AmbiSecure technology. Each certificate is held under the customer’s brand and covers the certified implementation only — not the AmbiSecure-branded product range. Every certificate below is independently verifiable on the FIDO Alliance site.
Standards we build against
These are not certifications — they are the specifications our products implement. Conformance is verifiable through inspection of the public protocol output (APDUs, CTAP frames, BER-TLV, etc.); see our utility tools.
| Authentication | FIDO U2F (CTAP1); FIDO2 (CTAP2.1); W3C WebAuthn Level 2; COSE (RFC 8152); CBOR (RFC 8949) |
|---|---|
| Identity | NIST SP 800-73 PIV (parts 1–4); RFC 4880 OpenPGP card spec |
| Smart card / contactless | ISO/IEC 7810 ID-1; ISO/IEC 7816-3/4; ISO/IEC 14443 Type A; ISO/IEC 8825 BER/DER |
| Card OS | JavaCard 3.x; GlobalPlatform 2.3.1 with Amendment D SCP03 |
| Cryptography | NIST FIPS 186-4 (DSA/ECDSA); NIST SP 800-38B (CMAC); FIPS 197 (AES); RFC 5869 (HKDF) |
| eSIM | GSMA SGP.22 (consumer eSIM); GSMA SGP.32 (M2M eSIM); ETSI TS 102 221 |
| NFC | NFC Forum NDEF 1.0; NFC Forum Type 4 Tag |
| PKI | X.509 v3 (RFC 5280); PKCS#10; PKCS#11 v2.40; PKCS#12; PKCS#15 |
| Identity assurance | NIST SP 800-63-3 AAL3 architecture patterns |
| IoT security baseline | TEC 31318:2021 (India IoT Security Code of Practice) — design alignment for the IoT Security Co-Processor product line. |
| V2X — certificate format | IEEE 1609.2 — design alignment; explicit and implicit certificate forms, ECDSA-P256 / P-384 signing. |
| V2X — security headers | ETSI TS 103 097 — design alignment; secured-message structure, certificate-included vs certificate-digest signing, validity restrictions. |
| V2X — trust & privacy | ETSI TS 102 941 — design alignment; Enrolment Authority and Authorisation Authority roles, EC/PC issuance flow, pseudonymity model. |
| ITS station services | ISO 21177 — design alignment; authentication, authorisation, data protection across the ITS station stack. |
Certifications we are targeting
These are explicit certification targets for current and upcoming product tiers, not active certifications. Each is being pursued in collaboration with the relevant chip vendor or accredited lab.
| FIDO Biometric Component | Targeted for OnePass Bio Card and BioKey. Match-on-card / match-on-device evaluation path. |
|---|---|
| Common Criteria — secure hardware platform | AmbiSecure products are built on secure hardware evaluated to EAL5+ or EAL6+, depending on the product generation and underlying platform; the AmbiSEC module and current hardware platforms use a minimum assurance level of EAL5+, and newer products use or are moving to EAL6+ silicon. That evaluation applies to the underlying secure element or hardware platform — it does not mean the complete AmbiSecure-branded product is independently Common Criteria certified, and the applet layer is not separately CC-evaluated by default. |
| SSCD / QSCD evaluation | Targeted for the Digital Signature Token under specific customer roadmaps (eIDAS-aligned issuance). |
| Automotive-grade for V2X | ISO 26262 (functional safety) and ASPICE (process maturity) certification of the integrated AmbiSEC Module / IoT Security Co-Processor product as a V2X deployment target is a goal under active scoping, not yet a claim. The underlying secure-element silicon already carries Common Criteria EAL6+ at the chip level (see preceding row). |
No claim of active certification at the AmbiSecure product / applet layer is implied for any of the above unless explicitly listed in the "Active" section.
Compliance frameworks we support
These are frameworks our products are designed to fit inside — not certifications we hold. Customers may pursue accreditation against these frameworks using AmbiSecure components as building blocks.
| NIST SP 800-63-3 | AAL3 architectures using AmbiSecure FIDO + biometric authenticators. |
|---|---|
| OMB M-22-09 | Phishing-resistant MFA for U.S. federal civilian executive-branch deployments. |
| eIDAS | Qualified electronic signatures — achievable via AmbiSecure Digital Signature Token paired with a Qualified Trust Service Provider. |
| EU Cyber Resilience Act (CRA) | IoT product cyber-resilience baselines — supported via AmbiSecure IoT Security Co-Processor and IoT Solution. |
| GSMA SAS-UP / SAS-SM | Subscriber-management security accreditation — supported through Ambimat’s SIMAuth line at esim.ambimat.com. |
Trust documents on request
The following documents are made available under NDA during procurement. Public-facing copies are deliberately not posted because most carry chip-vendor-confidential information. Email support@ambimat.com with your engagement scope.
- Per-product datasheet (security model, applet matrix, certification status)
- Personalisation-line audit hooks and chain-of-custody description
- SCP03 / GlobalPlatform key-ceremony procedure
- Secure-element chip-platform CC EAL certificate (issued to the silicon vendor; provided as a reference document)
- FIDO Certified product certificate IDs (independently verifiable on the FIDO Alliance site once disclosed)
- Standard-form vendor-security-questionnaire responses (CSA STAR-style)
What this page is and is not
- This page is not a certificate. It is a summary of certification posture. Active certificates and certificate IDs are issued by independent bodies and are verifiable on those bodies’ sites — not on ours.
- Standards conformance is not certification. Building to a standard (e.g. ISO/IEC 7816-4) is not the same as being certified against an evaluation scheme. We list the two separately.
- Chip-level evaluation does not auto-extend to the applet layer. A CC EAL6+ chip-platform certificate is held by the silicon vendor and applies to the chip platform; AmbiSecure-authored applets sitting on that platform are not separately evaluated unless explicitly stated.
- "Targeted" means in flight, not awarded. Targets in the evaluation pipeline are clearly marked as such.
- Legacy badge artwork is reproduced as-is. Continued validity of any third-party trust mark should be verified with the issuing organisation.
- Compliance frameworks are deployment patterns, not held accreditations. Customers can pursue accreditation against these frameworks using AmbiSecure components; AmbiSecure itself does not claim those accreditations except where explicitly listed in the "Active" section above.
Need a specific certificate document for procurement?
Tell us which product, which framework, and which evaluator. We will send you the active certificate IDs (verifiable on the issuing body’s site) and any reference documents that are appropriate to share at your stage of engagement.
Frequently asked questions
Does AmbiSecure hold its own FIDO certification?
No. AmbiSecure technology has been certified to FIDO Level 1 through a customer-branded implementation; AmbiSecure does not hold a directly listed FIDO certification under its own brand. FIDO Certified products and their levels are independently verifiable at the FIDO Alliance certified-products directory.
What Common Criteria assurance do the products reach?
AmbiSecure products are built on secure hardware evaluated to EAL5+ or EAL6+, depending on the product generation and underlying platform. That assurance is at the secure-element / silicon level, not a product-wide claim.
How can I verify a certification?
Certificate details are supplied on request, and FIDO certifications are independently verifiable on the FIDO Alliance certified-products directory.
Does a certified chip make a finished product certified?
No. Certification applies to a defined evaluation target under stated assumptions. A CC-evaluated secure element is a certified component; the product built on it inherits confidence, not the certificate.
Why do certification schemes matter for procurement?
They convert a vendor claim into something independently assessed against a published standard, which is what lets a buyer compare offerings and satisfy their own audit requirements.