Yubico

Sweden · www.yubico.com · 20 vendors

Yubico AB is a global cybersecurity company that invents and manufactures hardware authentication devices, including the YubiKey and YubiHSM. The company provides strong multi-factor authentication and passwordless login solutions for secure access to computers, mobile devices, servers, and internet accounts. Yubico is a key contributor to open authentication standards such as FIDO2, WebAuthn, and FIDO Universal 2nd Factor (U2F).

Resilience scores

Disruption prediction

Yubico has an estimated 10% probability of disruption in the next 6 months.

13 of Yubico's 20 vendors monitored for disruptions.

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 20 sub-vendors.

Insights

Last updated 2026-07-30 · revision 1

20 direct vendors, 218 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Yubico exhibits a foundational readiness for migration, primarily driven by its internal tech stack. The presence of AWS, Python, Go, and Rust indicates a strong capability for adopting cloud-native architectures, containerization, and microservices. This modern technology base provides a solid platform for efficient and effective migration. The absence of specified data residency requirements could also simplify migration planning by potentially reducing complex compliance hurdles. Nevertheless, several factors pose challenges and introduce uncertainty. Crucially, information regarding the regulatory environment and data residency requirements is either missing or not specified, which are critical considerations for any migration strategy. The lack of data on financial stability (revenue concentration, growth history) makes it impossible to assess Yubico's capacity to fund a potentially significant migration effort. The vendor relationships present a mixed picture and a significant unknown: "Total Services: 25" suggests a potentially complex ecosystem of integrations, and the "Vendor Lock-in Risk: Unknown" is a major concern. If there is high vendor lock-in, it could significantly increase the cost, complexity, and duration of a migration. The ambiguity of "Total Vendors: 0" makes it hard to determine if there are few vendors (high lock-in risk) or if the count is simply not provided. Overall, while the tech stack is promising, the substantial data gaps and unknown vendor lock-in risk place Yubico in a medium state of migration readiness.

Compliance

8 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed into Swedish law via the Cybersäkerhetslagen) is potentially applicable to Yubico as an EU-based company. Yubico operates in the cybersecurity/digital infrastructure sector and provides authentication hardware and services (YubiKey, YubiHSM, YubiCloud, YubiKey as a Service) that underpin critical digital infrastructure for thousands of organizations globally, including government agencies, financial institutions, and healthcare providers. Under NIS2, 'digital providers' and 'ICT service management' entities may qualify as Important Entities. Yubico's YubiCloud (OTP validation cloud service) and YubiKey as a Service subscription model could constitute digital service provision. The size threshold (50+ employees or €10M+ turnover) is very likely met given Yubico's global scale, 4,000+ enterprise customers, and public listing on Nasdaq First North Growth Market. Risk is Medium because: (1) Yubico's primary product is hardware (physical security keys), which may not directly fall under NIS2 digital service categories; (2) the cloud/SaaS components (YubiCloud, YubiKey as a Service) are more likely to trigger NIS2 obligations; (3) formal NIS2 classification by Swedish authorities has not been publicly confirmed. Missing information: official NIS2 entity classification by the Swedish Civil Contingencies Agency (MSB) or equivalent authority.

Evidence: https://www.yubico.com/why-yubico/, https://www.yubico.com/products/yubicloud/, https://www.yubico.com/products/yubikey-as-a-service/, https://www.yubico.com/support/terms-conditions/legal-imprint/

FIPS 140-3 — Compliant

Yubico has achieved FIPS 140-3 validation for its YubiKey 5 FIPS Series and YubiHSM 2 FIPS products, as publicly confirmed on its website. This is a US government (NIST/CMVP) product-level certification required for cryptographic modules used in US federal government systems. Risk is Low because Yubico has already achieved this certification, which is a significant competitive differentiator and compliance milestone. Maintaining FIPS 140-3 validation requires ongoing compliance with NIST standards and re-validation upon firmware updates.

Evidence: https://www.yubico.com/products/yubikey-fips/, https://www.yubico.com/product/yubikey-5-fips-140-3-series/yubikey-5c-nfc-fips-140-3/, https://www.yubico.com/products/hardware-security-module/, https://www.yubico.com/blog/yubikey-5-fips-series-is-now-fips-140-3-validated-what-it-means-for-high-assurance-security/

FedRAMP — Assessment Required

Yubico actively markets its products to US federal government agencies and explicitly offers YubiKey FIPS 140-3 series for federal use cases. YubiCloud (the cloud-based OTP validation service) and YubiKey as a Service may require FedRAMP authorization if used by US federal agencies. Risk is Medium because: (1) Yubico's FIPS 140-3 validated products are already positioned for federal use; (2) if YubiCloud or YubiKey as a Service are used by federal agencies, FedRAMP authorization would be required for those cloud components; (3) lack of FedRAMP authorization could limit Yubico's ability to expand federal cloud service sales.

Evidence: https://www.yubico.com/industries/federal/, https://www.yubico.com/products/yubikey-fips/, https://www.yubico.com/products/yubicloud/

Financials

Three-year financials

Financial Resilience Score: 8/10

Yubico exhibits strong financial resilience underpinned by a fortress balance sheet: SEK 856M net cash at year-end 2025, total equity of SEK 1,659.9M, an equity ratio of approximately 75%, and virtually no interest-bearing debt beyond SEK 39M in lease liabilities. The company generates high gross margins (77.9% in 2025, historically 79-82%) driven by proprietary IP, in-house programming, and premium enterprise positioning. Operating cash flow remains solidly positive at SEK 254M in 2025 (SEK 344M in 2024), enabling continued investment and share repurchases (SEK 88.3M in 2025) without balance sheet strain. The business benefits from a blue-chip customer base (19 of the top 20 U.S. tech companies, ~30% of the Fortune 500) with no single customer exceeding 10% of revenue, growing recurring revenue (ARR +20.7% to SEK 391M; subscription share of bookings up to 23.1%), and dual-site manufacturing in Sweden and the U.S. that mitigates tariff and geopolitical risks. Long-term growth is impressive with a 2020-2025 revenue CAGR of approximately 30%. However, 2025 exposed material vulnerabilities: reported revenue declined 4.7% (only -1.4% in constant currency) due to significant SEK/USD FX headwinds, and EBIT margin collapsed from 18.8% to 9.0%, missing the company's 20% EBIT margin and 25% growth targets. Deal lumpiness in the Americas (68% of sales), a 15% headcount increase creating negative operating leverage, rising LTIP costs (SEK 87.5M), and a CEO transition in December 2025 (Acting CEO Jerrod Chong replacing Mattias Danielsson) all introduce near-term execution uncertainty. Overall the balance sheet strength and business model quality clearly outweigh the cyclical setback, warranting a score of 8.

Key strengths: Net cash position of SEK 856M with virtually no interest-bearing debt, Equity ratio of ~75% (SEK 1,659.9M equity on SEK 2,214.4M assets), High gross margins of 77-82% driven by proprietary IP, Strong operating cash flow generation (SEK 254M in 2025), Blue-chip customer base with no customer >10% of revenue, Growing recurring revenue (ARR +20.7%, subscription bookings share 23.1%), Dual-site manufacturing in Sweden and U.S. mitigates geopolitical risk, 2020-2025 revenue CAGR of ~30%

Risk factors: High USD revenue exposure (~60%+) with no transaction hedging causes reported earnings volatility, Americas concentration (67.7% of sales) with lumpy large enterprise deals, Single core product (YubiKey) vulnerable to platform-embedded passkey substitution from Apple/Google/Microsoft, Chip and supply-chain dependency despite ARM multi-sourcing, EBIT margin collapsed from 18.8% to 9.0% in 2025, missing 20% target, Growth target of 25% significantly undershot (-4.7% reported in 2025), Headcount grew 15% while revenue was flat/down, causing negative operating leverage, CEO transition in December 2025 with only Acting CEO in place, No dividend paid for 2024 or 2025

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report