Skip to content
Nenkin

MIFARE: Contactless Smart Card Certifications

MIFARE is a family of contactless smart card ICs introduced in 1994 and now owned by NXP Semiconductors. It is widely deployed in transit ticketing, physical access control, and loyalty applications. The family includes MIFARE Classic, DESFire, Plus, and Ultralight. MIFARE itself is not a certification scheme, but specific MIFARE devices (particularly secure variants in the DESFire and Plus families) are evaluated under Common Criteria and are frequently tracked alongside scheme certificates.

Key facts

  • Authorizing body: Evaluations are performed under CC schemes such as BSI; MIFARE as a brand is owned by NXP
  • Country / region: Global product; certifications are issued by national CC schemes (most commonly BSI)
  • Year established: The first MIFARE products were released in 1994; secure variants have been CC-evaluated for two decades
  • Product types: contactless smart card ICs (MIFARE Classic, MIFARE DESFire, MIFARE Plus, MIFARE Ultralight variants)
  • CCRA status: MIFARE products are typically certified under a CCRA authorizing scheme (BSI); MIFARE itself is a product family, not a scheme
  • Canonical portal: NXP MIFARE page: https://www.nxp.com/products/mifare

Overview

NenkinTracker treats MIFARE as a dedicated data source because the certificates for MIFARE ICs are a well-defined set of hardware products that customers procure, deploy, and monitor distinctly from other smart card ICs. The relevant certifications are typically BSI CC certificates at EAL4+ with AVA_VAN.5, against smart card-oriented Protection Profiles.

How evaluations work under this scheme

MIFARE IC evaluations follow the standard CC flow at BSI: an accredited ITSEF evaluates the IC against the TOE’s Security Target and the relevant smart card PP. Attack methods follow joint interpretation documents developed by smart card scheme participants, with attack potential rated High for the secure variants. Maintenance reports extend certificates after minor hardware or firmware updates.

Notable product categories

  • MIFARE DESFire family (EV1/EV2/EV3 and later): the secure, CC-evaluated variants
  • MIFARE Plus family: CC-evaluated smart card ICs for access and transit
  • MIFARE Ultralight secure variants where CC certification is relevant
  • MIFARE-compatible ICs from other vendors (tracked separately when present)

Relationship to CC baseline

MIFARE certification activity maps onto the Common Criteria baseline of ISO/IEC 15408, the CEM, and smart card interpretation documents. As a product family it does not alter the CC methodology; the MIFARE tag simply groups a set of high-assurance contactless IC certificates. Under EUCC, MIFARE IC certificates can transition into the EUCC high-level framework where issued by a participating NCCA.

Where to find official records

See also: BSI, EMVCo, Glossary.

Frequently asked questions

What is MIFARE?
MIFARE is a family of contactless smart card integrated circuits designed by NXP Semiconductors and widely deployed in transit ticketing, physical access control, and loyalty applications. The first MIFARE products shipped in 1994. MIFARE itself is a product family rather than a certification scheme, but secure variants are routinely evaluated under Common Criteria, most often by BSI in Germany.
Is MIFARE a Common Criteria scheme?
No. MIFARE is a brand and product family owned by NXP, not a scheme. The certificates that apply to specific MIFARE ICs are issued by national CCRA Certificate Authorizing schemes, in practice usually BSI. NenkinTracker treats MIFARE as a dedicated data source because the certificates for these ICs form a well-defined hardware product set that transit, access, and payment integrators need to monitor distinctly.
Which MIFARE products are CC-certified?
The secure, CC-evaluated MIFARE products fall into a few families. The MIFARE DESFire family (EV1, EV2, EV3, and later) is the main CC-evaluated line for transit and access. The MIFARE Plus family covers CC-evaluated cards for access and transit. Selected MIFARE Ultralight secure variants are also CC-evaluated, where the use case requires it. MIFARE-compatible ICs from other vendors are tracked separately when present.
What assurance level do MIFARE certifications use?
Secure MIFARE ICs are typically certified at EAL4+ with AVA_VAN.5, which corresponds to high attack potential. The evaluations follow standard smart card Protection Profiles and apply joint smart card interpretation documents developed by European scheme participants. AVA_VAN.5 is the same vulnerability assessment level used for payment and eID smart card ICs.
How is a MIFARE certificate issued?
The flow is the standard BSI Common Criteria flow. An accredited ITSEF evaluates the IC against the relevant smart card PP and the product's Security Target. Attack methods follow the joint interpretation documents, with attack potential rated High for the secure variants. BSI reviews the Evaluation Technical Report and issues the certificate. Maintenance reports under assurance continuity keep the certificate live after minor hardware or firmware updates.
Where can I find official MIFARE certificate records?
Certificate records for MIFARE ICs are published on the BSI certified product list and mirrored on the CCRA portal. NXP also maintains product security pages for each MIFARE family. NenkinTracker consolidates MIFARE-family certificates with other smart card and IC certifications so the full set is searchable next to records from ANSSI, CCN, OCSI, and other smart card schemes.