Compatibility issue between FIDO2 and ELATEC LEGIC readers resolved
Enable FIDO2 on existing ELATEC LEGIC readers instead of replacing thousands of devices. How we solved the compatibility problem and what this means for your cards.

Enable FIDO2 on existing ELATEC LEGIC readers instead of replacing thousands of devices. How we solved the compatibility problem and what this means for your cards.
We have removed the biggest practical barrier to FIDO2 adoption: you don't have to replace all your readers first.
The German NIS2 implementation act has come into force, and multi-factor authentication is one of the risk management measures that companies must implement.
The Cyber Resilience Act is another aspect that organizations must consider when selecting suppliers. From the end of 2027, the hardware you purchase must meet its security requirements.
Considering those together, affected companies face the same task: strong authentication for logical access, properly documented and implemented by the end of 2027.
"The card protects your building, FIDO2 protects your logical access." Edis Hasinovic, evolutionID
FIDO2 has established itself as the standard solution. It is phishing-resistant, replaces passwords, and is fast enough for people who need quick access in critical situations.
The catch was the hardware. Until now, using FIDO2 meant you had to purchase new readers that support this standard and provide a USB dongle to everyone who needed a second authentication factor.
If your employee ID cards are based on LEGIC and your card readers are already integrated into HMIs, production terminals, time-tracking points, and machine control panels, implementing FIDO2 previously meant replacing every reader in your ecosystem.
FIDO2 is the most secure path. So, you have to change something.
Our solution: You don't have to replace everything
We enable FIDO2 on ELATEC readers with a LEGIC chipset that are already installed in your environment.
This requires a firmware update on the reader combined with an operating system update on the chipset. Afterward, the reader supports FIDO2 in addition to all previous functions. Your existing infrastructure remains unchanged. However, FIDO2 must be on the card from the start. The FIDO applet cannot be installed retroactively. You continue to use cards with a suitable applet; you replace all others. We will clarify what applies to your ecosystem before the update.
Furthermore, you don't need to purchase any additional software. And that is more important than it sounds. You avoid a massive migration project that would normally be associated with additional software license fees.
The required combination is quite specific. You need LEGIC partner status just to be able to provide the operating system update. You must know the reader hardware well enough to carry this out safely within a mixed, already installed base. And you must have a deep enough understanding of LEGIC to ensure that the result continues to work with the cards and infrastructure already in use in your ecosystem.
We estimate that fewer than three percent of LEGIC partners possess this combination. You also cannot solve the problem by ordering new readers, as this feature is not enabled on currently available devices.
We are partners of both ELATEC and LEGIC, placing us among the estimated three percent of partners capable of implementing this solution.
We have already successfully implemented this solution for two major automotive manufacturers and two energy suppliers, in environments with thousands of readers and numerous applications. In one implementation, we tested more than twenty applications for FIDO2 compatibility to determine exactly what the standard can cover. The vast majority worked without any issues. The only exception was an application that does not use a reader at all.
To be honest: it will be soon. Many companies have not yet reached the point where this becomes a problem, but that point is coming. As soon as a FIDO2 requirement meets an already installed reader base, the question of hardware replacement arises.
If you are planning an introduction, conducting a proof of concept, or want to find out what NIS2 means for your access infrastructure, talk to us. We will examine your ecosystem and show you what you can keep and what really needs to change.
Contact us to discuss your requirements.