Contact us
NEW PIV smartcard support in Secure Disk for BitLocker

One PIV credential.
Three ways to unlock BitLocker.

Secure Disk for BitLocker now accepts PIV smartcards for pre-boot authentication. Your users unlock their encrypted drive before Windows starts, with the credential that suits them: a contact smartcard, a contactless NFC card or a USB token.

  • Based on the NIST FIPS 201 PIV standard
  • Two-factor: card + PIN
  • From USD 50 per device
Pre-boot authentication before Windows starts
Smartcard · NFC · USB one PIV standard
Central management console included
AES-256 BitLocker encryption
Why it matters

Encryption is only as strong as the way it is unlocked

BitLocker protects data at rest. But in the common TPM-only setup, the drive is decrypted automatically when the device starts, with no user involved. Whoever holds the laptop reaches the Windows logon screen with the disk already unlocked.

Attacks such as cold boot and DMA attacks target exactly that moment. Strong authentication before Windows starts closes the gap, and a PIV smartcard is one of the most robust and widely accepted ways to do it.

Ask us about your BitLocker setup
TPM only

Unlocks automatically at boot

No proof of who is starting the device. A lost or stolen laptop boots to an unlocked drive.

Password / PIN only

A single factor that can be shared or guessed

Passwords get written down, reused and phished. They prove knowledge, not possession.

PIV + PIN

True two-factor before Windows starts

Something you have (the PIV card or token) plus something you know (the PIN). The private key never leaves the chip.

Choose your form factor

Same PIV credential, the form your users prefer

PIV is an open standard. You decide how the credential reaches the device, per user group or per site, and you can mix form factors in one deployment.

01

Contact smartcard

The classic: insert the PIV card into a built-in or external smartcard reader and enter the PIN.

  • Ideal for organisations that already issue PIV or corporate ID badges
  • One card for building access, Windows logon and disk unlock
  • Works with standard smartcard readers
Best for: office workstations, public sector, regulated industries
02

Contactless NFC card

Tap the PIV card on the NFC reader, enter the PIN, done. Fast and with no wear on the card or the reader.

  • The quickest unlock for busy users
  • No card slot needed, only an NFC reader
  • Hygienic and robust in shared environments
Best for: shift work, shared devices, healthcare, production floors
03

USB token

A PIV-capable USB security key (for example a YubiKey 5 series key) holds the certificate. Plug it in, enter the PIN and the drive unlocks.

  • No reader hardware required
  • Small enough for any key ring
  • Often combined with FIDO2 for passwordless logins elsewhere
Best for: mobile workforce, notebooks, field and remote staff
How it works

From power button to desktop in four steps

1

Power on

Secure Disk for BitLocker starts its pre-boot authentication before Windows loads. The BitLocker volume stays locked.

2

Present the PIV credential

The user inserts the smartcard, taps the NFC card or plugs in the USB token.

3

Enter the PIN

The PIN unlocks the private key on the chip, and the certificate-based check confirms the user is authorised for this device.

4

BitLocker unlocks

The drive is decrypted and Windows starts. With single sign-on, the user continues straight to the desktop.

See PIV pre-boot authentication live

An online demo with our engineers, covering all three form factors.

Book your demo
Benefits

Built for everyone who touches the device

For users

  • No long BitLocker recovery passwords to remember, only a short PIN
  • The same card or token they already use every day
  • Single sign-on: one authentication from power-on to desktop
  • A clear, consistent logon experience on every device

For IT administrators

  • Reuse your existing PKI and PIV certificates, with no new identity silo
  • Central management console included at no extra cost
  • Helpdesk recovery for forgotten PINs or lost cards
  • Multiple users per device, and no TPM required
  • Mix smartcard, NFC and USB tokens in one policy

For CISOs and management

  • Strong two-factor authentication before the operating system starts
  • Supports GDPR, NIS2 and ISO 27001 requirements for protecting data on endpoints
  • Audit-ready reporting on encryption and authentication status
  • Predictable cost: a perpetual licence per device, not per user
Features at a glance

Everything you need for PIV-based disk unlock

✓

Standards-based PIV support

Works with PIV credentials following NIST FIPS 201 and SP 800-73.

✓

Three form factors, one standard

Contact smartcard, contactless NFC card or USB token, freely combinable.

✓

Certificate-based two-factor

Possession of the card plus knowledge of the PIN. The private key stays on the chip.

✓

Pre-boot authentication

The user is verified before Windows and BitLocker unlock the disk.

✓

Single sign-on to Windows

One authentication from power-on to the desktop.

✓

Multi-user devices

Several users, each with their own PIV credential, can unlock the same device.

✓

Central management and helpdesk

Manage policies, users and recovery keys from one console, which is included.

✓

Integration with your PKI and Active Directory

Use existing certificates and directory groups for a smooth roll-out at scale.

✓

No TPM required

Protect older or mixed hardware fleets with the same strong authentication.

✓

Compliance reporting

Prove encryption and authentication status to auditors at any time.

Use cases

Where PIV disk unlock makes the difference

Public sector and government

Use the PIV and ID cards your staff already carry to meet strict requirements for protecting classified and personal data.

Defence and critical infrastructure

Hardware-bound two-factor authentication before boot for suppliers and operators with high security obligations.

Healthcare

Fast NFC tap-and-PIN unlock on shared ward and practice devices that hold patient data.

Banking, finance and insurance

Meet regulatory expectations for strong authentication and endpoint encryption on every notebook.

Law firms and consultancies

Protect client confidentiality on devices that travel to courts, clients and home offices.

Engineering and R&D

Keep intellectual property locked even if a notebook is lost or stolen.

Pricing

Simple, transparent licensing per device

Secure Disk for BitLocker is licensed per Windows device, regardless of how many users work on it. PIV smartcard authentication is available from USD 50 per device.

Volume pricing applies to larger roll-outs. Maintenance and support are available for 1, 2 or 3 years. Contact us for a quote tailored to your number of devices and your preferred form factors.

Request your personal quote
Starting from
USD50
per device (endpoint)
  • PIV smartcard, NFC card and USB token support
  • Pre-boot authentication and single sign-on
  • Central management console included
  • Licence per device, not per user
  • Volume discounts for larger deployments
Get pricing for your fleet

Perpetual licence plus optional maintenance. Smartcards, readers and USB tokens are not included. Prices exclude VAT.

FAQ

Frequently asked questions

What is a PIV smartcard?
PIV (Personal Identity Verification) is a smartcard standard defined by the US National Institute of Standards and Technology in FIPS 201. A PIV credential stores X.509 certificates and the matching private keys on a secure chip, protected by a PIN. Beyond government use, it is widely adopted by enterprises and supported by many card and token vendors.
Can I use the PIV cards we already have?
In many cases, yes. If your organisation already issues PIV-compatible smartcards or tokens, Secure Disk for BitLocker can use these credentials for pre-boot authentication. Contact us and we will check compatibility with your cards, readers and PKI.
What is the difference between the smartcard, NFC and USB options?
They all use the same PIV standard and the same security model: a certificate on a chip, protected by a PIN. The only difference is how the credential connects to the device: through a contact reader, a contactless NFC reader, or directly over USB. You can mix all three in one deployment.
What happens if a user forgets the PIN or loses the card?
Secure Disk for BitLocker includes helpdesk functions that let IT restore access securely, without exposing the BitLocker recovery key to the user. Lost cards can be revoked, and a replacement credential can be issued.
Do I need a TPM?
No. Secure Disk for BitLocker provides pre-boot authentication without a TPM, so you can protect mixed and older hardware with the same PIV-based two-factor authentication.
How much does it cost?
PIV smartcard authentication with Secure Disk for BitLocker starts from USD 50 per device. The final price depends on the number of devices and the maintenance term. Contact us for a quote.
Get started

Ready to unlock BitLocker with PIV?

Tell us about your environment, whether smartcards, NFC or USB tokens, and our team will show you how PIV pre-boot authentication fits in, with a live demo and a quote tailored to you.