Mobile Identity
PKI on Every Smartphone
Deploy MyID® for mobile-first credential programmes, issuing derived PKI credentials to iOS and Android devices, managing mobile MFA and supporting BYOD and government-issued device programmes.
What this deployment model delivers
iOS and Android derived credentials
MyID issues X.509 PKI certificates to iOS and Android devices, with keys held in the device's hardware-backed secure key store so they cannot be exported. Each credential is derived from a primary PIV card or smart card, so no new identity proofing is required.
NIST SP 800-157 compliant
MyID's mobile derived credential implementation meets NIST SP 800-157 and 800-157r1 requirements for PIV-Derived credentials. Compliant for US federal mobile access programmes under OMB M-19-17.
Remote enrolment
Remote workers verify their identity from anywhere using document scan, NFC chip reading and biometric liveness detection, then collect their mobile credential through the MyID Identity Agent app. No in-person visit is required for LOA-3 derived credentials.
Lifecycle management from CMS
Mobile credentials are managed through the same MyID CMS admin console as smart cards and USB tokens. Renewal, suspension and leavers revocation are consistent across all credential types.
Architecture components
| Identity verification | document scan, NFC, liveness |
| Mobile app | MyID Identity Agent (iOS and Android) for credential collection and activation |
| TEE / Secure Enclave | device hardware-backed key store |
| MyID CMS | Central lifecycle management, issue, renew, revoke mobile credentials |
| MDM Integration | Works alongside Intune, Jamf and other MDM platforms |
Detailed platform requirements
Full server, operating system, database, HSM and client requirements for every MyID deployment are maintained in the Technical Overview, alongside the architecture and API detail.
Mobile identity, derived credentials for the smartphone-first workforce
Derived credentials bring hardware-grade identity assurance to smartphones and tablets. A physical PIV card is used to verify identity and derive a credential onto the mobile device, the derived credential is issued under NIST SP800-157 at LOA-3, or at LOA-4 where in-person biometric authentication is performed, and can be used for logical access, VPN, email signing and mobile applications. PIV-D and NIPR/SIPR mobile access scenarios are supported. MyID handles the full derived credential lifecycle, initial derivation, renewal, and revocation, integrated with your existing PKI infrastructure.
Common questions
Need something specific? Contact our team →
A derived credential is a PKI certificate issued to a mobile device that is derived from an existing primary credential (typically a PIV smart card) without requiring full re-identity proofing. The derivation process verifies the primary credential before issuing to the mobile device. NIST SP 800-157 defines the technical requirements for derived PIV credentials.
Derived credential issuance work without an MDM. However, an MDM (Intune, Jamf, SOTI) is recommended for enterprise deployment to manage app distribution, device compliance policy and certificate profile deployment. MyID integrates with major MDM platforms.
iOS 14 and later (Secure Enclave key binding). Android 9 and later with StrongBox or TEE (Trusted Execution Environment) support. Specific device compatibility is tested against the MyID app, refer to the current compatibility matrix in our support documentation.