Skip to content

NXP Smart Card Chip Comparison

MIFARE Plus EV2 vs DESFire EV3: Migration & Files

Evaluate MIFARE Plus EV2 for a staged MIFARE Classic migration that preserves sector-oriented application logic while moving toward AES. Evaluate DESFire EV3 for an application-and-file credential platform. Both require a defined reader, personalization and key-management plan; neither is an automatic system upgrade or a drop-in replacement for the other.

Updated · Configuration and sample planning

On this page

Compare the requirements that change the choice

A practical specification and deployment comparison of current-generation MIFARE Plus EV2 and MIFARE DESFire EV3 chips.
Decision pointMIFARE Plus EV2MIFARE DESFire EV3
Frequency and interface13.56 MHz; ISO/IEC 14443 Type A; up to 848 kbit/s13.56 MHz; ISO/IEC 14443 Type A; up to 848 kbit/s
Available memory2 kB or 4 kB2 kB, 4 kB, 8 kB or 16 kB
Common Criteria certificationEAL5+ (hardware and software)EAL5+ (hardware and software)
Security directionAES-128 authentication and secure messaging, with security levels that support staged migrationAES-128 plus DES/2K3DES/3K3DES options, secure messaging and transaction-focused security features
Data organization2 kB: 32 sectors of 4 blocks; 4 kB adds 8 sectors of 16 blocksApplications with up to 32 files per application; application count depends on available memory
MIFARE Classic migrationProvides Classic-compatible modes; exact identifier handling, security level and application still need testingOwn commands and file/application structure; no drop-in Classic compatibility
Additional application featuresTransaction MAC, Proximity Check and Transaction Timer; validate the required modeSecure Dynamic Messaging for SUN/NDEF workflows, plus transaction and proximity features; requires configuration and backend validation
Best fitPhased upgrades where Classic continuity and infrastructure transition are prioritiesNew or redesigned high-security, multi-application credential programs
Reader impactCan reduce migration friction, but reader firmware, keys and security level still require validationRequires DESFire-capable readers and application software; ISO compliance alone is not enough
Sample and quote scopeSpecify memory, security level, sector layout and personalization; price migration work separatelySpecify memory, application/files, authentication and personalization; price integration work separately
  • Both use 13.56 MHz, but they are not drop-in equivalents: Both support ISO/IEC 14443 Type A and data rates up to 848 kbit/s. Reader RF compatibility alone does not guarantee that keys, commands and the application stack will work.
  • Plus EV2 is designed around a staged Classic migration: Its security levels and mixed-mode options help teams move from legacy Crypto1 workflows toward AES-128 without replacing every credential and reader in one step.
  • DESFire EV3 is built for richer credential applications: Its application-and-file architecture, broader memory range and security features suit campus, transit, enterprise access, hospitality and multi-service credentials.

Choose MIFARE Plus EV2 if

  • You are replacing MIFARE Classic credentials and need a phased reader, key and card migration instead of a single cutover.
  • The application still fits a sector-based card structure and does not require a complex multi-application file system.
  • Budget and installed-infrastructure continuity matter, but the program still needs a defined path to AES-128 security.

Choose MIFARE DESFire EV3 if

  • You are building a new credential platform for enterprise access, campus, transit, hospitality, loyalty or multiple services on one card.
  • You need flexible applications and files, more memory options or transaction-oriented security features.
  • The project can validate or update readers and backend software now instead of preserving Classic-oriented application logic.

Do not choose from the chip name alone

Ask the reader or system vendor which chip generation, security mode, keys and commands the installed application supports. Then test encoded samples on the real readers before ordering production cards. A reader that detects both chips may still fail the actual application transaction.

Common decisions

Questions buyers ask before choosing

Is MIFARE Plus EV2 simply a lower-cost DESFire EV3?

No. Plus EV2 focuses on sector-oriented applications and a staged Classic migration, while DESFire EV3 uses applications and files. Compare the required integration, personalization and supply configuration instead of assuming a fixed chip-price hierarchy.

Can a MIFARE Classic reader use MIFARE Plus EV2?

A compatible mode can support migration, but the installed reader, identifier handling, application and chosen security level must be checked. Legacy operation does not mean the full application is already protected by AES. Validate the transition with authorized encoded samples.

Does the 4 kB Plus EV2 have the same sector layout as the 2 kB version?

No. NXP specifies 32 sectors of 4 blocks for the 2 kB variant. The 4 kB variant adds 8 sectors of 16 blocks. Approve the exact variant and sector access plan rather than copying a 2 kB memory map into a 4 kB purchase specification.

Does EAL5+ mean the finished access system is certified?

No. NXP lists Common Criteria EAL5+ for the hardware and software of these ICs. That does not certify an RFIDAK finished card, the reader installation or the backend application. Those require their own appropriate evidence and validation.

Is DESFire EV3 backward compatible with MIFARE Plus?

It is not a drop-in Plus or Classic replacement. NXP describes backward compatibility within the DESFire family, including EV2, EV1 and D40. Using EV3-specific functions can require new commands and configuration; test the actual application even within that family.

What must a comparison sample prove?

Have the integrator issue test credentials with non-production data. Verify authentication, required sector or file operations, permissions, interrupted-transaction handling where relevant, and revocation. Record reader firmware, memory variant and application configuration. Agree secure personalization responsibilities without sending live keys in an inquiry.

Move from the guide to a sample

Product options to investigate

These pages describe product formats. Confirm the exact chip, construction and system compatibility for your selected configuration.

Check the basis for your decision

Sources and technical references

Chip and standards references describe their own scope. They do not establish a finished product’s read distance, durability or compatibility.

  1. NXP: MIFARE Plus EV2

    Memory variants, security levels, sector layout and certification for the IC.

  2. NXP: MIFARE DESFire EV3

    Application/file structure, memory variants, cryptography and IC certification.

  3. NXP: MIFARE Plus EV2 short data sheet

    Variant-specific memory organization and migration functions.

  4. NXP: MIFARE DESFire EV3 short data sheet

    Application architecture and backward compatibility within the DESFire family.

  5. NXP: System-level security measures

    Security implementation guidance for MIFARE installations; an IC feature is not a complete system design.

Make the next step specific

Bring your requirements into a sample plan.

Send the system details and acceptance conditions you already know. The offered configuration, sample charges and delivery terms should be confirmed in your quotation.

Include these details

  • Current credential and reader/controller/firmware
  • Migration stages or new application; required transaction
  • Memory variant and sector layout or application/file needs
  • Target security mode and personalization owner, without secret keys
  • Sample/production quantities, destination and required date

Sample termsDelivery planning

WhatsAppGet a Quote